Muhammad Basim
Pin for Gmail, Yahoo and Microsoft Bulk Sender Requirements: The 2026 Checklist
Email Marketing

Gmail, Yahoo and Microsoft Bulk Sender Requirements: The 2026 Checklist

Muhammad Basim
Muhammad Basim
·11 min read

✦Part of the comprehensive guide on: Email Authentication: SPF, DKIM, DMARC, and BIMI

Gmail, Yahoo and Microsoft Bulk Sender Requirements: The 2026 Checklist

Bulk sender requirements are the conditions Gmail, Yahoo, and Microsoft impose on anyone sending roughly 5,000 or more messages a day to their users: authenticated mail with an aligned From domain, one-click unsubscribe honoured within two days, and a spam complaint rate below 0.1%. Non-compliant mail is rejected at the server rather than filtered.

The rules took effect in February 2024 and have tightened in stages since. Enforcement is no longer a warning phase.

Updated 7 September 2026: the Microsoft column has been corrected — one-click unsubscribe is strongly recommended by Microsoft rather than enforced, and the requirements Microsoft recommends without yet enforcing are now listed separately. A section on the shift toward engagement-based reputation has been added.


The requirements, by provider

Requirement Google Yahoo Microsoft Apple
Volume threshold 5,000/day 5,000/day 5,000/day No published threshold
SPF Required Required Required Expected
DKIM Required Required Required Expected
DMARC published p=none minimum p=none minimum p=none minimum Not mandated
Aligned From domain Required, via SPF or DKIM Required Required Expected
One-click unsubscribe Required, honoured in 2 days Required Recommended, not enforced Not mandated
Spam complaint rate Below 0.1%, never 0.3% Below 0.1%, never 0.3% No published figure No published figure
TLS transmission Required Required Required Expected
Forward-confirmed reverse DNS Required Required Required Expected
Valid, non-impersonating From Required Required Recommended, not enforced Expected

Microsoft enforces authentication and nothing else. The rejection at Microsoft is triggered by SPF, DKIM, or DMARC failure. Unsubscribe mechanics, sender-address validity, and list hygiene are published as strong recommendations rather than enforced conditions, which means a technically authenticated sender with poor list practice is currently rejected by Google and accepted by Microsoft.

Treating Microsoft's recommendations as optional is a short-term reading. They are the same items the other providers enforce, which makes them the most likely content of a future enforcement phase.

Apple has not published an equivalent bulk-sender programme. iCloud Mail enforces authentication and rate limits without a public threshold or checklist, and a sender compliant with the other three is generally compliant there.


The enforcement timeline

Date Provider What changed
February 2024 Google, Yahoo Requirements take effect; non-compliant mail met with temporary 421 deferrals
5 May 2025 Microsoft Outlook.com enforcement begins, authentication only
November 2025 Google Enforcement ramps to permanent 550 rejections
2026 All three Full enforcement as industry standard

The shift from 421 to 550 is the change that matters. A 421 is a temporary deferral — the sending platform retries, and mail eventually arrives. A 550 is a permanent rejection: the message is gone, the recipient never sees it, and the sender receives a bounce.

Senders who passed through 2024 and 2025 without noticing a problem may have been surviving on retries that no longer happen.


The error codes and what each one means

Code Meaning
421-4.7.26 SPF and DKIM both failed
421-4.7.30 DKIM does not pass for a bulk sender
421-4.7.32 No DMARC alignment
550-5.7.26 Unauthenticated mail, permanently rejected
550 5.7.515 Microsoft hard authentication rejection

Bounce logs are where compliance failures actually surface, and they name the specific requirement that failed. A sender seeing 421-4.7.32 has an alignment problem rather than a missing record — the difference is explained in email authentication: SPF, DKIM, DMARC and BIMI.


Does the 5,000-a-day threshold apply to you?

The threshold is counted per provider, per day, based on messages sent to that provider's users from the same primary domain.

Situation Subject to the rules
5,000 messages a day to Gmail addresses Yes, at Google
20,000-person list mailed weekly, roughly half Gmail Yes on send days
800 subscribers mailed daily No, at any provider
5,000/day across all providers combined Not necessarily — the count is per provider
Crossed 5,000 once during a launch Yes, and the status is retained thereafter

Crossing the threshold once makes a sender subject to the rules from then on, so campaign-driven senders who exceed it on launch days are treated as bulk senders permanently.

