[{"data":1,"prerenderedAt":345},["ShallowReactive",2],{"legal-pages":3,"guide:\u002Fblog\u002Fgmail-yahoo-bulk-sender-rules":13},[4,7,9,11],{"path":5,"draft":6},"\u002Flegal\u002Facceptable-use",false,{"path":8,"draft":6},"\u002Flegal\u002Fprivacy",{"path":10,"draft":6},"\u002Flegal\u002Fsubprocessors",{"path":12,"draft":6},"\u002Flegal\u002Fterms",{"id":14,"title":15,"author":16,"body":17,"date":329,"description":330,"draft":6,"extension":331,"meta":332,"navigation":333,"path":334,"seo":335,"stem":336,"tags":337,"tool":342,"updated":343,"__hash__":344},"blog\u002Fblog\u002Fgmail-yahoo-bulk-sender-rules.md","Gmail and Yahoo's bulk sender rules, in plain English","Carrier Crow",{"type":18,"value":19,"toc":317},"minimark",[20,24,27,32,35,38,41,144,148,159,174,177,181,191,201,214,229,233,236,239,245,248,251,255,258,261,264,268,275,281,285,288,297,300,304,307,311],[21,22,23],"p",{},"In February 2024, Gmail and Yahoo stopped treating good sending practice as optional. Authentication, an easy way out, a ceiling on complaints: most of it had been advice for years. What changed is enforcement. It was phased in rather than switched on overnight, but the phase-in is long over, and a newsletter that misses the bar now risks being deferred, filtered or rejected.",[21,25,26],{},"Here is what the rules ask for, what each one means, and how to check yours.",[28,29,31],"h2",{"id":30},"who-counts-as-a-bulk-sender","Who counts as a bulk sender",[21,33,34],{},"Google defines a bulk sender as anyone sending close to 5,000 messages or more to personal Gmail accounts in a 24-hour period, counting everything sent from the same primary domain. Google has also said that once you cross that line, you're treated as a bulk sender from then on. One big issue is enough.",[21,36,37],{},"Yahoo announced matching requirements at the same time, and Microsoft has since set out similar authentication rules for high-volume senders to Outlook.com, Hotmail and Live addresses. If you're anywhere near 5,000 a day to Gmail, meet the bulk requirements everywhere.",[21,39,40],{},"Some rules apply to every sender, however small; others only to bulk senders:",[42,43,44,60],"table",{},[45,46,47],"thead",{},[48,49,50,54,57],"tr",{},[51,52,53],"th",{},"Requirement",[51,55,56],{},"Who it applies to",[51,58,59],{},"How to check",[61,62,63,75,91,101,112,123,133],"tbody",{},[48,64,65,69,72],{},[66,67,68],"td",{},"SPF and DKIM",[66,70,71],{},"Everyone needs one; bulk senders need both",[66,73,74],{},"DNS, and a received message",[48,76,77,85,88],{},[66,78,79,80,84],{},"A DMARC record, ",[81,82,83],"code",{},"p=none"," or stricter",[66,86,87],{},"Bulk senders",[66,89,90],{},"DNS",[48,92,93,96,98],{},[66,94,95],{},"From domain aligned with SPF or DKIM",[66,97,87],{},[66,99,100],{},"The DMARC result on a received message",[48,102,103,106,109],{},[66,104,105],{},"One-click unsubscribe, honoured within two days",[66,107,108],{},"Bulk senders, for marketing and subscribed mail",[66,110,111],{},"Message headers",[48,113,114,117,120],{},[66,115,116],{},"Spam rate below 0.3%",[66,118,119],{},"Everyone",[66,121,122],{},"Google Postmaster Tools",[48,124,125,128,130],{},[66,126,127],{},"Forward and reverse DNS for sending IPs",[66,129,119],{},[66,131,132],{},"A reverse lookup on the IP",[48,134,135,138,141],{},[66,136,137],{},"TLS",[66,139,140],{},"Everyone (Google)",[66,142,143],{},"Message details in Gmail",[28,145,147],{"id":146},"spf-and-dkim-proving-the-mail-is-yours","SPF and DKIM: proving the mail is yours",[21,149,150,154,155,158],{},[151,152,153],"strong",{},"SPF"," is a DNS record on your domain listing the servers allowed to send mail for it. A receiving server takes the domain from the envelope sender (the hidden return address that bounces go to, not the From line readers see) and checks