Gmail, Yahoo and Outlook sender requirements — what a small business newsletter needs
Gmail and Yahoo require every sender to have SPF or DKIM and a spam rate below 0.3%. DMARC and one-click unsubscribe only come in at high sending volumes. Here is where the line is, each provider’s own wording and how seven email tools handle authentication.
The mailbox providers have published unambiguous requirements for senders. Some apply to every sender regardless of volume, others only to large ones. This page is read directly from the providers’ own guides, and every requirement links to its source.
The short answer
If you send a newsletter from your own domain through an email tool, you need domain authentication: the DKIM and SPF records the tool gives you, added to your DNS settings. That meets the authentication requirement that applies to every sender. Add a DMARC record at the same time, because it is required from bulk senders and most tools hand it to you ready-made. An unsubscribe link and a low spam rate are a matter of content and list hygiene, not technology.
What every sender must do
Google’s sender guidelines split the requirements into two parts. The first has applied since 1 February 2024 to everyone who sends messages to Gmail accounts:
- SPF or DKIM for the sending domain.
- Valid forward and reverse DNS (PTR) for the sending domains or IP addresses.
- A TLS connection for transmitting messages.
- A spam rate below 0.3% as reported in Postmaster Tools. Google recommends keeping it below 0.1%.
- Formatting according to RFC 5322, and the From header must not impersonate Gmail.
Yahoo’s sender guidelines say almost the same for all senders: at least SPF or DKIM, a spam rate below 0.3%, valid reverse DNS and compliance with RFC 5321 and 5322.
If you send through an email tool, reverse DNS, TLS and message formatting are handled by the tool’s sending servers. What stays with you is your domain’s DNS records and the spam rate — in other words, who you send to.
What bulk senders must do on top
The second part of Google’s guide applies to senders who send more than 5,000 messages a day to Gmail accounts. They must have:
- SPF and DKIM, both, not just one.
- A DMARC record, for which a policy of
p=noneis enough. - Alignment: the domain in the From header must match either the SPF or the DKIM domain.
- One-click unsubscribe for marketing messages, and a visible unsubscribe link in the message body.
Yahoo calls the same group bulk senders and requires SPF and DKIM, a passing DMARC policy of at least p=none, alignment and a visible unsubscribe link. A working List-Unsubscribe header that supports one-click unsubscribe is also required: Yahoo strongly recommends the RFC 8058 method, where the recipient’s click is enough without further confirmation, but also accepts the mailto method. Yahoo’s guide also sets a deadline: unsubscribes must be honoured within two days.
Microsoft followed the same line in 2025. According to Microsoft’s blog post (2 April 2025, updated 29 April), a domain that sends more than 5,000 messages a day to Outlook.com consumer addresses (hotmail.com, live.com, outlook.com) must pass SPF and DKIM and publish an aligned DMARC record with a policy of at least p=none. For Microsoft a working unsubscribe link is a recommendation, not a requirement.
The three providers side by side
| Requirement | Gmail, everyone | Gmail, over 5,000/day | Yahoo, everyone | Yahoo, bulk sender | Outlook.com, over 5,000/day |
|---|---|---|---|---|---|
| SPF | SPF or DKIM | Yes | SPF or DKIM | Yes | Yes |
| DKIM | SPF or DKIM | Yes | SPF or DKIM | Yes | Yes |
| DMARC | — | p=none is enough | — | p=none is enough | p=none is enough |
| One-click unsubscribe | — | Yes | — | Yes | Recommended |
| Spam rate | Below 0.3% | Below 0.3% | Below 0.3% | Below 0.3% | — |
← scroll →
Sources: Google, Yahoo and Microsoft’s blog, read on 24 September 2026. “—” means the guide does not require this from that group.
The DMARC record: what it is and how to add it
A DMARC record tells the receiving server what to do with a message that fails the SPF or DKIM check. According to Google’s DMARC guide, it is a TXT record at _dmarc. followed by your domain, and the v and p tags come first in the record. This format works as a starting point:
v=DMARC1; p=none; rua=mailto:postmaster@yourdomain.com
The p=none policy does not ask for anything to be rejected; the record only says that the domain monitors authentication. Google recommends starting with exactly that. The rua tag gives the address that reports are sent to, and Yahoo strongly recommends it for monitoring in the early stage. Move to a stricter policy, such as quarantine or reject, only once the reports show that all of the domain’s messages pass the check.
Usually you do not have to write the record yourself. Six of the seven tools we compare provide a DMARC record as part of domain authentication. MailerLite’s help page gives an example record but recommends getting an expert to set up DMARC.
How seven email tools handle authentication
The table below is read from each tool’s own help pages. Every cell links to the page the information comes from.
| Tool | SPF/DKIM/DMARC records from the app | DMARC guidance |
|---|---|---|
| Systeme.io | Yes | Yes |
| EmailOctopus | Yes | Yes |
| Brevo | Yes | Yes |
| MailerLite | Yes | No |
| Mailchimp | Yes | Yes |
| GetResponse | Yes | Yes |
| ActiveCampaign | Yes | Yes |
← scroll →
Yes = the help page describes the feature. No = the help page says it is absent or points to an external tool. — = not found in the help pages; that does not mean the feature is absent.
Authentication works the same way in all of them: the tool gives you three to five DNS records (usually CNAME records for DKIM and a TXT record for DMARC), you add them to your domain’s DNS settings, and the tool checks them. The differences are in whether the tool does it for you. Brevo and GetResponse offer automatic authentication by logging in to your DNS provider, ActiveCampaign replaces an unauthenticated sender with a generic address, and Systeme.io points you to external tools for checking the records.
Your own domain is a precondition
Everything above assumes that you send from your own domain, for example news@yourcompany.com. According to MailerLite’s help page, the domain of a free email provider, such as a gmail.com address, cannot be authenticated, because you have no access to its DNS records. According to Google’s sender guidelines, Gmail also applies a DMARC quarantine policy to messages that impersonate Gmail, so a newsletter sent through a tool from a gmail.com address is likely to end up in spam.
Your own domain is therefore the first thing to get before a newsletter, and it is worth keeping in mind when choosing a free plan too. What your own domain means on free plans is covered in the free email marketing comparison.
What to do now, while the list is small
- Authenticate your domain following your tool’s instructions, and add a DMARC record at the same time, even if you send little.
- Check the unsubscribe link in every campaign, including templates you built yourself. The data protection side of unsubscribing is covered in our guide to email marketing and GDPR.
- Keep the spam rate low: send only to people who subscribed, and clean out bouncing addresses.
If you are still choosing a tool, the comparison of email marketing software shows prices at three list sizes, and MailerLite vs Brevo compares two popular options side by side.