KorantixKorantix

Understand what your scan results mean / SPF

What is SPF, and why does β€œ~all” vs β€œ-all” matter?

SPF tells receiving mail servers which servers are allowed to send email for your domain. The difference between a soft-fail and a hard-fail policy decides whether a forged email gets flagged β€” or rejected outright.

SPF (Sender Policy Framework) is a DNS TXT record that lists the mail servers authorized to send email on behalf of your domain. When another mail server receives a message claiming to be from you, it checks your domain's SPF record to see if the sending server is on the list.

The record ends with a qualifier that tells receivers what to do about servers not on the list. β€œ-all” (hard fail) tells receivers to reject the message outright. β€œ~all” (soft fail) asks them to accept it but mark it as suspicious β€” which in practice often still lands in the inbox, just flagged. β€œ+all” authorizes literally any server, which defeats the purpose of having SPF at all β€” Korantix flags this as a critical finding.

A common mistake is stacking multiple SPF records for one domain, or nesting too many β€œinclude:” mechanisms β€” SPF has a hard limit of 10 DNS lookups per check, and exceeding it causes the entire check to fail, which some receivers treat as if SPF weren't published at all. Korantix's Email Security scan follows every include chain and reports your actual lookup count, not just whether a record exists.

What to do: start by moving from β€œ~all” to β€œ-all” only after you've confirmed every legitimate sending source (your email provider, any marketing tool, any transactional-email service) is actually listed β€” switching too early can cause your own legitimate mail to be rejected.

Check this on your domain β†’