DMARC Analyzer

The all qualifier: -all, ~all, ?all, +all

Every SPF record ends with an all mechanism (implicit ?all if omitted) that catches any sender not matched by an earlier rule:

-all — hard fail, the domain asserts this list is exhaustive.
~all — softfail, "probably not us, but don't reject."
?all — neutral, no assertion either way.
+all — pass, meaning literally any IP is "authorized." This defeats the purpose of SPF entirely and should never appear on a domain that wants any anti-spoofing benefit.

References