Last updated: February 2026. Google and Yahoo's sender requirements first landed in October 2023 and formally took effect in February 2024. As of 2026 they are enforced much more consistently, and the checklist for staying out of spam has grown from three items into a fuller set of technical requirements. This guide walks through every one of them so you can check your setup in minutes.
If you send marketing email, transactional email, or even a high volume of one-to-one email from a business domain, these requirements almost certainly affect you.
Who does this apply to?
Google's official threshold is 5,000 messages per day to Gmail addresses, measured across your entire organization. In practice, though:
- Smaller senders who ignore these requirements still see declining deliverability, because the underlying signals (SPF/DKIM/DMARC) are increasingly used for all inbox placement decisions, not just the bulk-sender threshold.
- If you use a shared sending domain via any marketing platform, your reputation is tied to every other sender on that platform — authentication is your best defense.
Bottom line: treat these as best practices for every domain that sends any email, not just high-volume senders.
The full 2026 requirement checklist
There are now more than just the original three requirements. Here is the complete set Google and Yahoo expect senders to meet in 2026.
1. A valid SPF or DKIM record (ideally both)
Your domain needs at least one working authentication method. Both is strongly recommended, since DMARC alignment can pass on either.
2. A DMARC record for your sending domain
This is the requirement that catches most senders. At minimum:
`
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com;
`
This won't block anything yet, but it satisfies the "has a DMARC record" check and starts collecting aggregate reports so you can see who's sending as you.
3. DMARC alignment for the visible From domain
Just having a DMARC record isn't enough in 2026 — the SPF or DKIM domain must align with the address recipients actually see in the From header. Google and Yahoo now evaluate whether either an SPF envelope-from or a DKIM d= domain matches the From domain. Non-aligned mail increasingly fails, even when the underlying records exist.
4. One-click unsubscribe for bulk senders
If you're a bulk sender (the 5,000/day threshold), Gmail and Yahoo require List-Unsubscribe and List-Unsubscribe-Post headers that support one-click unsubscribe. Google has been publicly de-prioritizing — and in some cases blocking — senders that don't offer it.
5. Spam-rate threshold of 0.3%
Keep your complaint rate under 0.3% of messages sent (as reported through Gmail and Yahoo's feedback loops). Senders that hover around or exceed this threshold face throttling, then outright rejection.
6. Valid reverse DNS (PTR record)
Your sending IPs must have a valid, matching PTR record that resolves to a hostname, and that hostname should resolve forward back to the same IP. Gmail and Yahoo both check reverse DNS as a basic sender-reputation signal.
7. TLS for message transmission
Email should be routed over TLS (encrypted transport) where possible. Google and Yahoo increasingly flag servers that only accept plaintext SMTP. You don't need to control the recipient's MX, but your own outbound connections and your ESP's should be TLS-capable.
What happens if you don't comply?
Google has stated non-compliant bulk senders will see increasing rates of temporary errors and rejections, not just spam-folder placement. Yahoo has signaled similar enforcement. For smaller senders below the bulk threshold, the risk is more gradual: missing authentication increasingly correlates with spam-folder placement across all major providers, not just Google.
A step-by-step compliance checklist
Work through these in order and you'll be compliant before you know it.
- Confirm your sending IPs have valid reverse DNS (PTR). Ask your hosting or ESP to verify each IP reverse-resolves to a hostname.
- Add SPF (if missing) and enable DKIM through your email provider. Both is best.
- Publish a
p=noneDMARC record so you start collecting reports without any risk of blocking legitimate mail. - Review DMARC aggregate reports (or use a monitoring tool) to confirm every legitimate sending source passes alignment with your From domain.
- Move DMARC policy to
p=quarantine, thenp=rejectonce reports are clean. - Add one-click unsubscribe headers (
List-Unsubscribe+List-Unsubscribe-Post) to every bulk message. - Keep your complaint rate under 0.3% and monitor it through Gmail and Yahoo's feedback loops.
- Confirm TLS is enabled on your outbound mail path.
- Monitor continuously — DNS records get overwritten during platform migrations, registrar changes, and staff turnover far more often than teams expect.
Frequently asked questions
Does the 0.3% spam-rate rule apply to all senders?
Strictly speaking, the enforceable threshold applies to bulk senders (5,000+ messages/day to Gmail or Yahoo). However, keeping your rate far under 0.3% is smart for senders of any size, because complaint rate drives reputation — and reputation drives inbox placement even below the official threshold.
What counts as "aligned" for DMARC?
DMARC alignment passes if either your SPF domain (envelope-from) or your DKIM signing domain (d=) matches the domain in the visible From header. You don't need both to pass — you need at least one that aligns.
Can I send without DMARC and still hit the inbox?
You can, sometimes — but it's increasingly risky. Gmail and Yahoo actively de-prioritize senders without DMARC, and without it you also have no visibility into spoofing or who's sending as you. There's no real downside to publishing a p=none record while you work up to a stricter policy.
What's the difference between reverse DNS and SPF?
SPF says which IPs are allowed to send for your domain. Reverse DNS (PTR) says what hostname an IP maps back to. Receivers check both as basic sender-legitimacy signals, so you want both in place.
I send under 5,000 messages a day. Do I still need one-click unsubscribe?
The strict one-click unsubscribe requirement is aimed at bulk senders. That said, adding List-Unsubscribe headers is cheap, reduces complaint rates, and future-proofs you for when your volume grows past the threshold.
Check your compliance in seconds
MailPosture's free scanner checks your SPF, DKIM, and DMARC setup against exactly these requirements and gives you the ready-to-paste DNS records to fix anything missing. You can also see how DKIM and DMARC fit together in our SPF, DKIM, and DMARC explained guide, or dive into the DKIM vs DMARC comparison.