Gmail, Yahoo and Microsoft sender requirements
What Gmail, Yahoo, and Microsoft require of a sending domain, which rules cover transactional mail, and what the rejection codes mean.
Set up SPF or DKIM, add DMARC once volume rules apply, and keep complaints low. Gmail and Yahoo require both SPF and DKIM, plus DMARC, for bulk senders. Microsoft requires all three for high-volume domains sending to its consumer email services. A password reset is not exempt from authentication. Gmail and Yahoo exempt it from one-click unsubscribe, while Microsoft recommends visible, functional unsubscribe links, particularly for marketing and bulk mail.
The FAQ calls a bulk sender anyone who sends "close to 5,000 messages or more to personal Gmail accounts within a 24-hour period." The guidelines also say "more than 5,000 messages per day". Messages from the same primary domain count together, so 2,500 from solarmora.com and 2,500 from promotions.solarmora.com are one sender. Gmail's bulk-sender classification is permanent once assigned. Yahoo's FAQ says a bulk sender sends "a significant volume of mail" and that Yahoo "will not specify a volume threshold." Microsoft's policies specify more than 5,000 emails a day to Outlook.com accounts, and its NDR guide specifies 5,000 or more from one From domain.
Who the rules cover
Gmail's guidelines cover @gmail.com and @googlemail.com. They do not apply to mail sent to Google Workspace accounts, and they do apply when a Workspace user sends to a personal Gmail account. Yahoo covers "all domains and consumer email brands hosted by Yahoo Mail." Yahoo Japan is a separate entity. Spoofed mail counts, and Yahoo views the sender at the authenticated domain or the From domain. Microsoft's 2 April 2025 announcement applies to hotmail.com, live.com, and outlook.com. Under 5,000 emails a day it calls authentication a benefit and says enforcement first targets large senders. The announcement and policies do not describe a rolling 24-hour window, a primary-domain total, or a status that stays forever.
What each provider requires
| Requirement | Gmail personal accounts | Yahoo Mail | Outlook.com consumer |
|---|---|---|---|
| Who | All senders from 1 February 2024. Stricter set above the bulk line. | All senders, plus a bulk set. No published message count. | High-volume domains. The policies specify over 5,000/day; the NDR guide specifies 5,000 or more from one From domain. |
| SPF | All senders: SPF or DKIM. Bulk: both. | All senders: SPF or DKIM. Bulk: both. | High volume: must pass. |
| DKIM | DKIM is required for bulk senders; other senders may use SPF instead. Personal Gmail: key of 1024 bits or longer. 2048 recommended. | Bulk: both. FAQ: 1024 bits or greater. 2048 recommended. | High volume: must pass. No key length on these pages. |
| DMARC | Bulk. Policy can be p=none. | Bulk: at least p=none, and DMARC must pass. rua is strongly recommended, not required. | High volume: at least p=none, aligned with SPF or DKIM. p=reject is recommended. |
| Alignment | Bulk direct mail: From aligned with SPF or DKIM. One is enough. Forwarded mail and lists are exempt. | Relaxed alignment is acceptable. From aligned with SPF or DKIM. | DMARC must pass through aligned SPF or DKIM. Both SPF and DKIM must still pass authentication. |
| PTR | Sending IP matches the PTR hostname, and that name has an A or AAAA record back to the same IP. | Valid forward and reverse DNS. Meaningful, non-generic PTR is a recommendation. | Not in the high-volume list. General rule: valid reverse DNS. Dynamic IP space may not be accepted. |
| TLS | Required for all senders and bulk senders. | Not stated on the requirements, FAQ, or error pages. | Not stated on the announcement or the two postmaster pages. |
| One-click unsubscribe | Bulk marketing and subscribed mail. Transactional messages are excluded. A visible unsubscribe link is also required in the body. | Bulk marketing and subscribed mail. Transactional messages are excluded. A visible unsubscribe link is also required in the body. A mailto method in the List-Unsubscribe header is acceptable. | Functional unsubscribe links are recommended; the announcement states no RFC 8058 mandate. |
| Complaint rate | Postmaster Tools below 0.3%. Stay below 0.10%. Avoid 0.30% or higher. | Below 0.3%, on mail delivered to the inbox. | No percentage on these pages. |
DMARC, complaint rates and unsubscribe rules
Bulk senders to Gmail set up both SPF and DKIM. The sender FAQ says "only one of these needs to be aligned", and forwarded mail and mailing lists are outside that rule. Google's DMARC setup page describes p=none as taking no action and delivering the message, while logging it. That is the policy tag, not proof the message passed. Yahoo's bulk rule is at least p=none and "DMARC must pass". Missing DMARC can prevent delivery support and cause deferral or rejection. The FAQ lists 4.7.31; the SMTP catalog lists 421 4.7.40 and 550 5.7.40.
