Why SPF fails on forwarded mail
Forwarding rewrites the path but not the sender, so SPF sees the wrong IP. Understanding this stops you chasing a bug that is working as designed.
A user sets up a forward from their old address to a new mailbox. Mail you send arrives at the old server, which relays it onward from its own IP. The receiving server checks SPF for your domain against the forwarder's IP, does not find it, and fails the check. Nothing is misconfigured. SPF simply cannot survive a hop it does not know about.
What survives and what does not
- SPF breaks on forwarding, unless the forwarder rewrites the envelope sender.
- DKIM usually survives, because the signature travels with the message and covers headers and body rather than the path.
- DMARC therefore usually still passes on forwarded mail, on the strength of DKIM alone.
This is the single strongest argument for making sure DKIM is signing everything before you enforce a DMARC policy. A domain relying on SPF alone will lose forwarded mail the moment it reaches p=reject.
SRS and ARC
Well-behaved forwarders use Sender Rewriting Scheme, which replaces the envelope sender with one in the forwarder's own domain so SPF checks against a domain the forwarder controls. Authenticated Received Chain goes further: it records the authentication results at each hop so a later receiver can see the message passed before it was forwarded. Both are the forwarder's responsibility, not yours.
If aggregate reports show failures from an IP you do not recognise, resolve it before assuming abuse. Mailing lists, universities and alumni forwarding services account for most of the surprising entries.
More on SPF
What SPF actually does
SPF authorises servers, not messages, and it checks the envelope sender rather than the From address your recipient sees. That explains most SPF confusion.
Reading an SPF record, mechanism by mechanism
A walk through every mechanism and modifier you are likely to meet in a real SPF record.
The SPF ten-lookup limit, and how to stay under it
SPF evaluation is capped at ten DNS lookups. Exceed it and the result is permerror, which most receivers treat as a failure, including DMARC.