Bulk Sender Requirements for Gmail, Yahoo and Outlook.com
Since February 2024, Gmail and Yahoo have required bulk senders to authenticate with both SPF and DKIM, publish a DMARC policy (p=none is enough) that passes with an aligned From domain, support one-click unsubscribe and keep spam complaint rates below 0.3%. Gmail defines a bulk sender as one that sends close to 5,000 or more messages a day to personal Gmail accounts.
Microsoft applied similar SPF, DKIM and DMARC requirements to Outlook.com, Hotmail and Live.com addresses starting May 5, 2025, for domains that send more than 5,000 messages a day.
By Stephen Williams · Updated
Requirements at a glance
| Requirement | Gmail | Yahoo | Outlook.com |
|---|---|---|---|
| Who it applies to | Close to 5,000+ messages a day to personal Gmail accounts | Bulk senders (Yahoo publishes no numeric threshold) | Domains sending 5,000+ messages to Microsoft consumer addresses |
| Effective | February 2024; enforcement ramping up since November 2025 | February 2024, phased in | May 5, 2025 |
| SPF | Required | Required | Must pass |
| DKIM | Required (key of 1,024 bits or longer; 2,048 recommended) | Required | Must pass |
| DMARC | Record required; p=none is the minimum; From domain must align with SPF or DKIM | p=none minimum; must pass; relaxed alignment accepted | Record required (p=none minimum); must pass with SPF and/or DKIM aligned to the From domain |
| One-click unsubscribe | Required for marketing and subscribed messages, plus a visible unsubscribe link | Required (RFC 8058 POST recommended, mailto accepted); honor within 2 days | Recommended: a functional unsubscribe link |
| Spam complaint rate | Below 0.3%; Google advises staying below 0.1% | Below 0.3% | No published threshold |
| Infrastructure | Valid forward and reverse DNS (PTR), TLS, RFC 5322 formatting | Valid forward and reverse DNS, RFC 5321/5322 compliance | Not specified beyond authentication |
Gmail (Google)
Google's sender guidelines took effect on February 1, 2024. Every sender must set up SPF or DKIM, have valid forward and reverse DNS records for sending IPs, use TLS, follow RFC 5322 formatting and keep the spam rate reported in Postmaster Tools below 0.3%.
Bulk senders must additionally:
- Set up both SPF and DKIM, with a DKIM key of 1,024 bits or longer (Google recommends 2,048).
- Publish a DMARC record. The policy can be
p=none. - Align the From domain with either the SPF domain or the DKIM domain for direct mail. Only one needs to align, though Google recommends aligning both.
- Support one-click unsubscribe for marketing and subscribed messages and include a visible unsubscribe link in the body. Google recommends processing unsubscribe requests within 48 hours.
- Keep the user-reported spam rate below 0.3%, ideally below 0.1%.
Google counts messages sent to personal Gmail accounts in a 24-hour period, including mail from subdomains of the same primary domain, and bulk sender status doesn't expire. Since November 2025 Gmail has been ramping up enforcement, returning temporary (4.7.x) or permanent (5.7.x) errors for some non-compliant traffic.
Yahoo
Yahoo's requirements also began in February 2024 and were rolled out gradually. All senders must authenticate with SPF or DKIM, keep spam complaints below 0.3%, have valid forward and reverse DNS, and comply with RFC 5321 and RFC 5322. Bulk senders must:
- Implement both SPF and DKIM.
- Publish a DMARC policy of at least
p=nonethat passes; Yahoo strongly recommends aruatag for reports. - Align the From domain with the SPF or DKIM domain (relaxed alignment is fine).
- Support one-click unsubscribe via the List-Unsubscribe header (the RFC 8058 POST method is highly recommended; mailto is acceptable), show a visible unsubscribe link, and honor unsubscribes within 2 days.
- Keep spam rates below 0.3%, calculated on mail delivered to the inbox.
