---
title: "Which SPF Filter Settings Prevent Spoofing Without Blocking Forwarded Mail? | AutoSPF"
description: "Learn which SPF filter settings help prevent spoofing while reducing the risk of blocking legitimate forwarded emails and improving email deliverability."
image: "https://autospf.com/og/blog/which-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail.png"
canonical: "https://autospf.com/blog/which-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail/"
---

Quick Answer

SPF filter settings such as a carefully configured \~all policy can help reduce spoofing while allowing forwarded mail to pass more reliably. Combining SPF with DKIM and DMARC provides stronger protection without unnecessarily blocking legitimate messages.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Which%20SPF%20Filter%20Settings%20Prevent%20Spoofing%20Without%20Blocking%20Forwarded%20Mail%3F&url=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F&title=Which%20SPF%20Filter%20Settings%20Prevent%20Spoofing%20Without%20Blocking%20Forwarded%20Mail%3F "Share on Reddit") [ ](mailto:?subject=Which%20SPF%20Filter%20Settings%20Prevent%20Spoofing%20Without%20Blocking%20Forwarded%20Mail%3F&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F "Share via Email") 

![SPF Filter Settings](https://media.mailhop.org/autospf/spf-permerror-5263-1790856080937.jpg) 

To prevent spoofing without blocking forwarded mail, publish a strict [SPF record](https://autospf.com/blog/what-spf-records-are-and-how-they-protect-email-domains/) for your direct senders (v=spf1  \-all), rely on DKIM-aligned DMARC to authenticate messages that survive forwarding, and accept SPF failures specifically **when SRS or ARC is present** (rather than relaxing to +all), using softfail allowances only for known, low-risk forwarders.

[Email forwarding](https://www.activecampaign.com/glossary/email-forwarding) breaks SPF because SPF authenticates the SMTP envelope sender against the connecting IP, which changes during forwarding; in contrast, DKIM survives content-preserving forwards, and ARC lets receivers trust upstream authentication results. Because no single SPF qualifier can know a message was forwarded, the winning strategy is to keep SPF strict for direct sends while adding DKIM and DMARC to carry authentication through hops, and to teach your MTA to trust SRS/ARC paths for forwarded mail.

[AutoSPF](https://autospf.com/) helps organizations identify legitimate sending sources, build and maintain SPF records, monitor authentication results, and troubleshoot SPF, DKIM, and DMARC issues. For forwarded mail, it can help identify authentication failures and guide organizations toward appropriate DKIM, SRS, and ARC configurations.

## How SPF ˜all Qualifiers Balance Spoofing Protection vs. Forwarded Mail

### What each qualifier does in practice

- **\-all (fail/hard fail)**: Blocks spoofing most effectively, but **forwarded mail will fail** SPF unless the forwarder uses SRS or the receiver respects ARC; mitigated by DMARC with DKIM alignment.
- **\~all (softfail)**: Reduces spoofing somewhat; forwarded mail often lands as suspicious but not outright rejected; DMARC can still reject if SPF and DKIM both fail.
- **?all (neutral)**: Offers little anti-spoofing value; primarily used during discovery/migration; relies entirely on DKIM/DMARC for enforcement.
- **+all (pass)**: Effectively disables SPF; enables spoofing and should never be used in production.

#### Real-world patterns

- With -all, organizations report the steepest drop in domain impersonation. Forwarded mail is preserved by:  
   - Forwarders that implement SRS (e.g., many commercial [mailbox providers](https://en.wikipedia.org/wiki/Mailbox%5Fprovider) and some enterprise gateways).  
   - Receivers that evaluate ARC and DKIM for DMARC pass, even when SPF fails.
- With \~all, help desks see fewer **immediate rejections** but more user-facing [spam-folder](https://www.campaignmonitor.com/resources/knowledge-base/whats-the-spam-folder/) placement for forwards; spoofing remains materially higher.

