"spf=softfail" in email headers: what it means and how to fix it

What's happening: The server that sent your message isn't listed in your domain's SPF record, and the record ends in ~all, so receivers treat it as suspicious rather than rejecting it outright. Combined with missing DKIM, softfail is a common reason legitimate mail lands in spam.

How to fix it

  1. Open the message headers (Gmail: Show original) and find the sending IP and the service that sent it (look at the Received and Return-Path lines).
  2. Add that service to your single SPF record using the include: it documents, for example include:spf.protection.outlook.com for Microsoft 365 or include:zoho.com for Zoho.
  3. If the mail came from your own server or website (contact forms, WordPress), either add its IP with ip4: or, better, send through your mail provider over SMTP.
  4. Also set up DKIM for that service: DMARC passes on DKIM alone, so aligned DKIM fixes delivery even when SPF can't align.
  5. Keep the record under 10 DNS lookups, then resend and check for spf=pass.

Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.

Other fix guides