whether the connecting server is on the list. Two classic mistakes: publishing more than one SPF record, which counts as an error rather than a merge, and chaining so many ",[81,156,157],{},"include:"," entries that you pass SPF's limit of ten DNS lookups. Either makes SPF fail while the record looks fine at a glance.",[21,160,161,164,165,169,170,173],{},[151,162,163],{},"DKIM"," is a cryptographic signature the sending server adds to each message. The matching public key lives in DNS under a ",[166,167,168],"em",{},"selector"," you or your provider choose, at an address like ",[81,171,172],{},"s1._domainkey.example.com",". Because the signature travels inside the message, DKIM survives forwarding in a way SPF doesn't.",[21,175,176],{},"Miss both and Gmail has little reason to believe the mail is from you. For a bulk sender, having only one is itself out of compliance.",[28,178,180],{"id":179},"dmarc-and-the-alignment-trap","DMARC, and the alignment trap",[21,182,183,186,187,190],{},[151,184,185],{},"DMARC"," is a TXT record at ",[81,188,189],{},"_dmarc.example.com"," telling receivers what to do with mail that claims to be from your domain but fails authentication, and where to send reports. The minimum the rules ask for is a monitoring-only policy:",[192,193,198],"pre",{"className":194,"code":196,"language":197},[195],"language-text","v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com\n","text",[81,199,196],{"__ignoreMap":200},"",[21,202,203,205,206,209,210,213],{},[81,204,83],{}," means \"don't act on failures, just tell me about them\". It's a starting point: the aggregate reports it produces show every service sending as your domain, which is how you find out when it's safe to move to ",[81,207,208],{},"quarantine"," or ",[81,211,212],{},"reject",".",[21,215,216,217,220,221,224,225,228],{},"The part that catches people out is ",[151,218,219],{},"alignment",". DMARC passes only if the domain in your visible From address matches the domain that passed SPF, or the domain that signed with DKIM. By default a match at the organisational level is enough, so ",[81,222,223],{},"news.example.com"," aligns with ",[81,226,227],{},"example.com",". The trap: unless you've set up domain authentication, many providers sign with their own DKIM domain and use their own bounce domain. SPF passes, DKIM passes, and DMARC still fails, because neither passing domain is yours. Your provider's domain authentication setup fixes it by making it sign and bounce as you.",[28,230,232],{"id":231},"one-click-unsubscribe","One-click unsubscribe",[21,234,235],{},"Bulk senders must let people unsubscribe from marketing and subscribed mail (newsletters included) in one click, and must honour the request within two days. Google also wants a clearly visible unsubscribe link in the body of the message; the header doesn't replace it.",[21,237,238],{},"\"One click\" has a specific technical meaning, set out in RFC 8058. Each message carries two headers:",[192,240,243],{"className":241,"code":242,"language":197},[195],"List-Unsubscribe: \u003Chttps:\u002F\u002Fexample.com\u002Funsubscribe\u002Fabc123>\nList-Unsubscribe-Post: List-Unsubscribe=One-Click\n",[81,244,242],{"__ignoreMap":200},[21,246,247],{},"When a reader uses the unsubscribe option Gmail or Yahoo shows beside your name, the mailbox provider sends an HTTPS POST to that address and your system unsubscribes them. No login, no confirmation page. It's a POST rather than a simple visit because security software follows links on its own, and nobody should be unsubscribed by a scanner. The standard also requires both headers to be covered by the message's DKIM signature.",[21,249,250],{},"Miss this and, compliance aside, readers who can't find the way out use the one button that's always there: \"Report spam\". