Gmail, Yahoo and Microsoft sender requirements

Since 2024 the largest inbox providers have required senders to authenticate their email. Messages that don’t comply are increasingly rejected or sent to junk. Here’s what each one asks for.

Last reviewed 7 October 2026. Providers update these rules; check the official pages linked below for the latest wording.

Gmail

Google’s requirements took effect in February 2024, and from November 2025 Gmail stepped up enforcement, with non-compliant messages facing temporary and permanent rejections.

Everyone sending to personal Gmail accounts must:

  • Set up SPF or DKIM for the sending domain.
  • Have valid forward and reverse DNS for sending servers.
  • Use a TLS connection to send email.
  • Keep the spam rate reported in Google Postmaster Tools below 0.3% (Google recommends staying under 0.1%).
  • Format messages to internet standards (RFC 5322).

Senders of more than 5,000 messages a day to Gmail accounts must also:

  • Set up both SPF and DKIM.
  • Publish a DMARC record (p=none is the minimum).
  • Make the From domain align with the SPF or DKIM domain.
  • Offer one-click unsubscribe in marketing email and honour requests within two days.

Yahoo

Yahoo’s rules, also from February 2024, closely match Google’s. All senders need SPF or DKIM, valid forward and reverse DNS and a complaint rate below 0.3%. Bulk senders also need SPF and DKIM, a DMARC policy of at least p=none that passes, a From domain that aligns with SPF or DKIM, and a working one-click unsubscribe honoured within two days.

Microsoft (Outlook.com, Hotmail, Live)

From 5 May 2025, Microsoft requires domains sending more than 5,000 messages a day to its consumer addresses to have:

  • SPF that passes for the sending domain.
  • DKIM that passes.
  • A DMARC record of at least p=none, aligned with SPF or DKIM.

Non-compliant messages are rejected. Microsoft also recommends valid From and Reply-To addresses, working unsubscribe links and regular list cleaning. These rules apply to consumer Outlook.com addresses; business Microsoft 365 mailboxes apply their own filtering.

Does this apply to a small business?

The strictest rules apply to bulk senders, but the thresholds count all email from your domain, including newsletters and system emails, and the basics apply to everyone. More importantly, inboxes increasingly treat unauthenticated email as suspicious whatever the volume. Setting up SPF, DKIM and DMARC takes under an hour and protects your domain from being used in fraud.

How to comply

  1. Run the email health check. Its sender requirements test shows whether SPF, DKIM and DMARC are all in place.
  2. Fix anything missing with the guide for your provider: all fix guides.
  3. Make sure newsletter and CRM tools sign with your domain: how to authenticate sending services.
  4. Paste the headers of a test email into the header analyser to confirm DMARC passes with alignment.

Official sources

What counts as a bulk sender?

Gmail and Microsoft use more than 5,000 messages a day to their users. Gmail treats a domain that reaches that level as a bulk sender permanently.

Is DMARC p=none enough to comply?

Yes, p=none meets the minimum for Gmail, Yahoo and Microsoft. It doesn’t stop others faking your domain, so moving to quarantine or reject is still recommended.

What happens if I don’t comply?

Messages may be delayed, sent to spam or rejected outright. Gmail and Microsoft both reject non-compliant bulk mail.

Do these rules apply to business email accounts?

They apply to email sent to personal Gmail, Yahoo and Outlook.com addresses. Business mail systems apply their own filtering, which also favours authenticated email.