SPF softfail (~all)
The sending server is not on your authorised list, but you are asking receivers to accept the mail anyway and mark it as suspicious.
What causes it
- The record ends in ~all, which is the intended, deliberate setting for most domains.
- A legitimate sender is missing from the record.
How to fix it
~all is the right default while you are still discovering senders. Once DMARC aggregate reports show every legitimate source is authenticated, tightening to -all is optional — with DMARC at p=reject in place, ~all and -all behave almost identically for spoofing protection.
Check your domain
Also searched for: ~all meaning, spf softfail meaning, what does ~all do.