Since February 2024, Gmail and Yahoo have required bulk email senders to have an authenticated domain with SPF and DKIM records, a DMARC record, one-click unsubscribe and a spam complaint rate below 0.3 %. Since May 2025, Microsoft has applied similar rules to Outlook.com, and since November 2025 Gmail has been rejecting non-compliant emails. In Quanda this means three CNAME records, one TXT record for DMARC and a company sender address. Below you will find exactly what to do.

In a nutshell

  1. The rules apply to anyone who sends around 5,000 emails a day to Gmail, the basic requirements apply to all senders.
  2. Set up the three CNAME records for SPF and DKIM in Quanda and confirm them with green ticks.
  3. Add a DMARC record to your domain, a p=none policy is enough to start with.
  4. Do not send bulk emails from gmail.com, yahoo.com, outlook.com or other free email addresses.
  5. Watch your spam complaint rate in Google Postmaster Tools, ideally below 0.1 %.
  6. Before you tighten DMARC, check every place that sends email from your domain.

In short: what, since when, who and what is at stake

  • What you need: an authenticated domain with SPF and DKIM records, a DMARC record with at least a p=none policy, one-click unsubscribe and a spam complaint rate below 0.3 %.
  • Since when: Gmail and Yahoo since February 2024, Outlook.com since 5 May 2025. Since November 2025, Gmail has been rejecting non-compliant emails.
  • Who it applies to: mandatory for anyone who sends around 5,000 or more emails a day to Gmail or Outlook.com. SPF or DKIM and a complaint rate below 0.3 % apply to all senders.
  • What is at stake: your emails end up in spam, or Gmail, Yahoo and Outlook.com reject them outright and they never reach recipients.

What has changed since the article was published: The article came out in January 2024, before the rules took effect. Since then, on 5 May 2025, Microsoft introduced similar requirements for Outlook.com, Hotmail.com and Live.com, and since November 2025 Gmail has been temporarily and permanently rejecting non-compliant emails instead of just warning. We have therefore updated the overview of requirements and the steps.

Why mailbox providers introduced the rules

Mailbox providers such as Gmail and Yahoo process millions of emails every day on their way to their users' inboxes. Those users expect to find the emails they want in their inbox and not to be buried in junk mail. As Marcel Becker, Senior Director of Product Management at Yahoo, puts it: "Yahoo's core mission is to deliver the messages consumers want to receive and to filter the ones they don't."

To fight spam and protect their users' inboxes as much as possible, Gmail and Yahoo introduced a set of requirements that bulk email senders must meet for their emails to be delivered.

Who has to meet the requirements

Google considers a bulk sender to be anyone who sends close to 5,000 or more emails to personal Gmail accounts within 24 hours. All emails from the same primary domain count towards the limit, subdomains included. So if you send 2,500 emails from company.com and another 2,500 from newsletter.company.com, you are a bulk sender. What is more, this status never expires. Exceeding the limit once is enough.

The basic requirements, meaning SPF or DKIM, valid DNS records and a complaint rate below 0.3 %, apply to all senders regardless of volume. We therefore recommend meeting all the requirements even if you send less to Gmail. An authenticated domain and DMARC help deliverability with every mailbox provider, not just Gmail.

Overview of Gmail, Yahoo and Outlook requirements

Requirement All senders Bulk senders What to do in Quanda
SPF and DKIM SPF or DKIM Both SPF and DKIM Set up three CNAME records from Settings / Domain & DNS verification
DMARC Recommended At least p=none and the From domain aligned with SPF or DKIM Add a _dmarc TXT record with the DNS provider of your domain
Valid DNS records for sending IP addresses Yes Yes Nothing, Quanda looks after the DNS records of the sending IP addresses
Spam complaint rate Below 0.3 % Below 0.3 %, ideally below 0.1 % Monitor it in Google Postmaster Tools
Unsubscribe Recommended One-click, processed within 2 days Nothing, every campaign has an unsubscribe link and an unsubscribed contact is removed from recipients
Sender address Do not impersonate an @gmail.com address The same Send from an address on your own company domain

Source: Google, Email sender guidelines; Yahoo, Sender Best Practices; Microsoft, requirements for high-volume senders to Outlook.com.

How the rules got stricter

Period Provider What changed
February 2024 Gmail, Yahoo The requirements took effect. Some non-compliant emails started getting temporary errors.
April 2024 Gmail Gmail started rejecting part of the non-compliant emails and gradually increased the share.
5 May 2025 Microsoft Outlook.com, Hotmail.com and Live.com require SPF, DKIM and DMARC from senders of more than 5,000 emails a day. Non-compliant emails are rejected with error 550 5.7.515.
November 2025 Gmail The end of soft enforcement. Gmail temporarily and permanently rejects non-compliant emails.

