InboxAudit

SPF softfail (~all)

The sending server is not on your authorised list, but you are asking receivers to accept the mail anyway and mark it as suspicious.

What causes it

  • The record ends in ~all, which is the intended, deliberate setting for most domains.
  • A legitimate sender is missing from the record.

How to fix it

~all is the right default while you are still discovering senders. Once DMARC aggregate reports show every legitimate source is authenticated, tightening to -all is optional — with DMARC at p=reject in place, ~all and -all behave almost identically for spoofing protection.

Check your domain

Also searched for: ~all meaning, spf softfail meaning, what does ~all do.