Short answer: Since February 2024, Gmail and Yahoo require bulk senders (for Gmail, anyone sending around 5,000 or more messages a day to personal Gmail addresses) to authenticate with SPF and DKIM, publish a DMARC record of at least p=none, align the From domain with SPF or DKIM, offer one-click unsubscribe in marketing mail and keep spam complaints below 0.3%. All senders, even small ones, need SPF or DKIM, valid reverse DNS, TLS and properly formatted messages. Microsoft announced similar rules for high-volume senders to Outlook.com in 2025.
Why the rules changed
For years, large mailbox providers published best practices that many senders ignored. Unauthenticated mail made it easy to impersonate brands, and unwanted marketing mail generated a steady flow of complaints. In late 2023, Google and Yahoo announced that the recommendations would become requirements, with enforcement starting in February 2024 and tightening over the following months. Non-compliant mail may be delayed, sent to spam or rejected.
The rules are not exotic. They codify what well-run senders were already doing. But they turned SPF, DKIM, DMARC and easy unsubscribing from “good hygiene” into a condition for reaching a large share of the world’s personal inboxes. The authoritative source is Google’s e-mail sender guidelines, which also include an FAQ; Yahoo publishes its own sender requirements with the same core points.
For businesses, the change has a useful side effect. The same records that satisfy the bulk sender rules also protect the domain from spoofing and make everyday business mail more trustworthy. A company that sends only a monthly newsletter but also relies on e-mail for quotes, invoices and support benefits from the work twice. It is also worth remembering that the threshold counts mail from every platform using your domain, so a business that feels “small” may cross it during a seasonal campaign or a product launch without anyone noticing.
Who counts as a bulk sender
Google defines a bulk sender as one that has sent close to 5,000 or more messages to personal Gmail accounts within a 24-hour period. A few details matter:
- The count is per primary domain. Mail from all subdomains and all platforms that use your domain in the From address adds up.
- Once you are classified as a bulk sender, the classification does not expire, according to Google’s guidance. One large campaign is enough.
- Personal accounts only. Mail to Google Workspace business accounts does not count toward the threshold, although good practice still applies there.
Yahoo does not publish an exact number in the same way, but applies similar expectations to senders with significant volume. The safe assumption for any business with a newsletter is that the bulk rules apply, or will once the list grows.
Requirements for all senders
These apply to everyone sending to Gmail, regardless of volume:
- SPF or DKIM for the sending domain.
- Valid forward and reverse DNS for sending IP addresses: the IP must have a PTR record pointing to a host name that resolves back to the same IP. Hosted providers take care of this; self-hosted servers often do not.
- TLS for the connection that transmits the mail.
- Spam rate reported in Postmaster Tools below 0.3%, with Google recommending staying below 0.1%.
- Messages formatted according to the internet message standard (RFC 5322), with valid headers.
- No impersonation of Gmail From addresses. You must not send with a
@gmail.comFrom address through your own platform; Gmail publishes a DMARC quarantine policy for its own domain. - ARC headers for forwarders and mailing lists that regularly forward mail, so receivers can see the original authentication results.
Additional requirements for bulk senders
- Both SPF and DKIM for the sending domain.
- A DMARC record for the sending domain. The policy can be
p=none; enforcement is recommended but not required. - DMARC alignment: the domain in the From header must align with the SPF domain or the DKIM domain. Passing SPF and DKIM for a platform’s domain is not enough.
- One-click unsubscribe for marketing and subscribed messages, using the
List-UnsubscribeandList-Unsubscribe-Postheaders described in RFC 8058, plus a clearly visible unsubscribe link in the message body. - Unsubscribe requests processed within two days.
- Spam rate below 0.3%, as for all senders, but with more at stake because of volume.
One-click unsubscribe applies to promotional and subscription mail. Transactional messages, such as password resets and order confirmations, are not expected to carry it, although they still need authentication.
Microsoft’s requirements for Outlook.com
In 2025 Microsoft announced comparable rules for domains sending more than 5,000 messages a day to Outlook.com, Hotmail.com and Live.com addresses: SPF, DKIM and a DMARC record of at least p=none, aligned with SPF or DKIM. Microsoft also listed recommended practices such as working unsubscribe links, list hygiene and a valid reply address. Non-compliant mail was to be routed to junk at first, with rejection to follow. For practical purposes, if you meet Google’s bulk requirements you also meet Microsoft’s core ones.