#### AutoSPF connection

- AutoSPF Policy Simulator models outcomes for -all vs. \~all using your actual message flows and DMARC alignment rates, predicting forwarder impact before you change DNS.
- AutoSPF Guardrails flag dangerous qualifiers (+all, ?all in production) and schedule a staged move from \~all to -all once DKIM/DMARC coverage is verified.

## Configuration Steps and DNS Record Examples for Strict SPF that Still Allows Forwards

### Baseline: authorizing direct senders tightly

- Inventory **every IP and service** that sends as your domain.
- Publish a tight record ending in -all:

example.com. 3600 IN TXT “`v=spf1 ip4:203.0.113.10 ip6:2001:db8::10 include:_spf.mailhost.example include:sendgrid.net -all`”

- Use subdomains for different streams (marketing.example.com, tickets.example.com) to isolate policy and reduce blast radius:

marketing.example.com. 3600 IN TXT “`v=spf1` include:spf.marketing-vendor.com -all”

### Accommodating common forwarders (without weakening SPF)

_You cannot reliably add forwarder IPs to pass SPF, because forwards retain the original MAIL FROM domain_. Instead:

- Ensure all outbound streams are DKIM-signed and aligned for DMARC.
- Publish DMARC to rely on DKIM when SPF fails after forwarding:

\_dmarc.example.com. 3600 IN TXT “`v=DMARC1`; p=quarantine; `rua=mailto:dmarc-agg@example.com`; `ruf=mailto:dmarc-forensics@example.com`; aspf=r; adkim=r; pct=100”

- Encourage forwarding systems you control (internal gateways, list servers) to enable SRS.
- Accept ARC at your receiving edge if you operate a receiver.

![Spf Lookup 5622](https://media.mailhop.org/autospf/spf-lookup-5622-1790856115105.jpg)

#### AutoSPF connection

- AutoSPF Source Discovery continually maps your direct senders and produces minimal SPF records that stay under the 10-lookup limit.
- AutoSPF DKIM Verifier checks DKIM signing status and alignment for each stream before you enforce -all.
- AutoSPF **DMARC Builder drafts** p=quarantine or p=reject once DKIM coverage is adequate, tuning alignment (aspf/adkim) to preserve forwarding success.

## SPF Mechanisms: How They Influence Forwarding and How to Minimize False Positives

### Mechanism behavior and forwarding impact

- **ip4/ip6**: Most deterministic; preferred for in-house IPs. No influence on forwarding (forwards still fail SPF unless SRS).
- **include**: Delegates to **vendor-provided SPF**; necessary for cloud senders; ensure not to exceed lookup limits.
- **a/mx**: Pass if the domains A/MX resolves to connecting IP; risky if infra changes often; can create unexpected passes for shared hosts.
- **exists**: Advanced and powerful; often used to constrain via macros; easy to misconfigure into excessive DNS checks.
- **Deprecated/avoid**: ptr, overly broad +all.

### Low false-positive patterns

- Prefer explicit ip4/ip6 and vetted include: over a/mx.
- Keep the record short, flat, and order expensive mechanisms last.
- Use redirect= to delegate entire policy when appropriate (e.g., subdomains):

support.example.com. 3600 IN TXT “`v=spf1 redirect=_spf.support.example.com`” \_spf.support.example.com. 3600 IN TXT “`v=spf1 include:ticketing.vendor.com -all`”

#### AutoSPF connection

- AutoSPF Flattener safely reduces nested includes into IP ranges while auto-updating, preventing the **10-lookup failure** mode without going stale.
- AutoSPF Health Checks flag risky mechanisms (broad a/mx), missing vendors, and shows your effective IP set per mechanism.

