Google & Microsoft bulk sender requirements, explained

Since 2024, the major mailbox providers require authentication for anyone sending volume. It's no longer a best practice; it's a delivery gate. If you send newsletters, notifications or campaigns, here's what you have to have in place.

What changed

Gmail and Yahoo rolled out shared sender requirements in 2024, with Microsoft following for Outlook/Hotmail. The shift: authentication and good sending hygiene moved from "recommended" to required for delivery. Fail them and your mail is rejected or filtered — regardless of content.

The core requirements

  • SPF and DKIM set up and passing for your sending domain.
  • DMARC published with a valid policy and proper alignment between the authenticated domain and your visible From.
  • One-click unsubscribe (RFC 8058) on bulk/marketing mail, honored promptly.
  • Low spam complaint rate — under 0.3%, ideally below 0.1%.
  • Valid forward and reverse DNS (PTR) on sending IPs, and mail sent over TLS.

Who counts as a "bulk sender"

The widely-cited line is roughly 5,000+ messages per day to Gmail, with comparable expectations elsewhere. But the authentication basics now apply broadly — the bulk threshold mainly adds the one-click unsubscribe rule and harder enforcement. If you run any newsletter or campaign program, assume the rules apply to you.

How to comply

  1. Confirm SPF and DKIM pass and align for every sending service.
  2. Publish DMARC and start moving it toward enforcement.
  3. Add compliant one-click unsubscribe to bulk mail.
  4. Tighten list hygiene to keep complaints under threshold.
  5. Monitor DMARC reports so a future change doesn't quietly break compliance.

Why it keeps slipping

Compliance isn't a one-time checkbox. Every new marketing tool, vendor or domain can re-break alignment or push your SPF over its limit — which is why the requirement is really an ongoing operational task, not a project you finish.

Frequently asked questions

Who has to comply with the bulk sender requirements?

The headline threshold is senders delivering roughly 5,000+ messages a day to Gmail accounts, with similar expectations at Yahoo and Microsoft. But the core requirements — SPF, DKIM and DMARC — are now effectively expected of all senders; the bulk threshold just adds one-click unsubscribe and stricter enforcement.

What DMARC policy do I need for bulk sending?

At minimum a published DMARC record (a valid policy, even p=none, with alignment) is required to pass. But to actually protect the domain and build reputation you should be moving to enforcement (p=quarantine or p=reject). The requirement is the floor, not the goal.

What is the spam complaint rate threshold?

Google asks senders to keep the spam complaint rate below 0.3%, and ideally under 0.1%. Cross 0.3% and you'll see delivery problems quickly. Clean lists and relevant, wanted mail are how you stay under it.

Check if you meet the requirements

StopForge's free exposure scan reads your live records and shows exactly where your email authentication stands — what passes, what silently fails, and whether anyone can still send as your domain. No changes to your mail, no obligation.

See if your domain can be spoofed

Related guides: Why your emails go to spam (and how authentication fixes it) · DMARC p=none vs p=reject: which policy actually protects you?

← All guides