Outlook.com (Microsoft)
Microsoft announced requirements for high-volume senders to its consumer services (Outlook.com, Hotmail, Live.com and MSN addresses) with enforcement starting May 5, 2025. Once a domain sends 5,000 or more messages to these services, with the same domain in the From address, its mail must:
- Pass SPF, with the domain's SPF record listing its authorized sending IPs and hosts.
- Pass DKIM.
- Pass DMARC: publish a record with at least
p=none, and have SPF and/or DKIM align with the From domain.
Non-compliant messages may be filtered to Junk or rejected with the error 550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level. Microsoft's announcement also recommends, without requiring, valid From and Reply-To addresses that can receive replies, functional unsubscribe links, list hygiene and bounce management, and transparent mailing practices.
Compliance checklist
- SPF: one SPF record listing every service that sends as your domain, within the 10-DNS-lookup limit. Build it with the SPF record generator and test it with the SPF checker.
- DKIM: turn on DKIM signing with your own domain in every sending platform (not the platform's default domain), using 2,048-bit keys where supported. Verify with the DKIM checker.
- DMARC: publish at least
v=DMARC1; p=none; rua=mailto:...and confirm messages pass with alignment. Use the DMARC record generator and DMARC checker, then follow the rollout guide to reach enforcement. - Unsubscribe: add List-Unsubscribe and List-Unsubscribe-Post headers to marketing mail, keep a visible unsubscribe link, and process requests within 2 days.
- Complaints: monitor Google Postmaster Tools and keep the spam rate well under 0.3%.
- Infrastructure: sending IPs with matching forward and reverse DNS, and TLS for SMTP connections. Hosted email platforms usually handle this for you.
One-click unsubscribe headers (RFC 8058)
One-click unsubscribe uses two headers. The HTTPS URL must accept a POST request and unsubscribe the recipient without further steps, and both headers must be covered by your DKIM signature.
List-Unsubscribe: <https://example.com/unsubscribe/opaque-token>, <mailto:unsubscribe@example.com?subject=unsubscribe>
List-Unsubscribe-Post: List-Unsubscribe=One-ClickMost email service providers add these headers automatically for marketing sends; check a delivered message's headers to confirm.
Sources
- Google: Email sender guidelines
- Google: Email sender guidelines FAQ
- Yahoo Sender Hub: Sender best practices
- Microsoft Tech Community: Outlook's new requirements for high-volume senders
- Microsoft Support: Fix NDR error 550 5.7.515 in Outlook.com
- RFC 8058: Signaling One-Click Functionality for List Email Headers
Frequently asked questions
Do these rules apply if I send fewer than 5,000 emails a day?
Partly. Gmail and Yahoo apply a baseline to all senders: authenticate with SPF or DKIM, have valid forward and reverse DNS for sending IPs, follow the email format standards and keep spam complaints below 0.3%. The extra bulk-sender rules (both SPF and DKIM, DMARC, one-click unsubscribe) kick in at volume, but meeting them anyway is good practice.
Does DMARC p=none satisfy the requirement?
Yes. All three providers accept p=none as the minimum policy, as long as messages pass DMARC, which means SPF or DKIM must pass for a domain that aligns with the From address. p=none doesn't stop spoofing of your domain, so plan to move to quarantine or reject.
How does Gmail count the 5,000 messages?
Google counts messages sent to personal Gmail accounts within a 24-hour period, and messages from subdomains count toward the same primary domain. Once a domain is classified as a bulk sender, the status doesn't expire.
Do I need one-click unsubscribe on transactional email?
No. Google and Yahoo require one-click unsubscribe for marketing and subscribed messages, not for transactional messages such as password resets or receipts.
What happens if I don't comply?
Gmail returns temporary or permanent errors for some non-compliant traffic and has been ramping up enforcement since November 2025. Outlook.com can reject mail from non-compliant high-volume domains with the error 550 5.7.515. In every case, deliverability to the inbox suffers.