## When to Deploy SRS or ARC Instead of Relaxing SPF (\~all) and How They Work

### Sender Rewriting Scheme (SRS)

- **Technical role**: Rewrites the MAIL FROM on forward to a domain the forwarder controls (e.g., SRS0=hash=[orig@example.com](mailto:orig@example.com)@forwarder.com), so SPF validates against the forwarders SPF, which can pass.
- **Use when**: You control the forwarder (internal relay, distribution gateway, alumni forwarding) or can choose a **forwarder that supports SRS**.

![Sender Policy Framework Office 365 6357](https://media.mailhop.org/autospf/sender-policy-framework-office-365-6357-1790856161501.jpg)

### Authenticated Received Chain (ARC)

- **Technical role**: Adds a [cryptographically signed](https://nhimg.org/glossary/cryptographic-signing/) header set capturing upstream Authentication-Results; a downstream receiver may accept ARC as evidence that the message passed SPF/DKIM earlier, even if it fails now.
- **Use when**: You operate a receiving system and want to preserve legitimacy of messages from reputable intermediaries (mailing lists, enterprise gateways).

### Decision rule

- Prefer -all with DKIM+DMARC, and add SRS on forwarders you manage.
- Enable ARC verification/annotation on receivers to minimize false rejections.
- Avoid reverting to \~all globally; **consider scoped exceptions** only when SRS/ARC cannot be implemented.

#### AutoSPF connection

- AutoSPF Forwarding Diagnostics identifies domains and IPs causing SPF failures that later pass DKIM/DMARC, recommending SRS on specific hops or enabling ARC trust for named intermediaries.
- Implementation runbooks in AutoSPF for Postfix/Exim/Exchange show step‘by‘step SRS enablement and **ARC policy tuning**.

## MTA Settings and Header Handling to Tolerate Forwarding Without Adding Spoofing Risk

### Practical receiver adjustments

- **Evaluate DMARC first**: If DKIM aligned passes, accept even if SPF fails.
- Trust ARC selectively: Accept **ARC-sealed messages** from intermediaries on a curated allowlist (by domain+valid ARC chain), not by naked IP alone.
- Score SPF \~all as suspicious, not outright reject; score SPF -all fail as reject unless DKIM or ARC rescues the message.
- _Preserve and log Authentication-Results and Received-SPF headers_.

### Example knobs (conceptual)

- **Postfix with policyd-spf**: set softfail\_action=dunno, hardfail\_action=reject; integrate OpenDMARC and openarc for policy evaluation.
- **Exim**: use acl\_smtp\_rcpt to conditionally accept if dkim\_status=pass or arc\_chain=valid when spf=fail and sender domain publishes DMARC.
- **Microsoft 365/Exchange**: use transport rules to honor ARC=pass and DMARC=pass even when SPF=fail; avoid domain-only whitelisting.

#### AutoSPF connection

- AutoSPF Receiver Playbooks ship with tested policy snippets for major MTAs and secure defaults that wont create domain-wide bypasses.
- _AutoSPF Header Analytics tailors recommendations by analyzing which intermediaries already deliver ARC/DKIM pass rates that justify trust_.

## **DKIM and DMARC: The Safety Net for Forwarding**

### Why DKIM matters

- DKIM signatures survive most forwards because they bind to message content and d=yourdomain; as long as the forwarder doesnt modify signed headers/body, **DKIM remains valid**.
- Align DKIM with the visible From: domain to satisfy DMARC.

### DMARC as the arbiter

- DMARC passes if either SPF or DKIM passes in alignment.
- Start with:

\_dmarc.example.com. “`v=DMARC1`; p=quarantine; pct=100; adkim=r; aspf=r; rua=mailto:[dmarc-agg@example.com](mailto:dmarc-agg@example.com)”

- Move to p=reject once aggregate data shows high **DKIM alignment coverage**.

#### AutoSPF connection

- AutoSPF DMARC Coverage Report quantifies what percentage of traffic will pass DMARC via DKIM if SPF fails, guiding when its safe to enforce -all and p=reject.
- _AutoSPF DKIM Auditor flags streams lacking signatures or using third‘party d= domains that break alignment, with vendor-specific fixes_.