The more useful reading: every requirement on the list is something a well-run small sender should be doing anyway. SPF, DKIM, DMARC, working unsubscribe links, and a complaint rate below 0.1% are the baseline for anyone who wants their mail delivered, threshold or not. The rules made the baseline enforceable rather than inventing it.


The compliance checklist

Seven items. Each can be verified in minutes.

1. SPF published, single record, under 10 lookups. Query the domain's TXT records and confirm exactly one record starting v=spf1. Two records cause a permanent error.

2. DKIM signing under your own domain. Confirm the sending platform shows the domain as authenticated, and that the signature is not being applied under the platform's domain.

3. DMARC published at p=none or stronger. Query _dmarc.yourdomain.com for a TXT record starting v=DMARC1. The staged path to enforcement is in how to set up DMARC safely.

4. Alignment confirmed, not assumed. Send a message to Gmail, open Show original, and check that the DKIM or SPF domain matches the visible From domain. Passing all three checks while failing alignment is the most common compliance failure.

5. One-click unsubscribe in the headers. The requirement is an RFC 8058 List-Unsubscribe-Post header alongside List-Unsubscribe, not merely a link in the footer. Most major sending platforms add it automatically; verify rather than assume, and confirm requests are honoured within two days.

6. Complaint rate below 0.1%. Check Google Postmaster Tools for the spam-rate chart. Reaching 0.3% costs eligibility for Gmail's mitigation support until the rate holds below the line — reading the charts is covered in how to read Google Postmaster Tools.

7. TLS and forward-confirmed reverse DNS. Sending platforms handle both. Senders on their own infrastructure need to verify that the sending IP's reverse DNS resolves forward to the same IP.


Compliance is now the smaller half of the problem

The requirements above are a technical floor, and clearing them has become the easy part. What determines placement above that floor has moved.

Complaint rate is now the dominant reputation signal. Provider filtering weights recipient behaviour — complaints above all — more heavily than the infrastructure signals that used to carry reputation. A sender with immaculate authentication and a complaint rate drifting toward 0.3% is in a worse position than one with an ordinary setup and subscribers who want the mail.

Domain and IP reputation carry less weight than they did. Both still matter. Neither compensates any longer for recipients marking mail as spam.

Recovery takes longer than it used to. Rebuilding sender reputation after a serious complaint episode is now measured in weeks to months rather than days. The practical consequence is that monitoring beats remediation by a wide margin: a complaint rate caught at 0.12% is a small correction, and the same problem caught at 0.35% is a quarter of degraded delivery.

This is why the seventh item on the checklist is not the last piece of work. Compliance gets mail accepted. Engagement decides where it lands, and that is covered in why authenticated emails still land in spam.


What happens when you fail

Failure is graduated rather than binary, and each stage is recoverable.

Temporary deferral (421). The receiving server refuses the message and invites a retry. Mail is delayed rather than lost, and the sending platform's queue absorbs it. Bounce logs show the specific failure.

Permanent rejection (550). The message is refused outright. The recipient never receives it, the sender gets a bounce, and repeated rejections damage domain reputation independently of the original compliance issue.

Rate limiting. Providers throttle accepted volume from a sender whose complaint rate is elevated, producing delayed delivery that looks like a platform problem.

Spam foldering. A compliant sender with poor engagement is still filtered. Compliance is a floor, not a guarantee.


What the rules do not require

Three things are widely believed to be mandatory and are not.

DMARC at p=reject. Only p=none is mandated. Enforcement is strongly recommended and remains a sender's own choice.

A dedicated IP address. Nothing in the requirements references IP dedication, and a dedicated IP is a liability below consistent high volume — discussed in which email service actually delivers.

BIMI. Entirely optional, and separate from compliance. Covered in BIMI: how to get your logo in the inbox.

What's in the book, not here. The 20-minute self-audit scorecard that walks every one of these checks with pass conditions is in The Email Deliverability Playbook.


Frequently asked questions

Do the bulk sender rules apply under 5,000 emails a day?
The published threshold is 5,000 messages a day to a single provider, counted per provider rather than across all of them. Crossing it once makes a sender subject to the rules from then on. Every requirement is baseline practice for any sender who wants mail delivered, regardless of volume.

