Reading an SPF fail as a broken SPF record
The commonest misreading, and it sends people to edit DNS that is already correct. If the raw SPF result is pass and the alignment result is fail, SPF worked: it authenticated the envelope domain, which belongs to the platform sending for you. The fix is a custom return path on your own domain, or DKIM alignment. Nothing you add to your SPF record changes it.