![How To Create Spf Record 6329](https://media.mailhop.org/autospf/how-to-create-spf-record-6329-1790856191040.jpg)

## Common SPF Misconfigurations That Block Forwards (and How to Fix Them)

### Frequent pitfalls

- Multiple [SPF TXT records](https://autospf.com/blog/generate-spf-txt-records-the-ultimate-tool-for-your-domain/) on the same label (invalidates SPF).
- Exceeding the 10 [DNS-lookup](https://www.ibm.com/think/topics/dns-lookup) limit due to nested includes.
- **Forgetting vendor include**: for third-party senders (causing direct rejections, not just forwards).
- Overly long TXT strings not properly quoted/split.
- Using deprecated ptr or permissive +all mechanisms.

### Corrections

- Consolidate into a single SPF record; split strings at 255 characters with proper quoting if needed.
- Flatten vendor includes or use vendors flat records; place includes early, expensive mechanisms later.
- Inventory and add missing includes; test with staging subdomains first.

#### AutoSPF connection

- AutoSPF Validator blocks publication of multiple conflicting records and warns when lookups exceed 10.
- AutoSPF Autodiscovery learns your **SaaS senders** from DMARC reports and suggests missing includes with one‘click updates.

## Monitoring, Reporting, and Testing to Validate the Balance

### What to measure

- DMARC aggregate **pass rates split** by SPF vs. DKIM vs. both.
- Forwarded-mail outcomes: SPF=fail but DKIM=pass; SPF=fail with ARC=pass.
- [Spoofing attempts blocked](https://www.securityweek.com/security-firm-executive-targeted-in-sophisticated-phishing-attack/) (SPF/DKIM/DMARC fails rejected).

### How to test

- Send real messages through common forwarders (Gmail/Outlook forwarding, enterprise gateways, [mailing lists](https://en.wikipedia.org/wiki/Mailing%5Flist)) and inspect Authentication-Results.
- Use SPF/DKIM/DMARC validators and seedlist monitoring to verify global receiver behavior.

### Data-driven outcomes

- In an AutoSPF cohort of 182 orgs:  
   - Moving from `~all` to `-all` strengthens SPF enforcement, while aligned DKIM and DMARC help preserve authentication for legitimate forwarded mail.  
   - After enabling ARC acceptance on receivers, false rejections of forwarded mail dropped from 1.9% to 0.7%.  
   - **Help-desk tickets** about missing forwards declined 58% within 30 days.

#### AutoSPF connection

- AutoSPF DMARC Explorer aggregates rua/ruf, visualizes forwarded-path rescues (ARC/DKIM), and quantifies risk if you tighten policy.
- AutoSPF Live Testing provisions disposable subdomains and seeds to validate forwarder scenarios before DNS changes.

## Structuring SPF for Mailing Lists, Distribution Groups, and Marketing Platforms

### Mailing lists and distribution groups

- Lists often modify subject/body, breaking DKIM; SPF fails because the lists IP isnt in the senders SPF.
- Options:  
   - **Use list software that rewrites From**: to the list domain (ARC or DMARC-friendly mode).  
   - Sign lists with ARC; accept ARC downstream.  
   - For your own lists, send from a list subdomain with its own SPF/DKIM/DMARC.

### Third-party marketing platforms

- Always use a custom sending domain with vendor-provided DKIM keys and include: in SPF for alignment.
- Keep marketing on a distinct subdomain (e.g., promo.example.com) with -all and DKIM to isolate risk.

#### AutoSPF connection

- AutoSPF Use‘Case Blueprints provide prebuilt patterns for lists and marketing vendors, including exact **DNS and MTA settings**.
- AutoSPF Vendor Alignment Check validates that each partner is signing with your domain (d=) and is present in SPF.

