Skip to content
Claim your free business email
Deliverability

Gmail bulk sender requirements, plus Yahoo and Outlook: the checklist

By Rasket TeamLast updated 11 min read

The short answer

Gmail’s bulk sender requirements apply once you send about 5,000 messages a day to personal Gmail accounts: SPF and DKIM, a DMARC record (p=none is fine) aligned with the From domain, one-click unsubscribe on marketing mail honoured within 48 hours, and a spam rate below 0.1%, never 0.3%. Yahoo and Outlook require nearly the same.

Who counts as a bulk sender

Gmail defines a bulk sender as “any email sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period.”[1] Three details in that definition catch people out:

  • Subdomains count toward the parent. 2,500 messages from example.com and 2,500 from news.example.com make you a bulk sender for example.com, because Gmail counts all mail from the same primary domain.[1]
  • It is permanent. A sender that crosses the line once is classed as a bulk sender for good: “Bulk sender status doesn’t have an expiration date.”[1]
  • Only personal accounts count. The rules cover mail to @gmail.com and @googlemail.com; they do not apply to messages sent to Google Workspace accounts.[2][1]

5,000

messages or more in 24 hours to personal Gmail accounts, counted across a primary domain and all its subdomains, is the line above which Gmail’s bulk sender requirements apply — once crossed, permanently.
Source: Gmail Help, Google, “Email sender guidelines FAQ” [1]

Yahoo publishes no number: its page lists requirements for “bulk senders” without saying where bulk begins.[3] Microsoft uses the same 5,000-a-day line as Gmail for Outlook.com, Hotmail and Live addresses, counted per domain in the From address.[4][5] If you are anywhere near the threshold, or plan to be, treat the bulk rules as yours: they are the ones a growing product crosses without noticing.

Requirements for every sender, whatever the volume

Since 1 February 2024, Gmail has required every sender to personal Gmail accounts, at any volume, to:[2]

  • Set up SPF or DKIM for the sending domain.
  • Have valid forward and reverse DNS — a PTR record — for the sending IPs.
  • Send over a TLS connection (added to the list in December 2023).
  • Keep the spam rate reported in Postmaster Tools below 0.3%.
  • Format messages to RFC 5322, the Internet Message Format standard.
  • Not impersonate Gmail in the From header.

Yahoo’s list for all senders is the same in substance: SPF or DKIM, a spam rate below 0.3%, valid forward and reverse DNS, and compliance with RFC 5321 and RFC 5322.[3][6] Most of this is the job of whoever runs your sending servers. The parts that are yours — the DNS records on your domain and the spam rate — are the ones that fail.

The Gmail bulk sender requirements, one by one

Above the threshold, Gmail adds five requirements to the baseline.[2] Each is below with what it means in practice and where Yahoo differs.

1. Both SPF and DKIM, not one or the other

Every message needs to pass SPF and carry a valid DKIM signature for your domain.[2] Gmail requires a DKIM key of at least 1024 bits and recommends 2048; RFC 6376 sets the same 1024-bit floor for long-lived keys.[2][7] Yahoo requires “both SPF & DKIM” too.[3] The mechanics are in DKIM, SPF and DMARC explained.

2. A DMARC record, and p=none is enough

Publish a DMARC record at _dmarc. on your sending domain. Gmail says the policy “can be set to none”;[2] Yahoo asks for “at least p=none” and strongly recommends a rua address so you receive aggregate reports;[3] Outlook.com asks for at least p=none.[5] DMARC’s current specification is RFC 9989, published in May 2026, which replaced RFC 7489 and dropped the old pct tag.[8]

A minimal DMARC record that meets all three providers
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

p=none meets the requirement without telling receivers to act on failures. Moving to quarantine or reject protects your domain from spoofing and is worth doing once the reports show every legitimate source passing; see DMARC policy: none, quarantine or reject.

3. The From domain aligned with SPF or DKIM

Passing SPF and DKIM for some domain is not enough: “the domain in the sender’s From: header must be aligned with either the SPF domain or the DKIM domain.”[2] Gmail checks this at the organizational level, so news.example.com aligns with example.com, and only one of the two needs to align — though Google recommends aligning both and says that will likely become a requirement.[1] Yahoo accepts relaxed alignment.[3] This is the requirement that fails when a provider signs with its own domain instead of yours. More in DMARC alignment.

