We generally run on Microsoft 365 and use SendGrid for transactional emails such as password resets.
Main domain has SPF set up correctly as per MS docs.
We have the CNAME set up for a like em1234 sub-domain as per SendGrid’s docs which their docs say should cover SPF even if the emails we send have a from address of our main domain (eg [email protected]), this is apparently because receiving servers are supposed to do SPF checks against the replyTo address which sendgrid does populate with an address on the subdomain.
This has worked fine for years, Gmail for example is happy and looking at mails from us says everything passes.
However, we recently onboarded a large corporate whose server was blocking the SendGrid emails because it was checking the SPF against the from header rather than the replyTo.
Only way to let the email through was to either add SendGrid SPF records to our main domain, or change the from address of the SendGrid emails, neither of which was 100% ideal.
Not going to try tell the client they’ve configured their server wrong, but have they?
No, they haven’t. With your current config sounds like you are failing SPF alignment. Is your SPF record in strict mode? Do you have DMARC set up and are you DKIM signing the SendGrid emails from your domain?
SPF doesn't check the reply-to address, only that the host sending the mail is allowed to send mail for the domain in the MAIL FROM: header.
See: http://www.open-spf.org/FAQ/What_it_does/
Edit: for those unfamiliar with the intricacies of SMTP, the first three lines sent are HELO, MAIL FROM:, and RCPT TO:. The From: address that you see in your mail client is actually another header that gets sent once the server provisionally accepts the message based on the first three headers. It's the difference between the return address on the envelope of a paper letter, and an address printed on the letterhead of the actual letter.