Founder price · 100 spots leftReserve

[ Guide ]

Gmail, Yahoo and Outlook sender requirements, explained

What Gmail, Yahoo and Outlook.com require from senders in 2026: SPF, DKIM, DMARC, one-click unsubscribe and spam-rate limits, and who counts as bulk.

· 6 min read

[ In short ]

  • Every sender to Gmail and Yahoo needs SPF or DKIM, valid reverse DNS, TLS and a spam rate below 0.3%.
  • Bulk senders (about 5,000 messages a day to one provider) need SPF, DKIM and DMARC aligned with the From address; p=none is enough.
  • Marketing mail from bulk senders needs one-click unsubscribe (RFC 8058) and a visible link, honoured within 2 days.
  • Outlook.com rejects non-compliant high-volume mail since 5 May 2025 with 550 5.7.515; Gmail has rejected non-compliant mail since November 2025.

01The sender requirements in short

Since February 2024 Gmail and Yahoo require every sender to authenticate with SPF or DKIM, keep spam complaints under 0.3% and use valid DNS and TLS. Senders of about 5,000 or more messages a day must also publish DMARC, align it with the From address and offer one-click unsubscribe. Outlook.com added the same authentication bar for high-volume senders in May 2025.

RequirementGmailYahooOutlook.com
SPF or DKIM, all sendersRequiredRequired—
SPF and DKIM, bulkRequiredRequiredBoth must pass
DMARC, bulkp=none or stricter, alignedp=none or stricter, must passp=none or stricter, aligned
Reverse DNS (PTR)RequiredRequiredRecommended
TLSRequired——
One-click unsubscribe, bulk marketingRequiredRequiredRecommended
Honour unsubscribesWithin 48 hours (recommended)Within 2 daysRecommended
Spam rateBelow 0.3%, aim for 0.1%Below 0.3%List hygiene recommended
Bulk thresholdAbout 5,000 a day to GmailNot a fixed numberOver 5,000 a day to Outlook.com

A dash means the provider does not state it as a requirement on its sender page; it is still good practice. Each provider counts its own users only: 5,000 messages to Gmail users is what makes you a bulk sender at Gmail.

02Gmail’s requirements

All senders

  • SPF or DKIM for the sending domain.
  • Valid forward and reverse DNS (PTR) for the sending IPs.
  • TLS for the connection.
  • A spam rate in Postmaster Tools below 0.3%; Google recommends staying below 0.1%.
  • Messages formatted to RFC 5322, and no impersonation of Gmail From addresses.

Bulk senders

  • Google calls you a bulk sender if you send close to 5,000 messages or more to personal Gmail accounts in 24 hours. Messages from the same primary domain count together, subdomains included, and the status does not expire.
  • SPF and DKIM and DMARC, with the From domain aligned with the SPF or the DKIM domain. The DMARC policy can be none.
  • Marketing and subscribed messages need one-click unsubscribe and a visible unsubscribe link in the body. Transactional messages (receipts, password resets) are exempt.

From November 2025 Gmail “is ramping up its enforcement on non-compliant traffic”: failing messages now get temporary and permanent rejections, not only the spam folder.

03Yahoo’s requirements

Yahoo (which also runs AOL mail) asks the same of all senders, with two differences in the bulk rules.

  • All senders: SPF or DKIM at minimum, valid forward and reverse DNS, a spam complaint rate below 0.3%, and mail that follows RFC 5321 and RFC 5322.
  • Bulk senders: SPF and DKIM, and a valid DMARC policy of at least p=none that passes.
  • One-click unsubscribe and a clearly visible link, with unsubscribes processed within 2 days.
  • Yahoo’s sender page gives no fixed bulk number; if you send to many Yahoo users, follow the bulk rules.

04Microsoft Outlook.com’s 2025 rules

Microsoft announced in April 2025 that domains sending more than 5,000 messages a day to its consumer addresses (outlook.com, hotmail.com, live.com) must pass SPF, pass DKIM and publish DMARC of at least p=none, aligned with SPF or DKIM. It planned to route failures to Junk first, then changed course: from 5 May 2025, non-compliant messages are rejected.

Outlook.com rejection
550; 5.7.515 Access denied, sending domain [example.com] does not meet the required authentication level.
  • Recommended on top: a working unsubscribe link, removal of bounced and inactive addresses, and a From or Reply-To address that can receive replies.
  • These rules apply to Outlook.com consumer mailboxes. Microsoft 365 business tenants filter with their own settings, which usually reward the same setup.

