"spf=softfail" in email headers: what it means and how to fix it
What's happening: The server that sent your message isn't listed in your domain's SPF record, and the record ends in ~all, so receivers treat it as suspicious rather than rejecting it outright. Combined with missing DKIM, softfail is a common reason legitimate mail lands in spam.
How to fix it
- Open the message headers (Gmail: Show original) and find the sending IP and the service that sent it (look at the
ReceivedandReturn-Pathlines). - Add that service to your single SPF record using the
include:it documents, for exampleinclude:spf.protection.outlook.comfor Microsoft 365 orinclude:zoho.comfor Zoho. - If the mail came from your own server or website (contact forms, WordPress), either add its IP with
ip4:or, better, send through your mail provider over SMTP. - Also set up DKIM for that service: DMARC passes on DKIM alone, so aligned DKIM fixes delivery even when SPF can't align.
- Keep the record under 10 DNS lookups, then resend and check for
spf=pass.
Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.
Other fix guides
- Gmail 550 5.7.26 "sender is unauthenticated"
- Outlook 550 5.7.515 "required authentication level"
- SPF permerror: too many DNS lookups
- Multiple SPF records found
- "dmarc=fail" in headers
- "dkim=none" / DKIM not set up
- Gmail "via" another domain next to your name
- "blocked using Spamhaus" bounce
- Gmail 550 5.7.1 "likely unsolicited mail"
- Emails going to spam or junk (general)