Gmail calculates the Postmaster Tools spam rate daily, and above 0.1% bulk inbox delivery is already affected. Bulk senders with a spam rate above 0.3% lose eligibility for delivery support, which returns after 7 consecutive days below 0.3%. Yahoo may defer mail from a domain with a high complaint rate. If people report your mail as spam at Outlook.com, the announcement points you at content, frequency, and the opt-out.
Gmail's one-click rule is "required only for marketing and promotional messages." Transactional messages are excluded, including password reset messages, reservation confirmations, and form submission confirmations. Headers must meet RFC 8058. Gmail's example is List-Unsubscribe-Post: List-Unsubscribe=One-Click plus an HTTPS List-Unsubscribe URL, and a mailto link does not meet Gmail's rule. The required body link may lead to a preferences page; it does not replace the unsubscribe header. Honor Gmail unsubscribe requests within 48 hours to remain eligible for delivery support. Missing one-click unsubscribe does not automatically cause rejection or spam placement. Yahoo accepts a mailto method in the List-Unsubscribe header, expects action within 2 days, and will not decide which messages need the link.
What transactional mail still has to do
At Gmail and Yahoo, staying under the bulk line does not drop authentication, DNS, or the complaint rate. Personal Gmail also requires TLS and RFC 5322, and Yahoo requires RFC 5321 and RFC 5322. One-click unsubscribe is the item the Gmail and Yahoo FAQs exclude for the transactional examples above.
Above the bulk line, DMARC applies even to receipts. On Gmail's FAQ, the gaps are failed alignment, mail without both SPF and DKIM, DNS, TLS, or RFC 5322. Any of them can mean a temporary failure, a permanent failure, or the spam folder. Spam-rate and unsubscribe compliance also affect eligibility for delivery support. A domain that has not sent more than 5,000 messages a day to personal Gmail since 1 January 2024 is on a faster timetable.
Microsoft requires high-volume senders to pass SPF, DKIM and DMARC, with at least p=none. Safe-sender lists do not bypass Microsoft's high-volume authentication enforcement.
Rejection codes
Gmail's 5.7.26 is an authentication or DMARC failure, not a missing mailbox. A missing mailbox is covered in 550 5.1.1 user unknown.
| Reply | What the provider documents |
|---|---|
Gmail 421 4.7.26 | "This email has been rate limited because it is unauthenticated." SPF or DKIM is required. |
Gmail 550 5.7.26 | "This email has been blocked because the sender is unauthenticated." Also used for an SPF -all failure, and when the domain's DMARC policy refuses unauthenticated mail. |
Gmail 451 4.7.26 | DMARC policy refuses the mail, but a temporary DNS failure prevents authentication. |
Gmail 421 4.7.27, 550 5.7.27 | SPF authentication failed on bulk-sender mail. |
Gmail 421 4.7.30, 550 5.7.30 | DKIM did not pass. Bulk senders. |
Gmail 421 4.7.32 | From is not aligned with the SPF or DKIM organizational domain. The catalog also lists 421 5.7.32 for a block with that sentence. |
Gmail 421 4.7.40, 550 5.7.40 | No DMARC record, or no policy in the record. The FAQ lists 4.7.31 for this condition and does not list 4.7.40. |
Gmail 451 4.7.23, 550 5.7.25 | No PTR, or forward DNS does not match the sending IP. The FAQ's temporary description is 4.7.23. |
Gmail 421 4.7.29, 550 5.7.29 | Not sent over TLS. Bulk senders. |
Gmail 421 4.7.28 | Unusual rate or quota. Wait at least 10 minutes before sending again. |
Yahoo 421, 451, TS* | Temporary. You may retry. Causes on the page include user complaints and a temporary authentication failure. TS* is a temporary deferral. Yahoo's error page groups failures by basic SMTP codes and labels such as TS* and PH*. |
Yahoo 553, 554 | Permanent. Do not retry a 5xx. Includes a DMARC or DKIM authentication failure. PH* is a content block. Other policy errors include 550 and 554. |
Outlook.com 550; 5.7.515 | "Access denied, sending domain [SendingDomain] does not meet the required authentication level." |
Gmail's wording is on the SMTP error list. The guidelines also say unauthenticated mail might be rejected with a 5.7.26 error. The FAQ and that catalog disagree on the temporary code for a missing DMARC record, 4.7.31 versus 4.7.40, so match the sentence you received. Yahoo's SMTP error page says not to retry a 5xx. After a code from 500 through 599, Microsoft's policies page says not to retransmit that message. Sendtier suppresses on an Amazon SES bounce type of Permanent, and on complaints, not on the SMTP digits.