In 2024, Google described its rejection approach like this:

"If 75 % of a sender's traffic meets our requirements, we will start rejecting the remaining 25 % of traffic that does not meet the requirements."

Google

1. How to set up SPF and DKIM for your sending domain

SPF (Sender Policy Framework) is a DNS record of your domain that specifies which servers may send email on its behalf.

DKIM (DomainKeys Identified Mail) is a digital signature that the sending server adds to every email and whose public key is stored in the DNS of the sender's domain. It lets the recipient verify that the email was sent by that domain and that nobody changed it on the way.

SPF and DKIM are the two basic forms of email authentication. Bulk senders must have both.

What you need to do:

  1. Check whether you have SPF and DKIM records set up. In Quanda they are set up with three CNAME records listed in the "Sender verification" section. In the top blue menu, open Settings / Domain & DNS verification and click the "Check DNS record settings" button in the top right corner of the page.
  2. If all the listed records have green ticks, the records are set up and verified correctly.
  3. If not, add the records with the DNS provider of your sending domain. Wait about 60 minutes and click "Check DNS record settings" again to verify them. Verification can take several hours.
  4. If you cannot set DNS records for your sending domain because you send from an address such as @gmail.com, @yahoo.com or @outlook.com, change the sender address to one on your company domain as soon as possible, see step 3.
The Domain & DNS verification page in Quanda with three CNAME records in the Sender verification section, each with a green tick, and the Check DNS record settings button in the top right
Three CNAME records in the Sender verification section. Green ticks mean SPF and DKIM are in order.

Tip: The records labelled "s1" and "s2" are DKIM domain keys. Thanks to them, Quanda signs emails with your domain, so DMARC passes in alignment with the sender address. Detailed steps, including setup with different DNS providers, are in the guide How to set up DNS records for sending.

2. Dedicated IP address: we look after the DNS records for you

Gmail and Yahoo require sending IP addresses to have valid forward and reverse DNS records. We take care of this on our side, for shared as well as dedicated IP addresses.

What you need to do:

  1. Whether you have a dedicated IP address for sending emails from Quanda, you can check in Settings / Your account / Plan settings, in the Extensions section.
  2. If you do, no action is needed on your side. We check the DNS records for your dedicated IP address.

When a dedicated IP address pays off is explained in the guide DKIM, SPF, DMARC, link branding and sending domain verification.

3. Do not send bulk emails from free email addresses

If your sender address is, for example, @gmail.com, @yahoo.com or @outlook.com, you need to change it to an address on your company domain as soon as possible. You cannot set up SPF, DKIM or DMARC on someone else's domain.

If you send your bulk emails from an @gmail.com address, Gmail treats them as impersonation because they do not leave from its servers. It will not deliver such emails to Gmail inboxes. Other mailbox providers take a similar approach.

What you need to do:

  1. If you send bulk emails from a domain where you cannot set DNS records, change the email of the Quanda user you use as the sender. Use an address on a domain you have access to and where you can set the required DNS records.
  2. Set up the records for the new domain as described in step 1.

4. Keep your spam complaint rate below 0.3 %

Senders must keep the spam complaint rate in Google Postmaster Tools below 0.3 %. Google recommends keeping it below 0.1 % and never reaching the 0.3 % threshold. From 0.3 % upwards, inbox delivery gets significantly worse.

What you need to do:

  1. Check whether you have Google Postmaster Tools set up.
  2. If not, set it up today. All it takes is signing in with a Google account and verifying your sending domain. You will find valuable information about sending from your domain there, including domain and IP reputation, the spam complaint rate, delivery errors and much more.

You will find very valuable information about sending from your domain there, including your reputation.

Jan Spáčil, CEO QuandaJan SpáčilCEO Quanda
The Google Postmaster Tools home page with the heading Be a better sender and a Get Started button
Google Postmaster Tools shows the spam complaint rate, domain reputation and Gmail delivery errors.

Tip: The complaint rate is calculated from emails delivered to the inbox. Most complaints come from people who do not remember subscribing. Send only to contacts who gave you consent or do business with you, do not hide the unsubscribe link and remove inactive contacts from time to time. Why an unsubscribe is better than a complaint is explained in the article My email was opened by only 20 % of people.

5. Offer one-click unsubscribe

Bulk senders must support one-click unsubscribe in marketing emails and include a clearly visible unsubscribe link in the email body. Yahoo requires unsubscribe requests to be honoured within 2 days, Google recommends within 48 hours.

In Quanda, an unsubscribe link is part of every email campaign. When a recipient clicks it, Quanda immediately sets their status to "We cannot send (unsubscribed)" and the contact no longer appears among the recipients of further campaigns.

What you need to do:

  1. Do not hide the unsubscribe link in small print or in a colour that blends into the background.
  2. Do not delete unsubscribed contacts in Quanda. Deleting them also deletes the unsubscribe information, and you could accidentally import the contact again. More in the guide Unsubscribed contacts.

