Bullhorn, JobDiva, Loxo and the rest send on your behalf, using your name. Whether a receiving system accepts that is decided by records on your domain, and almost nobody checks them.
Send me your domainA candidate does not reply. A hiring manager goes quiet. You log it as a slow market, a flaky candidate, a client going cold.
Some of that is exactly what it looks like. Some of it is mail that never arrived, and there is no way to tell the two apart from where you sit. No bounce comes back. Nothing appears in a log. The only record of what happened sits with the receiving system, and unless your domain asks for it to be sent to you, it is discarded.
Your recruiters' own mail keeps working throughout, because it goes out on a different path. That is the part that makes this hard to notice. The stream that fails is the automated one: interview confirmations, application responses, everything your CRM sends with your name on it.
Email authentication is the only part of an IT estate that fails silently. A broken website is obvious in a minute. This can be wrong for years.
Two things from the screen. One is a domain that publishes three lists where the standard allows one. The other is why that fault shows up as candidates who did not turn up, rather than as an email problem.
$ dig +short TXT anagency.co.uk | grep spf1 "v=spf1 a mx include:_spf.elasticemail.com ~all" "v=spf1 include:_spf.bullhornmail.com ~all" "v=spf1 include:spf.protection.outlook.com -all"
It stops mail being sent from your exact domain. It does nothing about a lookalike domain, a WhatsApp message using a recruiter's name, or a fake advert posted somewhere with your branding on it. Every documented case of a UK agency being impersonated that I could find used one of those routes, not the domain. Anyone selling you this as fraud protection is overstating it.
It will not make a weak email get replies. If your mail is arriving and nobody is answering, this is not your problem and I will tell you so.
I cannot tell from outside whether your mail is currently landing in junk. Nobody can. What I can tell you, before you pay anything, is exactly what your domain publishes and whether it works.
More than 3 decades working as a Unix/Linux and infrastructure engineer, including building the call centre systems that took a UK answering service from nothing to over 5,000 calls a day.
I found this on my own domain first. I switched reporting on, and the first report showed somebody forging it from a host with no reverse DNS that is listed on Spamhaus. Three messages, and the policy at the time told every receiving system to do nothing about it. I do this work for a living and I could not see it until I looked.
You get the check whether or not you ever buy anything. Of the 314 I have looked at, 242 were fine and were told so.