What are the Gmail and Yahoo sender requirements?
If you send roughly 5,000 or more messages a day to personal Gmail or Yahoo accounts, you must authenticate with SPF, DKIM and DMARC, offer one-click unsubscribe, and keep your spam complaint rate below 0.30%. These are not recommendations. They have been enforced since 1 February 2024, and enforcement has become steadily stricter since.
The short version, if you only read one thing:
- Authenticate everything. SPF and DKIM must pass, DMARC must exist (p=none is the minimum), and your From domain must align with SPF or DKIM.
- One-click unsubscribe. The List-Unsubscribe headers described in RFC 8058, plus a visible unsubscribe link in the body. Requests processed within two days.
- Stay under 0.30% spam complaints. Google recommends staying below 0.10%.
- Get the plumbing right. TLS on transmission, valid forward and reverse DNS for your sending IPs.
Microsoft has since joined with its own version of these rules for Outlook.com, Hotmail.com and Live.com. If you are compliant for Gmail, you are largely compliant for Microsoft too.
Who counts as a bulk sender?
Google defines a bulk sender as anyone sending close to 5,000 messages or more to personal Gmail accounts within a 24-hour period. Two details catch people out.
First, the count is per domain, not per campaign or per list. If several tools send from the same domain, they add up. Second, once you cross the threshold you are treated as a bulk sender going forward, so a single large seasonal send can change how your mail is judged afterwards.
The threshold only applies to personal accounts. Mail to Google Workspace addresses is not counted toward it, but it is still filtered on reputation, so the requirements remain good practice either way.
Below 5,000 a day, the rules are not enforced against you. They are still the baseline every mailbox provider uses to decide whether you look legitimate, so the practical advice for smaller senders is the same: do all of it anyway.
What has changed since the rules launched?
The requirements are not new, but the consequences of ignoring them are much sharper than they were at launch. The timeline that matters:
| When | What happened |
|---|---|
| February 2024 | Google and Yahoo requirements take effect for senders above 5,000 messages a day. |
| June 2024 | One-click unsubscribe becomes a hard requirement rather than a grace-period item. |
| May 2025 | Microsoft applies its own SPF, DKIM and DMARC requirements to high-volume senders on Outlook.com, Hotmail.com and Live.com. |
| November 2025 | Google ramps up enforcement on non-compliant traffic, moving from soft treatment to temporary and permanent rejections. |
That last line is the one to pay attention to. For the first stretch, non-compliant mail mostly got filtered to spam. Now it can be refused outright at the door, which means the message never reaches a folder at all.
Requirement 1: authenticate with SPF, DKIM and DMARC
All three are required, and they have to agree with each other.
SPF is a DNS record listing which servers may send for your domain. It must pass, and it must stay under the 10 DNS-lookup limit, which is the single most common reason an SPF record that looks fine actually fails.
DKIM cryptographically signs your messages so a receiving server can confirm nothing was altered in transit. It must pass. Use a 2048-bit key where your provider supports it.
DMARC tells mailbox providers what to do when authentication fails, and gives you reporting. A policy of p=none satisfies the requirement, which surprises people who assume they need p=reject. Start at none, read the reports, and tighten to quarantine or reject once you can see every legitimate source is passing.
Alignment is the part most often missed. Passing SPF or DKIM is not enough on its own: the domain in your visible From header has to match the domain that passed. A message can pass SPF for a provider's own domain and still fail DMARC, because the two do not line up.
Requirement 2: one-click unsubscribe
Marketing and subscribed mail must let recipients leave in a single click, without a landing page, a login, or a preference centre in between. Technically that means two headers, List-Unsubscribe and List-Unsubscribe-Post: List-Unsubscribe=One-Click, as described in RFC 8058.
Three things people get wrong here. The headers do not replace the visible unsubscribe link in the body, which is still required. Unsubscribe requests must be honoured within two days. And the header has to be signed by DKIM to be trusted, so an unauthenticated message with a perfect unsubscribe header still fails.
Campaigns sent through Mailpro carry these headers automatically and wire them to the real unsubscribe process. Mail sent through an SMTP relay from your own application is a different matter: there, the headers are yours to add. Our guide to one-click unsubscribe and List-Unsubscribe headers has the exact syntax and a test checklist.
Not sure whether your records actually pass? Mailpro walks you through SPF, DKIM and DMARC setup and shows you the result before you send.
Requirement 3: keep spam complaints below 0.30%
The hard ceiling is 0.30% of delivered messages marked as spam, measured in Google Postmaster Tools. Google's own guidance is to aim below 0.10%, and that gap is not pedantry: 0.30% is the level at which action is taken, not a safe cruising altitude. Cross it briefly and recovery takes weeks.
