C
conductor

Fix library / spf-softfail

MEDIUMOften searched as: "spf softfail vs hardfail"

SPF set to ~all (soft fail) — should you change it?

WHAT YOU'RE SEEING

Your SPF record ends in ~all (soft fail) instead of -all (hard fail).

WHY IT'S HAPPENING

You used a permissive policy when first setting up SPF. Soft-fail is safer during rollout but should be hardened once you're confident every legitimate source is included.

How to fix it

  1. 1

    For 2-4 weeks, monitor DMARC aggregate reports. Confirm no legitimate mail is failing.

  2. 2

    If clean, update your SPF TXT record: change ~all to -all.

  3. 3

    Save. Monitor for a week to ensure no new sources appear.

Where do I add these records? (by DNS host)

Records go in the DNS panel of whoever hosts your domain, not inside Gmail or Outlook. Find your host below.

Cloudflare

  1. 1.Log in and pick your domain.
  2. 2.Open the DNS tab, then Records.
  3. 3.Click Add record, choose the type (TXT/CNAME), paste the Name and Value, Save.
  4. 4.Tip: Conductor can apply Cloudflare records for you. Connect a token on your domain page instead of doing this by hand.

GoDaddy

  1. 1.Go to My Products, find your domain, click DNS.
  2. 2.Under Records, click Add.
  3. 3.Pick the type, enter the Name (Host) and Value, Save. Use "@" for the root domain.

Crazy Domains

  1. 1.Log in, go to My Account, then Manage next to your domain.
  2. 2.Open DNS / Manage DNS.
  3. 3.Add a record, choose the type, enter the Hostname and Value, Save.

VentraIP

  1. 1.Log in to VIPControl, open Domain Names, click your domain.
  2. 2.Choose Manage DNS / DNS Zone.
  3. 3.Add a record with the type, name and content shown above, Save.

Squarespace / Google Domains

  1. 1.Open Settings, then Domains, and pick your domain.
  2. 2.Choose DNS Settings, scroll to Custom Records.
  3. 3.Add the record type, host and data, Save.

Namecheap

  1. 1.Go to Domain List, click Manage next to your domain.
  2. 2.Open the Advanced DNS tab.
  3. 3.Click Add New Record, set the type, host and value, and save with the green tick.

Not listed? The steps are the same everywhere: find DNS or Manage DNS, add a record, pick the type, paste the name and value shown above.

Not sure if this is your problem?

Related fixes