4. One-click unsubscribe, honoured within 48 hours

“Marketing messages and subscribed messages must support one-click unsubscribe, and include a clearly visible unsubscribe link in the message body.”[2] One-click means the two headers RFC 8058 defines, with an HTTPS URL; a mailto: link or a link in the body does not meet Gmail’s requirement on its own.[1] The body link can go to a preference page.[1]

The one-click unsubscribe headers (RFC 8058)
List-Unsubscribe: <https://example.com/unsubscribe/7f3a9c>, <mailto:unsubscribe@example.com>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

RFC 8058 adds rules people miss: the DKIM signature must cover both headers, the POST must not need cookies or a login, and your endpoint must not answer with a redirect.[9] Yahoo accepts the mailto: method but calls the POST method “highly recommended”.[3]

48 hours

is how quickly Google asks bulk senders to fulfil unsubscribe requests; senders who do not are ineligible for delivery mitigation. Yahoo’s rule is “within 2 days”.
Source: Gmail Help, Google, “Email sender guidelines FAQ” [1]

Gmail shows its own unsubscribe button next to the sender name only on messages that pass its eligibility checks, even if your headers are correct — a gradual ramp and a low spam rate are part of qualifying.[1] The header itself is covered in the List-Unsubscribe glossary entry.

5. A spam rate below 0.1%, and never 0.3%

0.1%

is the user-reported spam rate Google asks senders to stay below, and 0.3% the level to never reach. Since June 2024, bulk senders above 0.3% are ineligible for mitigation until the rate stays under it for 7 consecutive days.
Source: Gmail Help, Google, “Email sender guidelines FAQ” [1]

The rate is calculated daily, and Postmaster Tools computes it from mail that reached the inbox, so it only counts people who could press the button.[1][10] Yahoo’s line for bulk senders is 0.3%, also measured on inbox-delivered mail.[3] The practical target is Google’s lower one — see complaint rate.

Gmail, Yahoo and Outlook requirements side by side

The three providers moved together, but they did not write identical rules. Outlook.com’s list is the shortest: authentication is required; unsubscribe and list hygiene are recommendations.[4]

Bulk sender requirements as each provider documents them, read 28 September 2026
RequirementGmailYahooOutlook.com
Who it applies to~5,000+ a day to personal accounts, by primary domain“Bulk senders” (no number published)5,000+ a day, by From domain
SPF and DKIMBothBothBoth must pass
DMARCPublished; p=none allowedAt least p=none; must pass; rua recommendedAt least p=none
AlignmentSPF or DKIM, organizational domainSPF or DKIM, relaxed OKSPF or DKIM (both preferred)
One-click unsubscribeRequired for marketing (RFC 8058, HTTPS)Required; POST highly recommended, mailto acceptedRecommended (functional link)
Unsubscribes honouredWithin 48 hoursWithin 2 daysNot specified
Spam rateBelow 0.1%; never 0.3%Below 0.3%Not specified
Reverse DNS (PTR)RequiredRequiredNot specified
TLSRequiredNot specifiedNot specified
Message formatRFC 5322RFC 5321 and 5322Not specified

“Not specified” means the provider’s requirements page does not list it, not that it does not matter: Microsoft’s own FAQ recommends ARC for forwarding and moving DMARC from none toward reject gradually,[4] and Yahoo recommends ARC for anyone who forwards mail.[3][11]

Enforcement: dates and error codes

Google announced the rules on 3 October 2023, with both authentication and a two-day unsubscribe window,[12] and they took effect on 1 February 2024.[2] The timeline since:

What changed, and when
WhenProviderWhat changed
1 February 2024GmailRequirements in force; gradual enforcement begins, with error codes on failing mail.
February 2024YahooEnforcement begins, rolled out gradually through the first half of the year.
1 June 2024GmailDeadline for one-click unsubscribe on promotional mail; spam rate above 0.3% ends mitigation.
5 May 2025Outlook.comMail from high-volume domains failing authentication rejected with 550 5.7.515.
November 2025GmailEnforcement ramps up: non-compliant mail sees temporary and permanent rejections.

Sources for the rows: Gmail’s FAQ,[1] Yahoo’s requirements page,[3] and Microsoft’s announcement, updated at the end of April 2025 to reject rather than junk non-compliant mail.[4]

The error codes Gmail sends

Gmail’s rejections name the requirement you failed. A 4.7.x code is a temporary rate limit; the 5.7.x twin is a block.[1]

Gmail’s sender-requirement error codes
CodeRequirement failed
4.7.23 / 5.7.25No PTR record, or the PTR does not resolve back to the IP
4.7.27 / 5.7.27SPF did not pass
4.7.29 / 5.7.29Not sent over TLS
4.7.30 / 5.7.30DKIM did not pass
4.7.31No DMARC record, or no policy in it
4.7.32From domain not aligned with SPF or DKIM

Outlook.com has one code for the whole set: 550 5.7.515 Access denied, sending domain … does not meet the required authentication level.[5]

The bulk sender checklist, step by step

In the order that avoids rework: DNS first, because every other check depends on it, and the spam rate last, because it only moves once everything else is in place.

  1. Publish SPF for every service that sends as you

    List each sending service in one SPF record on the domain that appears in the envelope sender, and keep the record within 10 DNS lookups so it does not fail with a permanent error.

