Gmail, Yahoo and Microsoft sender requirements

What Gmail, Yahoo and Outlook require of senders: SPF, DKIM, DMARC, alignment, one-click unsubscribe and spam-rate limits, who they apply to and how to comply.

Updated September 30, 2026

As of September 2026, Gmail and Yahoo require every sender to authenticate with SPF or DKIM, and bulk senders (about 5,000+ messages a day to Gmail) to use SPF and DKIM, publish DMARC (p=none is enough) with the From domain aligned, offer one-click unsubscribe on marketing mail and keep the spam complaint rate under 0.3%. Microsoft applies similar authentication rules to domains sending over 5,000 messages a day to Outlook.com, Hotmail and Live addresses, and has rejected non-compliant mail with error 550 5.7.515 since May 5, 2025.

Timeline: how the rules arrived

DateWhat happened
October 2023Google and Yahoo announce new requirements for senders to their consumer mailboxes.
February 1, 2024Gmail’s requirements take effect; Yahoo begins enforcement and rolls it out gradually.
June 2024One-click unsubscribe is enforced for marketing mail (Gmail deadline June 1, 2024; Yahoo from June 2024). Gmail bulk senders with a spam rate above 0.3% become ineligible for delivery mitigation.
April 2, 2025Microsoft announces requirements for high-volume senders to Outlook.com consumer addresses.
May 5, 2025Microsoft enforcement begins. An April 29 update changed the action from Junk-foldering to rejection with 550 5.7.515.
November 2025Gmail “ramps up” enforcement: non-compliant messages face disruptions, including temporary and permanent rejections.

These rules apply to mail sent to consumer mailboxes: personal Gmail accounts, Yahoo Mail, and Outlook.com, Hotmail and Live. Google states that its sender guidelines don’t apply to mail sent to Google Workspace accounts, though Workspace users sending to personal Gmail accounts must meet them.

Gmail vs Yahoo vs Microsoft requirements compared

As of September 2026
RequirementGmailYahooMicrosoft (Outlook.com)
Who counts as bulk~5,000+ messages in 24 hours to personal Gmail, counted per primary domain; status is permanentNo threshold published (“a significant volume”)Domains sending over 5,000 messages a day
SPF or DKIM (all senders)RequiredRequiredNot specified below 5,000/day
SPF and DKIM (bulk)Both requiredBoth requiredBoth must pass
DMARC (bulk)Required, p=none allowedRequired, p=none allowed; DMARC must passRequired, at least p=none
From alignment (bulk)With SPF or DKIM domainWith SPF or DKIM domainWith SPF or DKIM (preferably both)
One-click unsubscribeMarketing and subscribed mail, plus a visible link in the body; honor within 48 hoursMarketing mail, RFC 8058 POST “highly recommended”; honor within 2 daysRecommended: a functional, visible unsubscribe link
Spam complaint rateBelow 0.3% in Postmaster Tools; aim for below 0.1%Below 0.3%No number published
Forward and reverse DNS (PTR)RequiredRequiredNot listed
TLSRequiredNot listedNot listed
Message formatRFC 5322RFC 5321 and 5322Recommended: accurate subjects, no deceptive headers
What happens if you don’t complyTemporary (4.7.x) or permanent (5.7.x) errors, spam foldering, loss of mitigation supportDeferrals or filtering; enforcement rolled out graduallyRejected with 550 5.7.515

What every sender needs, even at low volume

Google’s list for all senders to personal Gmail accounts, which Yahoo largely mirrors:

  • SPF or DKIM for your sending domain. In practice, set up both: see SPF and DKIM. Gmail requires DKIM keys of at least 1024 bits and recommends 2048.
  • Valid forward and reverse DNS for sending IPs: the IP’s PTR record names a host that resolves back to the same IP. Your email provider handles this for its own IPs.
  • TLS for the SMTP connection (Gmail).
  • Spam rate below 0.3% as reported in Google Postmaster Tools.
  • Standards-compliant messages (RFC 5322 formatting), and no sending with a @gmail.com From address from servers other than Gmail’s.

What bulk senders need on top

  • SPF and DKIM both, not one or the other.
  • A DMARC record with at least p=none. Yahoo adds that DMARC must pass.
  • Alignment: the From domain must match the SPF domain or the DKIM signing domain. A vendor sending with its own bounce domain and its own DKIM domain doesn’t count, even if both pass. DMARC alignment explains the rule and why DMARC fails covers the usual fixes.
  • One-click unsubscribe for marketing and subscribed messages (not transactional mail such as receipts or password resets), using the RFC 8058 headers, plus a clearly visible unsubscribe link in the body. Process unsubscribes within 48 hours (Gmail) or 2 days (Yahoo).
  • Spam rate below 0.3%, and ideally below 0.1%. Google calculates it daily and says senders should never let it reach 0.3%.
One-click unsubscribe headers (RFC 8058)
List-Unsubscribe: <https://example.com/unsubscribe/opaque-token>, <mailto:unsubscribe@example.com?subject=unsubscribe>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

The HTTPS URL must accept a POST and unsubscribe the recipient without further steps. The headers must be covered by your DKIM signature. Most email service providers add them for you once list unsubscribe is turned on.

