What this check looks at
SPF (Sender Policy Framework) is a DNS TXT record that lists the servers permitted to send mail for a domain. When your test message arrives, JoltMx records the SPF verdict for the connecting IP, then re-reads the published record to check it for the faults that quietly break SPF:
- The verdict for the sending IP - pass, fail, softfail, neutral, or an error.
- Whether the domain publishes exactly one SPF record (more than one is a permanent error).
- The final
allqualifier --all,~all,?all, or the dangerous+all. - The DNS lookup count - the record must resolve within the RFC 7208 limit of 10 lookups.
Why it matters
SPF is one of the two pillars (with DKIM) that receivers use to decide whether mail is genuine. Major providers require SPF or DKIM to accept mail at all, and both for bulk senders. A failing or broken SPF record is a fast track to rejection - and a permissive one (+all) actively invites spoofing of your domain.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| SPF passed | Pass | The sending IP is authorised by the domain. |
| No SPF record | Critical | The domain publishes none. Publish a record starting v=spf1. |
| SPF failed | Critical | The sending IP isn't in the record. Add it, or relay through an authorised host. |
| Record is broken (permerror) | Critical | Syntax error - treated like a hard fail by many receivers. |
| Duplicate records | Critical | More than one v=spf1 record. Merge into one. |
Allows any sender (+all) | Critical | Authorises the whole internet. Replace with ~all or -all. |
| Lookup limit exceeded | Critical | Over 10 DNS lookups - SPF effectively never passes. Flatten includes. |
Soft-fail / neutral / no all | Warning | Weak protection; raises spam scoring. End with ~all or -all. |
| Lookup budget nearly exhausted | Warning | 9 of 10 lookups used - one more include is likely to break SPF. |
| Temporary error | Info | DNS was briefly unavailable during evaluation. Re-test. |
How to fix it
A healthy record lists your senders and ends with a strict qualifier:
v=spf1 include:joltmx.io ~all
- Keep one record only. If you send through several providers, merge their
include:terms into the single record. - End with
~all(soft fail) or-all(hard fail) - never+all. - If you're near the 10-lookup limit, remove unused
include:terms or flatten them to IP ranges.
SPF alone doesn't survive forwarding - the forwarder's IP isn't in your record. That's expected, and why DKIM and ARC exist. See message type for how to read SPF on forwarded mail.