  2. Sign every message with DKIM on your own domain

    Use a key of at least 1024 bits, 2048 where your provider supports it, published under your domain rather than your provider's, so the signature can align with your From address.

  3. Publish a DMARC record and check alignment

    Add a TXT record at _dmarc with v=DMARC1, p=none and a rua address for reports, then confirm the From domain matches the SPF or DKIM domain on real messages.

  4. Confirm reverse DNS and TLS

    Sending IPs need PTR records that resolve back to the same IP, and mail must go over TLS. Your email provider should already do both; check it if you run your own servers.

  5. Add one-click unsubscribe to marketing mail

    Send List-Unsubscribe with an HTTPS URL and List-Unsubscribe-Post: List-Unsubscribe=One-Click, cover both with the DKIM signature, add a visible unsubscribe link, and process requests within 48 hours.

  6. Keep the spam rate under 0.1%

    Mail only people who opted in, suppress complaints and bounces at once, and watch the spam rate and Compliance status dashboards in Postmaster Tools, allowing seven days for a fix to show.

Bulk sender checklist

  • SPF passes, and the record stays within 10 DNS lookups.
  • DKIM signs with your own domain, with a 2048-bit key.
  • A DMARC record exists at _dmarc, at least p=none, with a rua address.
  • The From domain aligns with the SPF or DKIM domain.
  • Sending IPs have PTR records that resolve back; mail goes over TLS.
  • Marketing mail carries List-Unsubscribe with an HTTPS URL and List-Unsubscribe-Post, both DKIM-signed.
  • A visible unsubscribe link sits in every marketing body.
  • Unsubscribes take effect within 48 hours — ideally at once.
  • Spam rate stays under 0.1% in Postmaster Tools.
  • Nobody’s From header claims to be @gmail.com.

The 10-lookup ceiling on SPF comes from the SPF standard itself: past it, the check returns a permanent error, which is not a pass.[13]

How to check you meet the requirements

Google built a checker. The Compliance status dashboard in Postmaster Tools shows, for each requirement, whether your traffic passes.[1] Three things to know when you read it:[10]

  • It reports on primary domains only, using data from their subdomains too — add news.example.com and you see example.com.
  • It is a rolling average over several days, so after a fix, check again in 7 days rather than the next morning.
  • DNS checks reflect what receivers saw on your mail, not your current records, and it only covers personal Gmail accounts.

Outside Gmail, the checks are manual: send to a Yahoo and an Outlook.com address you control, open the message source, and confirm spf=pass, dkim=pass and dmarc=pass in Authentication-Results. Your DMARC aggregate reports, which Outlook.com sends to the rua address,[4] show every source sending as your domain and whether it aligns.

Do the requirements apply to transactional email?

Mostly, yes. Authentication, alignment, reverse DNS, TLS, message format and the spam rate apply to every message you send. The one exemption is one-click unsubscribe: it is “required only for marketing and promotional messages”, and password resets, reservation confirmations and form confirmations are Google’s examples of messages excluded.[1]

And because the spam rate is counted across your domain, complaints about marketing mail lower delivery for everything you send, receipts included. Google says so directly: high spam rates “negatively affect message delivery for any message type that you send.”[1]

Meeting the requirements with Rasket

Most of the checklist is either done for you or checked before you can send. Each verified domain gets a 2048-bit DKIM key signed with your own domain and a return-path subdomain (send.yourdomain) that makes SPF pass and aligned with your From domain; the dashboard builds a DMARC value for you to start at p=none and tighten later. We recommend sending from a subdomain such as mail.example.com — it keeps reputations apart, though Gmail still counts it toward your primary domain’s volume.

Campaigns, our marketing feature, go out with the RFC 8058 one-click headers and a hosted preference page; a body without an unsubscribe link gets a footer with one and your postal address. Unsubscribes, complaints and hard bounces are written to an account-wide suppression list the moment they arrive and checked before every send. The transactional email API refuses List-Unsubscribe headers set by hand, so send marketing mail as a campaign rather than through the API.

Myths about the bulk sender requirements

  • Documented by Google “Under 5,000 a day, none of this applies.” False: SPF or DKIM, reverse DNS, TLS, RFC 5322 and a spam rate under 0.3% apply to every sender.[2]
  • Documented by Google “You need p=reject.” False: all three providers accept p=none.[2][3][5]
  • Documented by Google “An unsubscribe link in the footer counts as one-click.” Not for Gmail: only the RFC 8058 headers with an HTTPS URL meet the requirement.[1]
  • Documented by Google “A subdomain gets its own 5,000.” False: Gmail counts subdomains toward their primary domain.[1]
  • Documented by Google “Send less and you stop being a bulk sender.” False: the status is permanent.[1]
  • Documented by Google “Password resets need one-click unsubscribe.” False: transactional messages are excluded.[1]

The law sits on top of the requirements

Mailbox provider rules decide delivery; the law decides what you may send at all. In the United States, CAN-SPAM requires honest headers, a physical postal address and an opt-out honoured within 10 business days, with penalties of up to $53,088 per violating email.[14] In the UK, PECR requires consent, or the narrow soft opt-in, before marketing email to individuals.[15] Yahoo’s requirements page points senders to M3AAWG’s Sender Best Communications Practices for the rest.[3][16] If your emails are already landing in spam, start with why your emails go to spam.

