~ (SoftFail): SPF Qualifier

The SPF ~ qualifier (SoftFail) marks a match as suspicious but doesn't cause rejection. Used during SPF rollout and testing.

Published · Last verified · Maintained by TamingDNS

Type
Qualifier
Syntax
DNS Lookup
No (no extra lookup)

💬 What This Qualifier Does

The "~" qualifier produces a "SoftFail" result. Mail from unlisted senders is accepted but marked as suspicious (typically by adding an "X-Spam" or similar header). "~all" is the recommended qualifier while you're building out your SPF record and aren't yet confident all legitimate senders are covered.

When to Use This

  • "~all", safe default during initial SPF deployment
  • "~all", appropriate when mailing list forwarding is important and you can't use DMARC relaxed alignment

⚠️ Watch Out For

  • SoftFail is not rejection. Determined spammers can still deliver softfail mail.
  • DMARC works correctly with ~all, but some DMARC-unaware filters treat it more leniently.

📋 Complete Example Records

Every one of these is a complete record you can paste as it stands. Try one in the SPF Checker or build your own with the SPF Builder.

v=spf1 include:_spf.google.com ~all

The rollout record. Unlisted senders are marked rather than rejected, which buys you time to read DMARC reports and find the ones you forgot.

v=spf1 mx ~all

On-premise and still cautious: your MX hosts pass and everything else is flagged for closer inspection.

v=spf1 include:_spf.google.com include:servers.mcsv.net ~all

Two known senders with a soft ending. Tighten to "-all" once your DMARC reports show nothing else sending.

v=spf1 ~all

Nothing is authorised, but nothing is rejected either. It signals "we do not send from here" without asking receivers to act on it.

🔗 Related SPF Elements

all
Mechanism

🔧 Related Tools

Check whether your current SPF record is valid and covers all your senders, or move on to the DKIM and DMARC side of the same job.

SPF Checker → SPF Builder → DMARC Analyser → DKIM Checker → Route 53 Splitter →
← All SPF syntax