What is the 0.3% complaint rate rule?
Google and Yahoo require senders to keep spam complaint rates below 0.1% and never reach 0.3%. Crossing 0.3% costs eligibility for Gmail's mitigation support until the rate holds consistently below the line. Complaint rate moves before revenue does, which makes it the best early warning available.

What happens if I don't comply with bulk sender requirements?
Failure is graduated: temporary 421 deferrals delay mail, permanent 550 rejections discard it entirely, rate limiting throttles accepted volume, and poor engagement produces spam foldering on top. Google moved from deferrals to permanent rejections from November 2025.

Do I need DMARC at p=reject to comply?
No. All three providers mandate a published DMARC policy of p=none or stronger. Enforcement at quarantine or reject is strongly recommended for spoofing protection and is not a compliance requirement.

What counts as one-click unsubscribe?
An RFC 8058 List-Unsubscribe-Post header alongside a List-Unsubscribe header, allowing the mail client to unsubscribe the recipient without opening a web page. A footer link alone does not satisfy the requirement, and requests must be honoured within two days.

Does Microsoft have the same requirements as Gmail?
Not identical. Microsoft's Outlook.com enforcement began on 5 May 2025 with the same 5,000-a-day threshold and the same SPF, DKIM, DMARC and alignment requirements. Microsoft enforces authentication only — unsubscribe mechanics, sender-address validity and list hygiene are published as strong recommendations rather than enforced conditions, and Microsoft has published no complaint-rate figure.

Does Apple have bulk sender requirements?
Apple has not published an equivalent programme with a stated threshold or checklist. iCloud Mail enforces authentication and rate limits, and a sender compliant with Google, Yahoo, and Microsoft is generally compliant there.

Is passing the requirements enough to reach the inbox?
No. The requirements determine whether mail is accepted, not where it is placed. Provider filtering now weights recipient behaviour — complaints in particular — more heavily than infrastructure signals, so a fully compliant sender with poor engagement is still filtered to spam.

How long does it take to recover sender reputation?
Longer than it used to. Rebuilding reputation after a serious complaint episode is now measured in weeks to months rather than days, which makes monitoring considerably cheaper than remediation.


What to do next

Send one message to a Gmail address and read Show original. That check verifies four of the seven requirements at once — SPF, DKIM, DMARC, and alignment.

Then open Google Postmaster Tools and read the spam-rate chart, which verifies the fifth and is the only one of the seven that cannot be fixed with a DNS record.

Free: The 60-Minute Email Authentication Fix — the checklist for verifying every technical requirement on this page.

Go deeper: The Email Deliverability Playbook — the 20-minute self-audit scorecard with pass conditions for each check.


Deliberately not claimed

A date for Microsoft enforcing its recommended items. Microsoft has published no timeline for making unsubscribe mechanics, sender-address validity, or list hygiene enforced conditions. That they are likely candidates for a future phase is an inference, stated as one.

A figure for how much reputation weight shifted from infrastructure to engagement. The direction is documented across provider guidance and industry reporting. No provider publishes a weighting, and any percentage would be invented.

A specific recovery period. "Weeks to months" is the range reported across deliverability practice. A precise figure would depend on the sender, the severity, and the provider, and none is published.

A Microsoft complaint-rate threshold. Microsoft has not published one. The 0.1% and 0.3% figures are Google's and Yahoo's, and applying them to Microsoft would be an assumption.


Related guides

Free: The 60-Minute Email Authentication Fix

A no-fluff checklist to set up SPF, DKIM & DMARC correctly and pass Gmail & Yahoo's sender requirements.

Muhammad Basim

About the Author

Muhammad Basim

Digital Marketer & WordPress Developer

Muhammad Basim has worked in digital marketing since 2013, focused on email deliverability and AI-assisted content production. He is the author of The Email Deliverability Playbook and The Email Copywriting Playbook.

Related Articles

Newsletter

Free: The 60-Minute
Email Authentication Fix

A no-fluff checklist from the Deliverability Playbook. In one hour: set up SPF, DKIM & DMARC correctly, check your domain against blocklists, and pass Gmail & Yahoo's 2026 sender requirements.

No spam — that would be ironic. Unsubscribe anytime.