Complaint rate is judged per domain and per IP over a rolling window, so one bad send pollutes the average for a while. The practical defences are unglamorous: send only to people who genuinely opted in, make unsubscribing easier than complaining, drop inactive subscribers on a schedule, and never reuse an old list you have not mailed in a year.
Two guides go deeper: keeping your complaint rate below 0.3% and how to reduce it below 0.1%.
Requirement 4: TLS, DNS and message hygiene
The remaining items are infrastructure rather than strategy, and they are usually your sending platform's job:
- TLS for transmitting mail. Unencrypted connections are not acceptable for bulk traffic.
- Valid forward and reverse DNS for sending IPs. The PTR record must resolve back to the hostname that resolves to the IP.
- Standards-compliant message format, with an accurate From name and domain and no deceptive headers or subject lines.
- Do not impersonate Gmail or Yahoo in your From header. Sending as a gmail.com address from your own infrastructure will fail DMARC.
What happens if you do not comply?
You will see it in bounce messages rather than in a warning email, which is why many senders discover the problem late.
The error to recognise for Gmail is 5.7.26, which means the message was not accepted because it was not properly authenticated. Microsoft's equivalent is 550 5.7.515 Access denied, stating that the sending domain does not meet the required authentication level.
Both are permanent rejections. The mail is not in a spam folder waiting to be found; it was refused. Transient failures also happen during enforcement ramps, which is why a sudden rise in deferrals deserves the same attention as an outright block. If you are seeing this from Microsoft specifically, our guide on being blocked by Microsoft and Outlook covers the recovery path.
How do you check whether you are compliant?
Do not assume. Verify, in this order:
- Send yourself a test to a personal Gmail address and open the original message. The authentication summary should read pass for SPF, DKIM and DMARC.
- Check Google Postmaster Tools. Google added a compliance status dashboard specifically so senders can see where they stand against the requirements, alongside the spam-rate graph.
- Read your DMARC reports for a fortnight before tightening policy. They reveal the forgotten sources — invoicing systems, CRMs, a booking tool — that will break when you move to reject.
- Check your unsubscribe path end to end, including that a click actually removes the address within two days.
- Watch your bounce log for 5.7.26 and 550 5.7.515.
If your inbox placement has dropped without an obvious cause, work through diagnosing a sudden deliverability drop before changing anything else.
How Mailpro handles this for you
Most of the list above is infrastructure, and infrastructure is what a sending platform is for. With Mailpro, SPF, DKIM and DMARC setup is guided rather than improvised, campaigns carry the RFC 8058 unsubscribe headers automatically, unsubscribes are processed immediately, TLS and reverse DNS are handled on our side, and your complaint and bounce rates are visible in real time instead of discovered after the damage.
What stays yours is the part no platform can do for you: sending wanted mail to people who asked for it.
Frequently asked questions
Do the Gmail and Yahoo requirements apply if I send fewer than 5,000 emails a day?
Enforcement targets senders above roughly 5,000 messages a day to personal accounts. Below that, the requirements are not enforced against you, but they are still the criteria used to judge whether your mail looks trustworthy, so meeting them improves deliverability at any volume.
Is p=none enough for DMARC?
Yes. Both Google and Microsoft accept a minimum policy of p=none, provided the record exists and your From domain aligns with SPF or DKIM. Moving to quarantine or reject protects your brand from spoofing, but it is not what the requirement asks for.
What is a good spam complaint rate?
Below 0.10%. The enforced ceiling is 0.30%, but that is the point at which filtering decisions turn against you rather than a target to sit near.
Does one-click unsubscribe mean I can remove the unsubscribe link from my emails?
No. The List-Unsubscribe headers are required in addition to a visible unsubscribe link in the message body, not instead of it.
Do these rules apply to transactional email?
Authentication applies to everything you send. One-click unsubscribe applies to marketing and subscribed messages, not to genuine transactional mail such as password resets or receipts. Sending marketing content inside a transactional message does not exempt it.
My emails suddenly started bouncing with 5.7.26. What do I do first?
Check authentication before anything else. That code means the message was rejected as unauthenticated, so the cause is almost always a failing or misaligned SPF, DKIM or DMARC record rather than content or reputation.
Mailpro and sender requirements
Authentication that passes, on every send
Mailpro guides your SPF, DKIM and DMARC setup, adds the one-click unsubscribe headers automatically, and shows your complaint and bounce rates in real time — so the Gmail, Yahoo and Outlook requirements are met before they cost you an inbox.