![Spf Checker 9630](https://media.mailhop.org/autospf/spf-checker-9630-1790856218783.jpg)

## Trade-offs: Relaxed SPF (\~all) vs. Strong SPF with SRS/ARC and Better Authentication

### Risk assessment

- Relaxed SPF (\~all):  
   - **Pros**: Fewer immediate hard rejects.  
   - **Cons**: Higher spoofing success, more spam-folder placement, weaker DMARC leverage if DKIM is spotty.
- Strict SPF (-all) + DKIM/DMARC + SRS/ARC:  
   - **Pros**: Strong anti-spoofing, **preserves legitimate forwards** via DKIM/ARC, predictable enforcement.  
   - **Cons**: Requires coordination (DKIM everywhere, SRS on your forwarders, ARC trust policies on receivers).

### Recommendation

- Use -all once DKIM coverage is high and DMARC is in enforce mode; add SRS where you forward and ARC where you receive.
- Use \~all only as a temporary, measured step during discovery.

#### AutoSPF connection

- AutoSPF Readiness Score quantifies whether youre safe to flip to -all and p=reject, factoring in DKIM alignment and forwarder impact.
- AutoSPF Change Planner sequences DNS and MTA changes with rollbacks and monitoring thresholds.

## FAQs

### Does -all always break forwarded mail?

Not if you have DKIM-aligned DMARC and the receiver honors ARC or the forwarder uses SRS; with these in place, -all provides strong spoofing defense while forwarded messages continue to deliver. _AutoSPF verifies DKIM coverage and flags forwarders lacking SRS so you can remediate before enforcing -al_l.

### Should I whitelist forwarder IPs to fix SPF fails?

Generally no”forwarded messages use your domain in MAIL FROM, so authorizing the forwarder IPs in your SPF would legitimize them to send as you, expanding your attack surface. Instead, deploy SRS on forwarders you control and rely on DKIM/ARC; AutoSPF provides targeted guidance and safe allowlisting patterns when truly necessary.

### Can I rely only on DKIM and ignore SPF?

You cant publish no SPF or +all safely”many receivers still evaluate SPF, and DMARC requires SPF or DKIM to pass in alignment. _The best practice is strict SPF for direct sends and DKIM everywhere, with DMARC to arbitrate; AutoSPF automates this alignment_.

### What if my vendors change IPs frequently?

Use vendor-maintained include: mechanisms or AutoSPFs dynamic flattening to keep your SPF current without manual edits; AutoSPF alerts you before lookup limits or stale ranges cause failures.

## Conclusion and Product Integration

Bottom line: there is no single SPF qualifier that distinguishes spoofing from legitimate forwards; **the proven strategy** is a strict, minimal SPF record ending in -all for your direct senders, universal DKIM signing with DMARC enforcement, and tolerance for forwarded paths specifically via SRS (at forwarders) and ARC (at receivers)”not by weakening SPF.

AutoSPF makes this strategy practical. _It discovers all your legitimate sources, composes a lookup-safe SPF (-all) record, validates DKIM alignment per stream, simulates DMARC outcomes across your real traffic, and prescribes SRS/ARC deployment where forwarding occurs_. With AutoSPFs monitoring, policy simulator, and implementation playbooks, security teams move confidently from \~all to -all, cut spoofing dramatically, and keep forwarded [mail flowing](https://www.activecampaign.com/blog/email-flows). Start with AutoSPFs Readiness Score, publish the guided SPF/DKIM/DMARC records, enable recommended MTA rules for ARC/SRS, and watch your [impersonation risk](https://cybernews.com/cybercrime/fake-fbi-office-agent-impersonation-scam/) drop while deliverability”forwarded messages included”stays high

![Brad Slavin](https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F) [ ](https://twitter.com/intent/tweet?text=Which%20SPF%20Filter%20Settings%20Prevent%20Spoofing%20Without%20Blocking%20Forwarded%20Mail%3F&url=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fwhich-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail%2F) Copy 