05One-click unsubscribe (RFC 8058), done right

One-click unsubscribe lets the mail app show its own “Unsubscribe” button. It needs two headers on the message, and an HTTPS endpoint that accepts a POST with the body List-Unsubscribe=One-Click:

Headers
List-Unsubscribe: <https://example.com/unsubscribe/opaque-token>, <mailto:unsubscribe@example.com?subject=opaque-token>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
  • The POST must unsubscribe immediately: no login, no cookies, no confirmation page.
  • Do nothing on a GET to that URL. Security scanners open links in mail, and would unsubscribe people by accident.
  • Both headers must be covered by the message’s DKIM signature.
  • Keep a visible unsubscribe link in the body as well; the header does not replace it.

Leave these headers off person-to-person mail. A reply to a customer is not a list, and the headers mark it as bulk.

06Timeline: when each rule started

DateWhat changed
October 2023Google and Yahoo announce the new sender requirements
February 2024Gmail and Yahoo start enforcing them
April 2025Microsoft announces the same authentication bar for high-volume senders to Outlook.com
5 May 2025Outlook.com rejects non-compliant high-volume mail with 550 5.7.515
November 2025Gmail ramps up enforcement: non-compliant messages get temporary and permanent rejections

The direction is the same at every provider: authentication moved from best practice to a condition of delivery, and the grace periods are over. Expect the thresholds to tighten rather than loosen. A domain that passes SPF, DKIM and DMARC today, keeps complaints low and makes unsubscribing easy has nothing to change when they do.

07Do these rules apply to a small business?

The authentication rules for all senders apply to everyone, including a five-person company sending quotes and replies. Gmail rejects unauthenticated mail with 550 5.7.26 whatever your volume. The bulk rules apply when one domain sends about 5,000 messages a day to one provider, which a small team reaches mainly through newsletters, product notifications or a CRM sequence sent from the main domain.

The safe plan is to meet the bulk bar anyway. It costs a few DNS records, it protects you the day a campaign grows, and Gmail’s bulk status never expires once you have it.

  1. Publish one SPF record that covers every service sending as your domain.
  2. Turn on DKIM with your own domain in each of those services.
  3. Publish DMARC: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com.
  4. Check a sent message’s headers at Gmail for spf=pass, dkim=pass and dmarc=pass.
  5. Set up Google Postmaster Tools and look at the spam rate weekly.
  6. Send marketing from a subdomain or a separate service, with one-click unsubscribe.

The records in detail: SPF, DKIM and DMARC explained. The full list of habits that keep mail out of spam: email deliverability checklist.

Questions

What counts as a bulk sender for Gmail?
Any sender that sends close to 5,000 messages or more to personal Gmail accounts within 24 hours. Messages from the same primary domain count together, and once you are classified as a bulk sender the status does not expire.
Is DMARC p=none enough for Gmail and Yahoo?
Yes. Both accept p=none for bulk senders, as does Outlook.com. The DMARC check itself must pass, which means SPF or DKIM must pass for a domain aligned with your From address.
Do transactional emails need one-click unsubscribe?
No. Google says one-click unsubscribe is required only for marketing and promotional messages. Receipts, password resets and similar messages are excluded, though they still need authentication.
What does 550 5.7.515 mean?
Outlook.com rejected the message because the sending domain sends at high volume and does not meet its authentication requirements: SPF pass, DKIM pass, and DMARC of at least p=none aligned with one of them.
What spam rate does Gmail allow?
Gmail requires a spam rate below 0.3% as reported in Postmaster Tools and recommends keeping it below 0.1%. At 0.3% or more, senders lose eligibility for mitigation if they run into delivery problems.

See Skein follow up for you

Business email on your own domain with an agent that follows up on every conversation. Hosted in the EU. Try the demo with sample mail, nothing to install.

[ Sources ]

  1. 01Google: Email sender guidelines
  2. 02Google: Email sender guidelines FAQ
  3. 03Google Workspace: Gmail SMTP errors and codes
  4. 04Google: New Gmail protections for a safer, less spammy inbox (October 2023)
  5. 05Yahoo: Sender best practices
  6. 06Microsoft: Outlook’s new requirements for high-volume senders
  7. 07dmarcian: Microsoft’s May 2025 update to reject non-compliant mail
  8. 08RFC 8058: Signaling one-click functionality for list email headers
  9. 09RFC 9989: Domain-based Message Authentication, Reporting, and Conformance (DMARC)

Facts about other products were checked on 5 Oct 2026; prices and plans change.

[ Read next ]