A compliance checklist you can work through
| Requirement | How to verify |
|---|---|
| SPF passes for each platform | spf=pass in the Authentication-Results header of a test message |
| DKIM passes with your domain | dkim=pass header.d=yourdomain.com (or your subdomain) |
| DMARC record published | TXT record at _dmarc.yourdomain.com starting with v=DMARC1 |
| DMARC passes | dmarc=pass in headers; DMARC aggregate reports |
| Reverse DNS valid | PTR lookup of the sending IP, then forward lookup of the returned name |
| TLS used | Gmail shows a closed padlock for the message; headers show TLS in the Received line |
| One-click unsubscribe | Both List-Unsubscribe headers present; unsubscribe link visible in the body |
| Unsubscribes honoured within 2 days | Test yourself: unsubscribe and confirm no further campaigns arrive |
| Spam rate under 0.3% (ideally 0.1%) | Google Postmaster Tools for your domain |
Run through the list for each platform that sends with your domain: the newsletter tool, the e-commerce platform, the CRM, the helpdesk. The most common gap is a secondary tool that still signs with its vendor’s domain.
Common gaps in small and mid-sized businesses
- DMARC exists but only on paper. A record was added, but nobody reads the reports, so unaligned platforms stay unaligned.
- The newsletter platform is authenticated, the shop is not. Order and shipping notifications go out from the web server or the shop platform without aligned DKIM.
- Unsubscribe works only after login. Requiring a password or a multi-step preference centre does not meet the one-click expectation.
- Old lists imported into a new tool. A campaign to contacts who have not heard from you in years causes a spike in complaints, and the spam rate crosses the line in a single day.
- Self-hosted servers without PTR records. A server set up years ago by a contractor may never have had reverse DNS configured.
What happens if you do not comply
Enforcement has been gradual. Google described starting with temporary errors for a small share of non-compliant traffic and increasing the share over time, and has continued to tighten enforcement since. In practice, non-compliant senders see more mail deferred, filtered to spam or rejected with error codes that point to the missing requirement, such as a message saying the sender is unauthenticated or that the DMARC policy is missing. High spam rates also make a sender ineligible for mitigation if something goes wrong.
Because the rules are enforced per domain and messages are evaluated individually, one non-compliant tool can suffer while the rest of your mail is fine. That makes the problem easy to miss if you only test from your main mailbox.
Checking the DNS side quickly
The authentication part of the requirements is visible from outside. Site AI Audit checks SPF and its lookup limit, DKIM, the DMARC policy and MX records for a domain, and reports missing or broken records with the concrete fix. List practices, unsubscribe handling and spam rates are not visible from DNS, so you still need your sending platform and Postmaster Tools for those. Start with a free domain check, and see the plans if you want the checks repeated and an alert when something breaks.
Related reading
- DMARC Explained: Policies, Alignment and a Safe Rollout
- SPF vs DKIM vs DMARC: What Each One Does and Why You Need All
- Why Are My Emails Going to Spam? 12 Causes and Fixes
The bottom line
The bulk sender rules boil down to four things: authenticate with SPF and DKIM, publish DMARC and align your From domain, make unsubscribing a single click, and keep complaints very low. Check each platform that sends with your domain, not only your main mailbox. Meeting the rules does not guarantee the inbox, but failing them now reliably keeps you out.
FAQ
Do the Gmail requirements apply if I send fewer than 5,000 e-mails a day?
The basic requirements apply to everyone: SPF or DKIM, valid reverse DNS, TLS, proper formatting and a low spam rate. The stricter bulk rules, including DMARC and one-click unsubscribe, apply once you reach the bulk threshold, but meeting them early is sensible.
Is p=none enough for the DMARC requirement?
Yes, Google and Yahoo accept p=none for the bulk sender requirement. It gives no protection against spoofing, though, so moving to quarantine or reject after reviewing reports is recommended.
Do transactional e-mails need one-click unsubscribe?
No. The one-click requirement covers marketing and subscribed messages. Transactional mail such as receipts and password resets still needs authentication and alignment.
How do I see my spam rate in Gmail?
Verify your domain in Google Postmaster Tools. Once you send enough volume to Gmail users, it shows the user-reported spam rate, domain reputation and authentication results. Small senders may not have enough volume for data to appear.
Does the bulk sender status reset if my volume drops?
According to Google’s guidance, no. Once a domain has been classified as a bulk sender, it keeps that classification, so the stricter requirements continue to apply.



