3 ms·
Because SPF has many design flaws that will break SPF for legitimate use-cases (such as relaying/forwarding). You wouldn't want to rely on SPF, you should alway
by LeonM 2y ago
Because SPF has many design flaws that will break SPF for legitimate use-cases (such as relaying/forwarding). You wouldn't want to rely on SPF, you should always on DKIM instead.
SPF should be considered legacy at this point. But of course DMARC had to be designed with backwards compatibility in mind, thus it'll still consider the email to be DMARC alignment with just SPF alignment (without DKIM alignment). Also, understand that 'alignment' is different from a 'pass', so it's not as bad as many commenters here make it look.
There are proposals of adding a flag to the DMARC policy to have the receiver ignore SPF alignment, thus enforcing DKIM alignment. However, that is not final yet.