Google, Yahoo and Microsoft sender requirements explained
What Gmail, Yahoo and Outlook.com require from email senders: SPF, DKIM, DMARC, alignment, unsubscribe and spam rates, with the errors you'll see.
By Doug Hall · Updated
- All three providers expect authenticated email; bulk senders (around 5,000 a day to their users) must have SPF, DKIM and DMARC.
- DMARC at p=none is enough to meet the rules, but the From domain must align with SPF or DKIM.
- Google is enforcing with rejections since November 2025, and Microsoft rejects non-compliant bulk mail with 550 5.7.515.
Who the rules apply to
In February 2024 Google and Yahoo started enforcing minimum standards for email sent to their users. Microsoft followed for Outlook.com, Hotmail and Live addresses in May 2025. Each splits senders into two groups:
- Everyone. Basic authentication, a properly configured sending server and a low spam complaint rate.
- Bulk senders. Google defines them as sending close to 5,000 messages or more to personal Gmail accounts within 24 hours. Microsoft uses 5,000 or more messages to its consumer services from the same From domain. Yahoo's page doesn't give a number.
The count is per domain and includes everything sent as it: the client's own mailboxes, their newsletter tool, their invoicing system and their booking software. A small business with a 6,000-address mailing list is a bulk sender on the day it sends a newsletter, and Google's FAQ says that status has no expiry date.
The checklist, provider by provider
This is the combined list from each provider's own page, checked on 7 October 2026: Google's sender guidelines, Yahoo's sender best practices and Microsoft's note on error 550 5.7.515. "Bulk" means the rule applies to bulk senders only.
| Requirement | Gmail | Yahoo | Outlook.com |
|---|---|---|---|
| SPF or DKIM | Everyone | Everyone | Not stated for small senders |
| Both SPF and DKIM | Bulk | Bulk | Bulk (both must pass) |
| DMARC record, p=none or stricter | Bulk | Bulk | Bulk |
| From domain aligned with SPF or DKIM | Bulk | Bulk | Bulk |
| Valid forward and reverse DNS for sending IPs | Everyone | Everyone | Not stated |
| TLS for sending | Everyone | Not stated | Not stated |
| Spam rate below 0.3% | Everyone (bulk aim below 0.1%) | Everyone | Not stated |
| One-click unsubscribe on marketing mail | Bulk | Bulk | Recommended |
| Honour unsubscribes within 2 days | Bulk | Bulk | Recommended |
Microsoft's published requirement is about authentication. It also recommends a working unsubscribe link, list hygiene and a From or Reply-To address that can receive replies, which is good practice everywhere.
On timing: Google's FAQ says it began "ramping up" enforcement in November 2025, with temporary and permanent rejections for mail that doesn't meet the rules. Microsoft's announcement originally said non-compliant bulk mail would go to Junk from 5 May 2025; it then changed that to outright rejection, from the same date.
The DNS records you need
Three records, all published in the domain's DNS:
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net -all
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
v=DMARC1; p=none; rua=mailto:dmarc@example.co.uk
SPF lists the services allowed to send, and has a hard limit of 10 DNS lookups (see SPF and the 10-lookup limit). DKIM is set up separately for each sending service; each gives you its own selector and record, and the exact form varies by provider (the DKIM record above shows the general shape only). DMARC ties them together and asks for reports. The DMARC record generator writes a correct record if you're starting from nothing.
Alignment: the part people miss
Having SPF and DKIM isn't enough for bulk senders. DMARC needs at least one of them to pass for the same domain as the From address. That match is called alignment, and it's where most failures come from.
A typical case: a newsletter tool sends as news@example.co.uk, but signs the message with its own DKIM key (d=mailtool.com) and uses its own bounce address (so SPF passes for mailtool.com). SPF passes and DKIM passes, but neither is for example.co.uk, so DMARC fails. To Gmail that's unauthenticated bulk mail.
The fix is nearly always DKIM: most sending services let you add a DKIM record for your own domain, so they sign as you. Some also support a custom bounce domain, which aligns SPF. Alignment can be relaxed (a subdomain such as mail.example.co.uk counts) or strict (exact match only); relaxed is the default and what you want.
