Defaults.Exposed › Stats › Email authentication (SPF, DKIM, DMARC)
What percent of SPF records end in -all (hard fail)?
As of July 28, 2026 · census snapshot 2026-07-28
As of July 28, 2026, 39.2% of the 141,270,856 SPF records in the Defaults.Exposed census end in -all (hard fail) — 55,335,121 domains telling receivers to reject unauthorized senders outright.
| SPF terminal qualifier | Records |
|---|---|
| -all (hard fail) | 55,335,121 |
| ~all (soft fail) | 79,033,658 |
| ?all (neutral) | 4,339,914 |
| +all (allows anyone) | 36,262 |
| No terminal all (redirect/include-only) | 2,525,901 |
Cite this
Statistic current as of July 28, 2026. Recomputed from the live census each edition; the number on this page and the machine-readable twin always match. Please cite Defaults.Exposed and link this page.
Defaults.Exposed, "What percent of SPF records end in -all (hard fail)?" (as of July 28, 2026). https://defaults.exposed/stats/what-percent-of-spf-records-use-hard-fail
Permalink:https://defaults.exposed/stats/what-percent-of-spf-records-use-hard-fail · Machine-readable:spf-hardfail.json · Licence:open data
Methodology: how we grade the internet · Source data: defaults.exposed/data. Updated with each census edition.