The all qualifier: -all, ~all, ?all, +all
← All help articles · SPF
Every SPF record ends with an all mechanism (implicit ?all if omitted) that catches any sender not matched by an earlier rule:
-all — hard fail, the domain asserts this list is exhaustive.~all — softfail, "probably not us, but don't reject."?all — neutral, no assertion either way.+all — pass, meaning literally any IP is "authorized." This defeats the purpose of SPF entirely and should never appear on a domain that wants any anti-spoofing benefit.
References
- RFC 7208 §5.1