Email Authentication
SPF policy strength check
The ending of your SPF record (-all, ~all, ?all or +all) decides what receivers do with mail from servers you did not list.
Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.
What we look at
We read the all mechanism at the end of your SPF record. -all says reject everything else, ~all says be suspicious, ?all and +all say nothing useful.
Why it matters to your business
An SPF record that ends in ?all or +all lists your servers and then tells receivers it does not matter if mail comes from somewhere else, which gives an impersonator exactly what they need. ~all is common and acceptable when DMARC is enforcing; -all is the strongest statement you can make.
How to fix it
- Once your SPF record lists every service that sends for you, change the ending to -all (or ~all while you confirm nothing legitimate is missing).
- Never use +all. It authorizes the entire internet to send as your domain.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
Keep an eye on it
A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.
