For years, deliverability advice was folklore. Then Google and Yahoo published formal sender requirements that took effect in February 2024, and Microsoft followed for its consumer Outlook domains in May 2025. For the first time, the largest mailbox providers wrote down what they expect, and started rejecting mail that does not meet it.
Most of these rules were written with marketing email in mind, but cold outbound runs into every one of them. Here is what each provider requires, how the volume thresholds are counted, and what that means for a team sending one-to-one prospecting email.
Why These Rules Matter Now
Before 2024, missing authentication mostly cost you placement quietly. Now non-compliant mail can be rejected outright at the SMTP stage, so it never reaches spam, let alone the inbox. Google has tightened enforcement in stages since the rules took effect, moving from warnings and temporary errors toward hard rejections for traffic that does not comply.
The rules split into two tiers: a baseline that applies to everyone, and extra requirements for high-volume senders.
The Baseline Every Sender Must Meet
Google and Yahoo apply these to all mail sent to their users, regardless of volume:
- SPF or DKIM on the sending domain. At least one must pass.
- Valid forward and reverse DNS. The sending IP needs a PTR record that resolves to a hostname, and that hostname must resolve back to the same IP.
- TLS for the connection that transmits the message.
- Messages formatted to RFC 5322, the internet message format standard. Malformed headers, duplicate fields and broken From lines count against you.
- A low spam complaint rate. Google asks senders to keep the user-reported spam rate in Postmaster Tools below 0.3%, and recommends staying under 0.1%.
The 0.3% figure is a ceiling, not a target. A sender who sits near it is already in trouble.
The Extra Bar for Bulk Senders
Google defines a bulk sender as one sending roughly 5,000 or more messages a day to personal Gmail accounts. Yahoo applies similar requirements to bulk senders without publishing a hard number. Bulk senders must also have:
- SPF and DKIM and DMARC, all three. A DMARC policy of
p=noneis enough to comply. - From domain alignment: the domain in the visible From header must align with the SPF domain or the DKIM signing domain.
- One-click unsubscribe for marketing and subscribed messages, using the
List-UnsubscribeandList-Unsubscribe-Postheaders defined in RFC 8058, with a visible unsubscribe link in the body. - Unsubscribes honored within 2 days.
In practice, a minimal compliant setup looks like this:
; DMARC record at _dmarc.yourdomain.com v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com ; One-click unsubscribe headers (RFC 8058) List-Unsubscribe: <https://yourdomain.com/unsub?id=abc123> List-Unsubscribe-Post: List-Unsubscribe=One-Click
You can verify your SPF, DKIM and DMARC records with the SPF and DKIM checker, and the pre-send DNS checklist walks through every record in order.
Microsoft's Rules for Outlook.com and Hotmail
Microsoft's requirements apply to its consumer domains: Outlook.com, Hotmail.com and Live.com. From May 5, 2025, senders sending more than 5,000 messages a day to those domains must have SPF, DKIM and DMARC in place, with DMARC at least p=none and aligned with SPF or DKIM.
Microsoft first said non-compliant mail would go to junk, then switched to rejection. Mail that fails is bounced with 550 5.7.515 Access denied, sending domain does not meet the required authentication level. If you see that code, it is an authentication problem, not a content one. The guide to SMTP bounce codes covers how to read it alongside other rejections. Microsoft also recommends working unsubscribe links and list hygiene, though it frames those as best practice rather than hard requirements.
Side-by-Side Comparison
| Requirement | Google (Gmail) | Yahoo | Microsoft (consumer) |
|---|---|---|---|
| Effective date | February 2024 | February 2024 | May 5, 2025 |
| Bulk threshold | Around 5,000 a day to Gmail accounts | Not published as a number | More than 5,000 a day to Outlook.com, Hotmail, Live |
| All senders | SPF or DKIM, PTR, TLS, RFC 5322, spam rate under 0.3% | SPF or DKIM, PTR, TLS, RFC 5322, low spam rate | No separate published baseline tier |
| Bulk: authentication | SPF, DKIM and DMARC (p=none or stricter), aligned | SPF, DKIM and DMARC (p=none or stricter), aligned | SPF, DKIM and DMARC (p=none or stricter), aligned |
| Bulk: unsubscribe | One-click (RFC 8058), honored within 2 days | One-click (RFC 8058), honored within 2 days | Recommended, not a hard requirement |
| Non-compliance | Temporary and permanent rejections | Rejections and filtering | Rejected with 550 5.7.515 |
How Volume Is Counted for Cold Outbound
It is tempting to read "5,000 a day" and conclude cold email is exempt, since a well-run cold domain sends perhaps a hundred messages a day. Two details make that risky.
First, Google counts volume by primary domain, not by mailbox. Messages from every address and subdomain under the same organisational domain add up. If your marketing team sends newsletters from news.company.com and sales sends cold email from company.com, they share one total. Google has also said that once a domain qualifies as a bulk sender, it keeps that status permanently.
Second, the baseline rules apply at any volume. PTR, TLS, formatting and spam rate limits have no threshold. And because SPF, DKIM and DMARC cost nothing to set up, there is no good reason to run a cold domain without all three. Treat the bulk tier as your minimum, whatever your volume.
Why Plain-Text Cold Email Still Needs an Opt-Out
The one-click header requirement is aimed at marketing and subscribed mail, and a one-to-one cold email is neither. But the rule that actually limits cold senders is the spam rate. A prospect who cannot see an easy way out has one button left: report spam. Every one of those reports counts against the 0.3% ceiling.
A plain-text opt-out line keeps the email human while giving people a better option than the spam button:
Not the right person, or not a priority? Reply "no thanks" and I won't follow up.
Then honor it fast, across every mailbox and campaign. Adding the List-Unsubscribe headers on top is also legitimate and helps, since Gmail and Yahoo can show their own unsubscribe button. For tone that does not trigger complaints in the first place, see cold email copy that reads human. Opt-out laws such as CAN-SPAM and GDPR are a separate question that depends on where you and your prospects are, so check them for your markets.
A Compliance Checklist Before You Launch
- SPF published and passing for every sending domain.
- DKIM signing enabled with the sending domain as the signing domain.
- DMARC published, at least
p=none, with reporting enabled. - From domain aligned with SPF or DKIM.
- PTR record on the sending IP that matches its forward DNS.
- TLS supported on the sending server.
- A clear opt-out line in every email, and a process that honors it within 2 days.
- Spam rate monitored in Postmaster Tools where data exists, with placement tests where it does not.
Sendbox handles the server side of this list, including PTR and TLS on dedicated IPs. The DNS records on your domains and the opt-out discipline are still yours to own.
