SPF (Sender Policy Framework)
Definition
A DNS-based mechanism by which a domain owner publishes the list of IP addresses authorised to send mail for that domain. A receiving server checks whether the envelope sender's domain authorises the connecting IP and records the result as pass, fail, softfail, neutral, or none.
- Mechanism type
- DNS-based sender authorisation
- Published by
- Domain owner
- Checked against
- Envelope sender domain and connecting IP
- Possible results
- Pass, fail, softfail, neutral, none
Common questions
What is the practical difference between an SPF fail and a softfail result?+
A fail means the connecting IP is explicitly not authorised and receivers typically reject or flag the message strongly, while a softfail is an advisory result the domain owner uses during a transition, often only downgrading the message's spam score.
Why do investigators check SPF alongside DKIM and DMARC rather than alone?+
SPF authenticates only the envelope path and breaks under simple forwarding, so it is combined with DKIM's cryptographic signature and DMARC's alignment policy to build a fuller picture of whether a message was actually spoofed.
Related terms
- DKIM (DomainKeys Identified Mail)
- A cryptographic signing mechanism: the sending server signs the message headers and body with a private key, and the receiving server verifies...
- DMARC (Domain-Based Message Authentication, Reporting, and Conformance)
- A policy layer that requires the domain in the visible From header to align with a domain that passes SPF or DKIM....
- Envelope Sender (Return-Path)
- The address used at the SMTP protocol level for bounce notifications, recorded in the Return-Path header. It is distinct from the display...
- Message-ID
- A globally unique identifier assigned to each message by the originating mail server, recorded in the Message-ID header. It is set by...
- Received Header
- A header line prepended by each mail server that accepts a message in transit, recording the server's own identity, the IP or...