One-click unsubscribe
For marketing and subscribed messages, Gmail and Yahoo require one-click unsubscribe as defined in RFC 8058. It's two headers, not a link in the footer (though you need that too):
List-Unsubscribe: <https://example.co.uk/unsubscribe?u=8f2c> List-Unsubscribe-Post: List-Unsubscribe=One-Click
RFC 8058 says the message must carry a valid DKIM signature that covers both headers. Any mainstream newsletter platform adds them for you. Where it bites is home-made sending: a WordPress plugin or a CRM that sends campaigns through an ordinary mailbox. Transactional email such as receipts and password resets doesn't need it.
What a rejection looks like
When mail falls short, the sender gets a bounce. These are the codes to look for, from Google's SMTP error reference and Microsoft's page:
| Code | Provider | Meaning |
|---|---|---|
| 550 5.7.26 | Gmail | Unauthenticated: no SPF or DKIM pass, or the domain's DMARC policy failed |
| 421 4.7.27 / 550 5.7.27 | Gmail | SPF didn't pass (rate limited, or blocked) |
| 421 4.7.30 / 550 5.7.30 | Gmail | DKIM didn't pass (rate limited, or blocked) |
| 451 4.7.23 / 550 5.7.25 | Gmail | No PTR (reverse DNS) record for the sending IP, or it doesn't match |
| 421 4.7.29 / 550 5.7.29 | Gmail | Not sent over TLS |
| 550 5.7.515 | Outlook.com | Sending domain doesn't meet the required authentication level |
A 4xx code is temporary: the sending server will retry, and the mail may get through late. A 5xx code is final. If a client says "some of our emails to Gmail bounce", ask for the bounce message: the code tells you which record to fix.
How to test a domain in five minutes
- Run the sender requirements checker on the domain. It reads the public SPF, DKIM and DMARC records and marks each rule.
- Send a real email from each service the client uses (their mailbox, the newsletter tool, the invoicing system) to our free email test. It shows whether SPF, DKIM and DMARC passed for that message and whether they aligned, which you can't see from DNS alone.
- If you have a bounce message or a received email's headers, paste them into the email header analyser.
- Check the spam rate in Google Postmaster Tools. It's the one number nobody can see from outside.
If the domain has no DMARC record at all, fix that first; see how to add a DMARC record. Then publish reports to an address someone reads, because the reports are how you find the senders you didn't know about.
When a client's newsletter tool isn't aligned
This is the most common real-world failure. The client's main mailboxes pass, but the newsletter, the CRM or the booking system sends as their domain without aligned DKIM. What to do:
- Find the domain authentication setting in the tool. It's usually called "authenticate your domain", "custom DKIM" or "sender authentication", and gives you one to three DNS records to add.
- Add the records and press the tool's verify button. DNS can take a little while to update.
- Send a test to the email test and confirm DKIM now passes for the client's own domain.
- If the tool can't sign as the client's domain, send its mail from a subdomain it can authenticate, or move to a tool that can. Don't paper over it by adding more includes to SPF: that doesn't fix alignment, and it uses up lookups.
The rules don't ask for p=reject, but once every sender passes, moving there is what actually stops other people sending as the client. The DMARC guide explains the steps, and how to read a DMARC report shows you how to spot a sender that's failing.
Doing this for clients? Domain Health Hub checks every client domain each day and puts the results in a monthly report card with your logo. Start a free trial; no card needed.
Questions
Do the rules apply to email sent to Google Workspace or Microsoft 365 business mailboxes?
Google's rules are for mail to personal Gmail accounts, and Microsoft's are for its consumer services (Outlook.com, Hotmail and Live). Business mailboxes are filtered by their own settings, but the same records help there too.
We send far fewer than 5,000 emails a day. Can we ignore this?
Not entirely. Gmail and Yahoo ask every sender for SPF or DKIM, valid reverse DNS and a low spam rate. And a newsletter to a big list can cross the line in a single afternoon.
Does p=none really count?
Yes, for these rules. But p=none doesn't stop anyone spoofing the domain. Treat it as the starting point, not the finish.
Is a bulk sender always a bulk sender?
At Google, yes: its FAQ says bulk sender status doesn't expire. Once a domain has crossed the line, keep it compliant.
Watch every client's domains, every day.
Reports read for you, and a monthly report card your clients will understand.