Microsoft Outlook.com requirements for high-volume senders

Microsoft’s rules cover Outlook.com, its consumer service for outlook.com, hotmail.com and live.com addresses, and apply to domains sending more than 5,000 messages a day. SPF must pass for the sending domain, DKIM must pass, and DMARC must be published at p=none or stricter and align with SPF or DKIM, preferably both. Microsoft first said non-compliant mail would go to Junk, then updated its announcement on April 29, 2025: from May 5, 2025, such mail is rejected with:

Outlook.com rejection for non-compliant high-volume senders
550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.

Microsoft also recommends, without hard thresholds: a valid From or Reply-To address that can receive replies, a functional unsubscribe link, regular list hygiene and bounce removal, and transparent practices (accurate subjects, no deceptive headers, recipient consent).

How Gmail enforces the rules now

Since November 2025, Gmail answers non-compliant bulk mail with SMTP errors that name the requirement you missed. Temporary errors (4.7.x) rate-limit the mail; permanent errors (5.7.x) block it. Examples from Google’s FAQ:

CodeMeaning
4.7.23 / 5.7.25Sending IP has no PTR record, or it doesn’t resolve back to the IP
4.7.27 / 5.7.27SPF didn’t pass
4.7.29 / 5.7.29Not sent over TLS
4.7.30 / 5.7.30DKIM didn’t pass
4.7.31No DMARC record, or the record has no policy
4.7.32From domain not aligned with the SPF or DKIM domain
5.7.26Message not authenticated

Missing one-click unsubscribe, unsubscribes not honored within 48 hours and a spam rate above 0.3% don’t trigger their own codes; they make you ineligible for Google’s delivery support and mitigation. Postmaster Tools has a compliance status dashboard that shows which requirements your domain meets.

Check your domain against the requirements

See whether your domain has SPF, DKIM and a DMARC policy, with the exact fixes for anything missing.

Sender requirements compliance checklist

  1. SPF record published, one record only, 10 or fewer DNS lookups (SPF checker).
  2. DKIM signing with your own domain on every platform that sends as you, 2048-bit where supported (DKIM checker).
  3. DMARC record at _dmarc.yourdomain with at least p=none and a rua address (DMARC record generator).
  4. Every sender aligned: DMARC reports show SPF or DKIM passing for your domain, not the vendor’s (DMARC report analyzer).
  5. Sending IPs have matching forward and reverse DNS; connections use TLS.
  6. Marketing mail carries List-Unsubscribe and List-Unsubscribe-Post headers and a visible link; unsubscribes are processed within 48 hours.
  7. Google Postmaster Tools set up for your domain; spam rate below 0.1%, never reaching 0.3%.
  8. Lists cleaned of bounces and inactive addresses; only mail people asked for.

p=none satisfies the rules, but it doesn’t stop anyone spoofing your domain. Once your senders are aligned, move to p=reject. DMARC Dojo hosts your DMARC, SPF and DKIM records and reads every aggregate report, so you can see which senders still fail alignment before a mailbox provider rejects them.

Frequently asked questions

Do the Gmail and Yahoo rules apply if I send fewer than 5,000 emails a day?

Partly. Every sender needs SPF or DKIM, valid reverse DNS and a spam rate below 0.3%. The DMARC, alignment and one-click unsubscribe rules are for bulk senders, but meeting them anyway improves delivery.

Is p=none enough to meet the requirements?

Yes. Gmail, Yahoo and Microsoft all accept a DMARC policy of p=none, as long as your mail passes with alignment (Yahoo says DMARC must pass). p=none doesn’t protect your domain from spoofing, though.

Do transactional emails need an unsubscribe link?

No. One-click unsubscribe applies to marketing and subscribed messages. Receipts, password resets and account alerts are exempt, but they still need authentication.

How do I see my Gmail spam rate?

Verify your domain in Google Postmaster Tools. It shows the user-reported spam rate for your mail and a compliance status view for the sender requirements.

What does 550 5.7.515 mean?

It’s Outlook.com rejecting mail from a high-volume domain that doesn’t meet Microsoft’s authentication requirements: SPF and DKIM passing, and a DMARC record of at least p=none that aligns.