6. How to set up a DMARC record

DMARC (Domain-based Message Authentication, Reporting & Conformance) is a DNS record that tells mailbox providers what to do with an email that fails both SPF and DKIM checks aligned with the sender's domain, and where to send you reports. It builds on SPF and DKIM records and does not authenticate anything by itself.

How can that happen when you have everything set up correctly? Very easily. Someone impersonates you and sends emails in your name. Since they have no access to your domain's DNS records, SPF and DKIM checks fail for their emails. The DMARC record then tells Gmail, Yahoo, Outlook.com and other providers whether to deliver such an email, move it to junk or reject it.

Anatomy of a DMARC record

Tag Example value Meaning
v DMARC1 Version. Identifies the record as DMARC and must come first.
p none Policy for emails that fail the check: none (monitor only), quarantine (to junk) or reject.
pct 100 Percentage of emails the policy applies to, a whole number from 0 to 100.
rua mailto:you@yourdomain.com Address that receives aggregate reports. Separate multiple addresses with a comma.
sp none Policy for subdomains, same values as p.
aspf r SPF alignment mode: r (relaxed) or s (strict).
adkim r DKIM alignment mode: r (relaxed) or s (strict).

An example DMARC record to start with:

v=DMARC1; p=none; pct=100; rua=mailto:you@yourdomain.com; sp=none; aspf=r; adkim=r;

How to check whether you have a DMARC record

  1. Open the DMARC Check tool on the MxToolbox website, or another DMARC checking tool.
  2. Enter your sending domain in the empty field. The sending domain is the part of the address after the @ sign. For us it is "quanda.com", because we send from addresses such as "name@quanda.com".
  3. Look at the result.
  4. If you do not have a DMARC record, add one following the steps below.
The DMARC Check tool on the MxToolbox website with an empty Domain Name field and a DMARC Lookup button
Enter your sending domain in the Domain Name field and click DMARC Lookup.

Adding a DMARC record step by step

  1. Copy the record from the example above and replace "you@yourdomain.com" with a valid email address where you will receive the reports.
  2. Sign in to the service that manages your domain's DNS records (usually your domain registrar or hosting provider) and create the DMARC record:
    1. Add a new record of type TXT.
    2. Enter _dmarc as the name. The full name should be _dmarc.yourdomain.com, but DNS providers usually append the domain to the name automatically.
    3. Paste the copied record as the value.
    4. Set the TTL to 3600.
    5. Save the record and check that it appears in your DNS.
  3. Monitor the reports that start arriving at the address you entered.
  4. Check that all emails you send from the domain, not just from Quanda, pass SPF and DKIM. See step 7.
  5. Once you have confirmed, also with the help of DMARC reports, that all your sending is set up correctly, change p=none to p=quarantine in the record and later to p=reject.

Watch out: Do not switch to quarantine or reject straight away. If any system sends emails from your domain without SPF and DKIM, its emails will stop arriving. For Gmail, Yahoo and Outlook.com, p=none is enough.

7. Check every place you send emails from

Do not forget SPF and DKIM for regular emails, notifications or emails from your website or online shop that are sent from the same domain.

Once you start using a DMARC record, all emails you send from that sending domain will be checked.

Jan Spáčil, CEO QuandaJan SpáčilCEO Quanda

If some of them cannot be verified with SPF and DKIM, mailbox providers will handle them according to your DMARC policy.

What you need to do:

  1. Make a list of every place that sends emails from the domain you use in Quanda for bulk emails. Typically company mail, your online shop, invoicing system, CRM, booking system or web forms.
  2. Check that outgoing emails from all these places have SPF and DKIM set up.
  3. If they do, everything is fine.
  4. If not, add SPF and DKIM. DMARC reports will help too, as they show every server that sends from your domain.

Tip: You can send bulk emails from a subdomain, such as info.company.com. That way the reputation of your marketing campaigns mixes less with your regular company mail. The subdomain needs to be verified in Quanda just like the main domain. The main domain's DMARC record covers subdomains through the sp tag, and subdomains count towards the 5,000 email limit.

What to check in Quanda right now

  • Open Settings / Domain & DNS verification and confirm the green ticks next to all three CNAME records.
  • Make sure all users send from an address on your company domain, not a free email address.
  • Check that your domain has a DMARC record with at least a p=none policy.
  • Set up Google Postmaster Tools and monitor your spam complaint rate.
  • List every place that sends email from your domain and check SPF and DKIM for each of them.
  • Go through the DMARC reports and only then tighten the policy.

Final word

If you have any questions or are not sure how to proceed, contact us at support@onquanda.com or call +420 605 163 892. We will help you check your settings and add all the DNS records. The online course Email Deliverability from A to Z explains deliverability in context, from domain authentication to metrics. If you would like to go through the whole setup together, book a free consultation.