Gmail, Yahoo and Outlook sender requirements — what a small business newsletter needs

Gmail and Yahoo require every sender to have SPF or DKIM and a spam rate below 0.3%. DMARC and one-click unsubscribe only come in at high sending volumes. Here is where the line is, each provider’s own wording and how seven email tools handle authentication.

The mailbox providers have published unambiguous requirements for senders. Some apply to every sender regardless of volume, others only to large ones. This page is read directly from the providers’ own guides, and every requirement links to its source.

The short answer

If you send a newsletter from your own domain through an email tool, you need domain authentication: the DKIM and SPF records the tool gives you, added to your DNS settings. That meets the authentication requirement that applies to every sender. Add a DMARC record at the same time, because it is required from bulk senders and most tools hand it to you ready-made. An unsubscribe link and a low spam rate are a matter of content and list hygiene, not technology.

What every sender must do

Google’s sender guidelines split the requirements into two parts. The first has applied since 1 February 2024 to everyone who sends messages to Gmail accounts:

  • SPF or DKIM for the sending domain.
  • Valid forward and reverse DNS (PTR) for the sending domains or IP addresses.
  • A TLS connection for transmitting messages.
  • A spam rate below 0.3% as reported in Postmaster Tools. Google recommends keeping it below 0.1%.
  • Formatting according to RFC 5322, and the From header must not impersonate Gmail.

Yahoo’s sender guidelines say almost the same for all senders: at least SPF or DKIM, a spam rate below 0.3%, valid reverse DNS and compliance with RFC 5321 and 5322.

If you send through an email tool, reverse DNS, TLS and message formatting are handled by the tool’s sending servers. What stays with you is your domain’s DNS records and the spam rate — in other words, who you send to.

What bulk senders must do on top

The second part of Google’s guide applies to senders who send more than 5,000 messages a day to Gmail accounts. They must have:

  • SPF and DKIM, both, not just one.
  • A DMARC record, for which a policy of p=none is enough.
  • Alignment: the domain in the From header must match either the SPF or the DKIM domain.
  • One-click unsubscribe for marketing messages, and a visible unsubscribe link in the message body.

Yahoo calls the same group bulk senders and requires SPF and DKIM, a passing DMARC policy of at least p=none, alignment and a visible unsubscribe link. A working List-Unsubscribe header that supports one-click unsubscribe is also required: Yahoo strongly recommends the RFC 8058 method, where the recipient’s click is enough without further confirmation, but also accepts the mailto method. Yahoo’s guide also sets a deadline: unsubscribes must be honoured within two days.

Microsoft followed the same line in 2025. According to Microsoft’s blog post (2 April 2025, updated 29 April), a domain that sends more than 5,000 messages a day to Outlook.com consumer addresses (hotmail.com, live.com, outlook.com) must pass SPF and DKIM and publish an aligned DMARC record with a policy of at least p=none. For Microsoft a working unsubscribe link is a recommendation, not a requirement.

The three providers side by side

RequirementGmail, everyoneGmail, over 5,000/dayYahoo, everyoneYahoo, bulk senderOutlook.com, over 5,000/day
SPFSPF or DKIMYesSPF or DKIMYesYes
DKIMSPF or DKIMYesSPF or DKIMYesYes
DMARC—p=none is enough—p=none is enoughp=none is enough
One-click unsubscribe—Yes—YesRecommended
Spam rateBelow 0.3%Below 0.3%Below 0.3%Below 0.3%—

Sources: Google, Yahoo and Microsoft’s blog, read on 24 September 2026. “—” means the guide does not require this from that group.

The DMARC record: what it is and how to add it

A DMARC record tells the receiving server what to do with a message that fails the SPF or DKIM check. According to Google’s DMARC guide, it is a TXT record at _dmarc. followed by your domain, and the v and p tags come first in the record. This format works as a starting point:

v=DMARC1; p=none; rua=mailto:postmaster@yourdomain.com

The p=none policy does not ask for anything to be rejected; the record only says that the domain monitors authentication. Google recommends starting with exactly that. The rua tag gives the address that reports are sent to, and Yahoo strongly recommends it for monitoring in the early stage. Move to a stricter policy, such as quarantine or reject, only once the reports show that all of the domain’s messages pass the check.

