- (Fail) — SPF Qualifier
The SPF - qualifier (Fail) causes a hard fail when a mechanism matches. The receiving server should reject the message.
Type
Qualifier
Qualifier
Syntax
DNS Lookup
No — no extra lookup
No — no extra lookup
💬 What This Qualifier Does
The "-" qualifier produces a "Fail" result. When used as "-all" at the end of a record, it tells receiving servers to reject any mail not covered by earlier mechanisms. This is the strongest SPF enforcement level and is required for full DMARC-aligned protection.
When to Use This
- "-all" — recommended ending for mature SPF records where all senders are known
- "-ip4:203.0.113.0/24" — explicitly block a specific IP range
⚠️ Watch Out For
- Don't use "-all" until you're confident your SPF record covers every legitimate sender.
- Legitimate forwarded mail (mailing lists, aliases) will fail SPF hard — consider DMARC alignment.
📚 RFC References
🔗 Related SPF Elements
🔧 Validate Your SPF Record
Check whether your current SPF record is valid and covers all your senders.