Yunes is an Operations Team Lead at PowerDMARC with expert knowledge in email authentication and security. Yunes is a Microsoft-certified Azure Administrator Associate with certifications in CompTIA A+ and many more.
Domain owners can configure multiple domains to make use of a single SPF record hosted on one domain using SPF redirect. While it may seem to be beneficial in some ways, we don’t recommend it.
Most mailbox providers in recent times read the SPF -all and ~all mechanisms as "NOT PASS". This was not the case before DMARC and is still not the case for a handful of providers.
Companies should properly designate the IP Addresses used to send out emails on their behalf as a permitted sender in the SPF Record to fix the "SPF softfail domain does not designate IP as permitted sender" error.