Usually you do not have to write the record yourself. Six of the seven tools we compare provide a DMARC record as part of domain authentication. MailerLite’s help page gives an example record but recommends getting an expert to set up DMARC.

How seven email tools handle authentication

The table below is read from each tool’s own help pages. Every cell links to the page the information comes from.

ToolSPF/DKIM/DMARC records from the appDMARC guidance
Systeme.ioYesYes
EmailOctopusYesYes
BrevoYesYes
MailerLiteYesNo
MailchimpYesYes
GetResponseYesYes
ActiveCampaignYesYes

Yes = the help page describes the feature. No = the help page says it is absent or points to an external tool. — = not found in the help pages; that does not mean the feature is absent.

Authentication works the same way in all of them: the tool gives you three to five DNS records (usually CNAME records for DKIM and a TXT record for DMARC), you add them to your domain’s DNS settings, and the tool checks them. The differences are in whether the tool does it for you. Brevo and GetResponse offer automatic authentication by logging in to your DNS provider, ActiveCampaign replaces an unauthenticated sender with a generic address, and Systeme.io points you to external tools for checking the records.

Your own domain is a precondition

Everything above assumes that you send from your own domain, for example news@yourcompany.com. According to MailerLite’s help page, the domain of a free email provider, such as a gmail.com address, cannot be authenticated, because you have no access to its DNS records. According to Google’s sender guidelines, Gmail also applies a DMARC quarantine policy to messages that impersonate Gmail, so a newsletter sent through a tool from a gmail.com address is likely to end up in spam.

Your own domain is therefore the first thing to get before a newsletter, and it is worth keeping in mind when choosing a free plan too. What your own domain means on free plans is covered in the free email marketing comparison.

What to do now, while the list is small

  1. Authenticate your domain following your tool’s instructions, and add a DMARC record at the same time, even if you send little.
  2. Check the unsubscribe link in every campaign, including templates you built yourself. The data protection side of unsubscribing is covered in our guide to email marketing and GDPR.
  3. Keep the spam rate low: send only to people who subscribed, and clean out bouncing addresses.

If you are still choosing a tool, the comparison of email marketing software shows prices at three list sizes, and MailerLite vs Brevo compares two popular options side by side.

Frequently asked questions

Do Gmail’s sender requirements apply to a small newsletter?
Yes. The basic requirements in Google’s guide apply to everyone sending to Gmail accounts: SPF or DKIM, valid reverse DNS, a TLS connection, formatting according to RFC 5322 and a spam rate below 0.3%. DMARC and one-click unsubscribe become mandatory only when you send more than 5,000 messages a day to Gmail accounts.
Do I need a DMARC record?
In Google’s and Yahoo’s guides DMARC is mandatory for bulk senders, and a policy of p=none is enough. For smaller senders it is not a requirement in Google’s guide, but six of the seven email tools we compare add a DMARC record as part of domain authentication, so it usually comes with the same job.
What does a DMARC record look like?
It is a TXT record at _dmarc.yourdomain.com. A good starting point is v=DMARC1; p=none; rua=mailto:postmaster@yourdomain.com. According to Google’s guide the v and p tags come first, and none is the recommended policy to begin with.
Can I send a newsletter from a gmail.com address?
It is not a good idea. According to MailerLite’s help page, the domain of a free email provider cannot be authenticated, and you have no access to the DNS records of gmail.com. Google also says it applies a DMARC quarantine policy to messages that impersonate Gmail.
What happens if I do not meet the requirements?
According to Google’s guide, unauthenticated messages may be marked as spam or rejected with error 5.7.26. According to Microsoft, from 5 May 2025 Outlook.com routes messages that fail the requirements to the junk folder, and later rejects them with error 550 5.7.515.
How is the 5,000 message limit counted?
Google’s guide refers to messages sent to Gmail accounts per day, so the limit covers only messages to gmail.com and googlemail.com addresses. Microsoft’s requirements apply to domains that send more than 5,000 messages a day to Outlook.com consumer addresses.

Ad link

More information