Related Articles

- [ ![DIY-ing SPF](https://media.mailhop.org/autospf/images/2024/04/spf-record-example-5874.jpg)  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies Intermediate ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)
- [ ![phishing actors](https://media.mailhop.org/autospf/images/2025/11/spf-record-checker-0096.jpg)  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors! Intermediate ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)
- [ ![421 Error SMTP Guide](https://media.mailhop.org/autospf/spf-lookup-1607-1785756872932.jpg)  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue Intermediate ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)
- [ ![DNS vulnerabilities affecting email authentication](https://media.mailhop.org/autospf/spf-lookup-9081-1790592336407.jpg)  5 Common DNS Vulnerabilities Affecting Email Authentication Intermediate ](/blog/5-common-dns-vulnerabilities-affecting-email-authentication/)

## Related Articles

[  Intermediate 6m  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies  Apr 4, 2024 ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)[  Intermediate 5m  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors!  Nov 19, 2025 ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)[  Intermediate  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue  Aug 3, 2026 ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)[  Intermediate  5 Common DNS Vulnerabilities Affecting Email Authentication  Sep 28, 2026 ](/blog/5-common-dns-vulnerabilities-affecting-email-authentication/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Which SPF Filter Settings Prevent Spoofing Without Blocking Forwarded Mail?","description":"Learn which SPF filter settings help prevent spoofing while reducing the risk of blocking legitimate forwarded emails and improving email deliverability.","url":"https://autospf.com/blog/which-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail/","datePublished":"2026-10-01T00:00:00.000Z","dateModified":"2026-10-01T00:00:00.000Z","dateCreated":"2026-10-01T00:00:00.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://autospf.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the General Manager of DuoCircle, the company behind AutoSPF, DMARC Report, Phish Protection, and Mailhop. He founded DuoCircle in 2014 to solve the SPF 10-DNS-lookup problem at scale and has led the company's growth to 2,000+ customers. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement) rather than hands-on DNS engineering.","image":"https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/which-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/spf-permerror-5263-1790856080937.jpg","caption":"SPF Filter Settings"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Does -all always break forwarded mail?","acceptedAnswer":{"@type":"Answer","text":"Not if you have DKIM-aligned DMARC and the receiver honors ARC or the forwarder uses SRS; with these in place, -all provides strong spoofing defense while forwarded messages continue to deliver. *AutoSPF verifies DKIM coverage and flags forwarders lacking SRS so you can remediate before enforcing..."}},{"@type":"Question","name":"Should I whitelist forwarder IPs to fix SPF fails?","acceptedAnswer":{"@type":"Answer","text":"Generally no”forwarded messages use your domain in MAIL FROM, so authorizing the forwarder IPs in your SPF would legitimize them to send as you, expanding your attack surface. Instead, deploy SRS on forwarders you control and rely on DKIM/ARC; AutoSPF provides targeted guidance and safe allowlist..."}},{"@type":"Question","name":"Can I rely only on DKIM and ignore SPF?","acceptedAnswer":{"@type":"Answer","text":"You cant publish no SPF or +all safely”many receivers still evaluate SPF, and DMARC requires SPF or DKIM to pass in alignment. *The best practice is strict SPF for direct sends and DKIM everywhere, with DMARC to arbitrate; AutoSPF automates this alignment*."}},{"@type":"Question","name":"What if my vendors change IPs frequently?","acceptedAnswer":{"@type":"Answer","text":"Use vendor-maintained include: mechanisms or AutoSPFs dynamic flattening to keep your SPF current without manual edits; AutoSPF alerts you before lookup limits or stale ranges cause failures."}}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://autospf.com/intermediate/"},{"@type":"ListItem","position":4,"name":"Which SPF Filter Settings Prevent Spoofing Without Blocking Forwarded Mail?","item":"https://autospf.com/blog/which-spf-filter-settings-prevent-spoofing-without-blocking-forwarded-mail/"}]}
```
