Yes, SPF on fail should prevent people from using other mail servers besides the ones authorized on the SPF record. Clients ISP SMTP servers included, but you can always suggest they use mail.theirdomain.com ..and if their ISP blocks port 25 (as many do), they can use port 587 as an alternative...