SPF hardfail (-all)
The sending server is not authorised and you are asking receivers to reject the mail outright.
What causes it
- The record ends in -all and a genuine sender was left out of it.
- Mail was forwarded, which breaks SPF by design — the forwarder becomes the sending IP.
How to fix it
Before publishing -all, confirm from DMARC aggregate reports that every legitimate sender passes. Forwarding will still break SPF regardless; that is what DKIM is for, since a DKIM signature survives forwarding intact.
Check your domain
Also searched for: -all meaning, spf hardfail, spf fail hard.