InboxAudit

SPF hardfail (-all)

The sending server is not authorised and you are asking receivers to reject the mail outright.

What causes it

  • The record ends in -all and a genuine sender was left out of it.
  • Mail was forwarded, which breaks SPF by design — the forwarder becomes the sending IP.

How to fix it

Before publishing -all, confirm from DMARC aggregate reports that every legitimate sender passes. Forwarding will still break SPF regardless; that is what DKIM is for, since a DKIM signature survives forwarding intact.

Check your domain

Also searched for: -all meaning, spf hardfail, spf fail hard.