SPF finding

SPF passes every server

The SPF record ends in +all, which passes every server on the internet and is worse than having none.

Finding code

spf_passes_everyone

This finding appears in the findings array of the spam checker and the POST /v1/sender API response when the condition above is detected.

How to fix it

The fix.

Replace "+all" with "-all". The current record tells every receiver to accept mail from any server claiming to be this domain.

Related SPF findings

Other things we check.

Finding What it means
spf_missing No SPF record
spf_multiple_records Multiple SPF records
spf_syntax_error SPF syntax error
spf_no_all_mechanism No all mechanism in SPF
spf_neutral_all SPF neutral all
spf_soft_fail SPF soft fail
spf_too_many_lookups Too many SPF lookups
spf_deprecated_ptr Deprecated ptr in SPF