Dnia 25.05.2023 o godz. 20:10:02 Scott Mutter via mailop pisze:
> So basically SPF is worthless.  You can define all the IPs that legitimate
> mail for the domain should be coming from and exclude everything else with
> a -all and mail servers are just supposed to ignore that and look for a
> DMARC record?

Interpretation of SPF check results is and always was a decision of the
recipient. The SPF RFC (RFC 7208) says clearly: "Disposition of SPF fail
messages is a matter of local policy."

You can use SPF check results to influence spam score of the message, and it
is usually used this way.
   Jaroslaw Rafa