What changed since 2024
Gmail's requirement list is still the 1 February 2024 list. Senders who already had an unsubscribe link had until 1 June 2024 to add one-click unsubscribe on commercial and promotional mail. From November 2025 the FAQ says Gmail "is ramping up its enforcement on non-compliant traffic", including temporary and permanent rejections. It does not say the requirement text changed, and it names no end date. Postmaster Tools has a Compliance status dashboard.
Yahoo's pages still describe a February 2024 start and a rollout through the first half of that year, with List-Unsubscribe enforcement from June 2024. They do not document a 2025 or 2026 rule change.
Microsoft's April 2025 update announced authentication rejections from 5 May 2025 using 550 5.7.515, and the previous junk-first timeline is crossed out. Its NDR guide documents this rejection, although the Postmaster policies retain junk-then-reject wording.
Check DNS and the reports
Look up the TXT record that starts with v=spf1, the DKIM record at your selector, and the TXT record at _dmarc plus the domain.
Yahoo still requires a DMARC pass when the policy is p=none. The rua mailbox receives aggregate reports. Google's setup page says Gmail does not support ruf, and Microsoft's announcement says it sends those reports and does not plan to send ruf. Yahoo recommends rua and does not require it. Use the reports to see which sources fail SPF, DKIM, or alignment.
Relaxed alignment compares organizational domains, so example.com and send.example.com align, while strict alignment requires an exact domain match (RFC 7489, section 3.1).
For Gmail's PTR rule, the hostname in the PTR record needs an A or AAAA record back to the sending IP. Postmaster Tools shows spam rate, authentication, delivery errors, and compliance. Updates typically land within 24 hours and can take longer. The Compliance status dashboard can take up to 7 days to reflect a fix, and it aggregates subdomain data under the primary domain. Yahoo's FAQ describes an ARF report from the Complaint Feedback Loop when a user marks enrolled DKIM mail as spam. Microsoft's policies page lists the Junk Email Reporting Program and Smart Network Data Services.
What Sendtier sets up
Sendtier sends through Amazon SES in AWS eu-central-1 (Frankfurt). A sending domain uses these six DNS records.
| Record | Name | Value |
|---|---|---|
| DKIM CNAME, three records | <token>._domainkey.<domain> | <token>.dkim.amazonses.com |
| MAIL FROM MX | send.<domain> | 10 feedback-smtp.eu-central-1.amazonses.com |
| SPF TXT | send.<domain> | v=spf1 include:amazonses.com ~all |
| DMARC TXT | _dmarc.<domain> | v=DMARC1; p=none; |
Sendtier's p=none record meets the minimum DMARC policy level, and messages must still pass authentication. You can later change the policy to quarantine or reject after reviewing reports. The Domains guide explains the records and verification checks.
Pending domains are re-checked every 30 seconds until they verify, then every 6 hours. A verified domain loses verification only after two failed checks in a row.
On a bounce, Sendtier keeps the SES type (Permanent, Transient, or Undetermined), the subtype, and each recipient's action, status, and diagnostic code. Status is the enhanced code, such as 5.7.26, when SES includes it. The diagnostic code is the receiving server's reply when that server returns one. Permanent bounces and complaints suppress the address, and transient and undetermined bounces do not. A later send to a suppressed address fails with 422 recipient_suppressed. The suppressions API lets you add, list and remove your organization's suppression entries.
Test-key emails are never delivered. Live sending is limited during the public preview. Start free with a test key in the quickstart.