Insight
Bulk sender rules for Gmail, Yahoo and Outlook: authentication, unsubscribe and spam rates
Since 2024 the largest mailbox providers have turned long-standing email best practice into enforced requirements for high-volume senders. Authentication, one-click unsubscribe and a low spam complaint rate now decide whether marketing and even transactional email reaches the inbox at all.
What changed, and why it matters to marketing teams
For years, authentication records and easy unsubscribes were recommendations that deliverability specialists repeated and many companies ignored. That changed when Google and Yahoo announced in late 2023 that, from February 2024, senders delivering large volumes to their consumer mailboxes would have to meet a defined set of requirements. Enforcement was introduced in stages through 2024, beginning with temporary errors on part of non-compliant traffic and moving towards rejection.
Microsoft followed in 2025 with comparable requirements for domains sending high volumes to its consumer addresses such as Outlook.com and Hotmail.com. Together these providers handle a very large share of the consumer inboxes that newsletters, promotions, order confirmations and account emails are sent to.
The practical effect is that email deliverability is no longer something a marketing team can leave to its email platform. Several requirements depend on DNS records for the company’s own domain, on how subscription forms and preference centres work, and on list hygiene decisions that sit with marketing, IT and whoever manages the domain. When one of those parts is missing, campaigns quietly land in spam folders or are refused, and reporting often shows only a drop in open rates.
Who counts as a bulk sender
Google describes bulk senders as those sending close to 5,000 or more messages a day to personal Gmail accounts, counting all mail from the same primary domain. Once a domain has been treated as a bulk sender, it continues to be treated that way, even if volumes later fall. Microsoft uses a threshold of more than 5,000 messages a day to its consumer domains.
Two details catch companies out. First, the count is per sending domain, so a business whose newsletters, invoices, password resets and sales sequences all use the same domain can cross the threshold even if no single system sends much. Second, the basic requirements for all senders apply regardless of volume, so smaller companies cannot simply ignore the topic.
Requirements that apply to every sender
Google’s guidelines for all senders to personal Gmail accounts include authenticating mail with SPF or DKIM, having valid forward and reverse DNS records for sending IP addresses, using TLS for transmission, keeping the spam complaint rate reported in Postmaster Tools below 0.3%, and formatting messages according to internet message standards. Senders must also not impersonate Gmail addresses in the From header.
Most reputable email service providers handle the infrastructure parts, such as TLS and reverse DNS, on their shared or dedicated IP addresses. What they cannot do on a customer’s behalf is publish records in the customer’s DNS or stop the customer from mailing people who never expected to hear from them.
Additional requirements for bulk senders
High-volume senders have to go further. The requirements are technical, but each exists for a clear reason: proving that the sender is who it claims to be, and giving recipients a reliable way to stop mail they no longer want.
- SPF and DKIM
- Both authentication methods must be set up for the sending domain, not just one of them.
- DMARC
- A DMARC record must be published for the sending domain, with a policy of at least p=none.
- Alignment
- The domain in the visible From address must align with the domain authenticated by SPF or DKIM, so mail sent through a platform is signed with the company’s own domain.
- One-click unsubscribe
- Marketing and subscription messages need a list-unsubscribe header supporting one-click unsubscription, plus a clearly visible unsubscribe link in the message body.
- Fast processing
- Google and Yahoo expect unsubscribe requests to be honoured within two days.
- Low complaint rate
- Spam complaints must stay below 0.3%, and Google recommends keeping them below 0.1%.
Where companies usually fail
The most common gap is the domain itself. A company sends newsletters through one platform, invoices through its accounting software, support replies through a help desk and sales sequences through a CRM, and each tool was connected by a different person. SPF records exceed their lookup limit, some tools were never given DKIM keys for the company domain, and nobody owns the DMARC reports.
The second gap is the unsubscribe journey. A footer link that leads to a login page, a preference centre that requires several clicks, or an unsubscribe that only removes someone from one list while other tools keep mailing them all undermine the requirement and generate complaints. Where a CRM and an email platform both send marketing mail, suppression lists need to be synchronised.
The third gap is list quality. Purchased lists, old event registrations and contacts imported without clear consent generate complaints quickly. In Europe, many of those contacts should not be receiving marketing email in the first place under consent and electronic marketing rules, so deliverability and legal compliance point in the same direction.
Transactional email is affected too
Order confirmations, password resets and invoices are not marketing, and one-click unsubscribe is not required on genuinely transactional messages. Authentication and alignment, however, apply to all mail from a bulk-sending domain. If a company’s marketing email damages the domain’s reputation, transactional messages sent from the same domain can suffer as well.
For that reason many organisations separate streams, for example by sending marketing from a subdomain and transactional mail from another, each properly authenticated. Separation does not excuse poor practice, but it limits the damage one stream can do to the other and makes monitoring clearer.
A practical order of work
Start with an inventory of every system that sends email using the company’s domains, including tools that marketing, finance, support and sales connected independently. For each one, confirm how it authenticates and whether it signs with the company’s domain.
Next, fix SPF so it stays within its limits, enable DKIM for every sending tool, and publish a DMARC record at p=none with reporting addresses so the reports show which sources pass and fail. Once legitimate sources all pass, many organisations move gradually to quarantine or reject, which also makes spoofing the domain harder.
Then review the unsubscribe experience from the recipient’s point of view: one click in the mail client, a visible link in the message, and removal across every tool within two days. Finally, register with Google Postmaster Tools and monitor complaint rates, domain reputation and authentication results over time rather than checking once.
Questions
Do these rules apply to B2B email?
They apply to mail sent to consumer mailboxes at these providers. B2B recipients often use company domains hosted elsewhere, but many business contacts also use personal addresses, and the same practices improve delivery everywhere.
What is the difference between SPF, DKIM and DMARC?
SPF lists which servers may send for a domain, DKIM adds a cryptographic signature to each message, and DMARC tells receivers how to treat mail that fails alignment and where to send reports.
Is p=none enough for DMARC?
It meets the minimum requirement for bulk senders. A stricter policy gives stronger protection against spoofing once all legitimate sending sources are authenticated.
Does one-click unsubscribe apply to transactional messages?
No. It is required for marketing and subscription messages, not for genuinely transactional email such as receipts or password resets.
What spam complaint rate is acceptable?
Google requires staying below 0.3% and recommends below 0.1%.
Can our email platform fix this for us?
Only partly. The platform handles its infrastructure, but DNS records for your domain, consent practices and list hygiene remain your responsibility.
Should marketing and transactional email use separate domains?
Separate, properly authenticated subdomains are a common approach that limits reputation damage between streams and simplifies monitoring.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Marketing Automation — CRM, lead capture and automated follow-up built as one system — so nothing arrives in an inbox and nothing depends on someone remembering.
- Why more traffic rarely fixes a pipeline problem
- Lead scoring that sales will actually use
- Service booking and reminders for car dealers and workshops: the revenue after the sale
- Choosing a CMS for a multilingual website: the questions that matter more than features
- All insight articles
Not sure which of your systems send email?
We audit sending sources, fix authentication and alignment, and connect unsubscribe and suppression across your CRM and email tools so campaigns reach the inbox.
Get in touch