Frequently asked questions

What are the Gmail bulk sender requirements?

For senders of about 5,000 or more messages a day to personal Gmail accounts: SPF and DKIM, a DMARC record with at least p=none, a From domain aligned with SPF or DKIM, reverse DNS and TLS, RFC 5322 formatting, one-click unsubscribe on marketing mail honoured within 48 hours, and a spam rate below 0.1%.

Who counts as a bulk sender for Gmail?

Anyone who sends close to 5,000 messages or more to personal Gmail accounts within 24 hours. Gmail adds up everything sent from the same primary domain, subdomains included, and a sender that crosses the line once stays classified as a bulk sender permanently.

What are Yahoo's sender requirements?

All senders need SPF or DKIM, a spam rate below 0.3%, valid forward and reverse DNS, and RFC 5321 and 5322 compliance. Bulk senders need SPF and DKIM, a passing DMARC policy of at least p=none with alignment, one-click unsubscribe honoured within two days, and a visible unsubscribe link.

Does Microsoft Outlook have bulk sender requirements too?

Yes. Since 5 May 2025, Outlook.com has required domains sending more than 5,000 messages a day to its consumer addresses to pass SPF and DKIM and publish DMARC of at least p=none, aligned with one of them. Failing mail is rejected with 550 5.7.515.

Is DMARC p=none enough to meet the requirements?

Yes, for all three providers. Gmail says the policy can be set to none, Yahoo asks for at least p=none, and Outlook.com gives v=DMARC1; p=none as its example. Moving to quarantine or reject protects your domain from spoofing and is worth doing once reports show every legitimate sender passing.

Do transactional emails need one-click unsubscribe?

No. Gmail requires one-click unsubscribe only for marketing and promotional messages, and names password resets, reservation confirmations and form confirmations as excluded. Every other requirement, from authentication to the spam rate, still applies to transactional mail.

What happens if I don't meet the Gmail sender requirements?

Gmail rate-limits or rejects failing mail with codes such as 4.7.30 for DKIM or 4.7.32 for alignment, and since November 2025 enforcement includes permanent rejections. Missing DMARC, one-click unsubscribe or a spam rate under 0.3% also makes you ineligible for delivery mitigation.

How can I check whether I meet the requirements?

Verify your domain in Google Postmaster Tools and read the Compliance status dashboard, which reports each requirement for your primary domain and updates as a rolling average over several days. For Yahoo and Outlook, check Authentication-Results on test messages and read your DMARC aggregate reports.

Sources

16 primary sources, each read on the date shown.

See all sources
  1. 1.Email sender guidelines FAQ — Gmail Help, Google,
  2. 2.Email sender guidelines — Gmail Help, Google,
  3. 3.Sender Requirements & Recommendations — Yahoo Sender Hub,
  4. 4.Strengthening Email Ecosystem: Outlook’s New Requirements for High‐Volume Senders — Microsoft Defender for Office 365 Blog (2 April 2025, updated April 2025),
  5. 5.Fix NDR error “550 5.7.515” in Outlook.com — Microsoft Support,
  6. 6.RFC 5322: Internet Message Format — IETF,
  7. 7.RFC 6376: DomainKeys Identified Mail (DKIM) Signatures — IETF,
  8. 8.RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC) — IETF,
  9. 9.RFC 8058: Signaling One-Click Functionality for List Email Headers — IETF,
  10. 10.Postmaster Tools dashboards — Gmail Help, Google,
  11. 11.RFC 8617: The Authenticated Received Chain (ARC) Protocol — IETF,
  12. 12.New Gmail protections for a safer, less spammy inbox — Google Blog (3 October 2023),
  13. 13.RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1 — IETF,
  14. 14.CAN-SPAM Act: A Compliance Guide for Business — U.S. Federal Trade Commission,
  15. 15.How do we comply with the PECR electronic mail marketing rules? — UK Information Commissioner’s Office,
  16. 16.Documents for Senders and ESPs (Sender Best Communications Practices) — M3AAWG,

Keep reading

Written by the Rasket Team. First published ; last checked against its sources . See something out of date? How we correct guides.

Send email that earns its place

Authenticated mail, one-click unsubscribe and separate reputations for campaigns and transactional mail, set up in minutes.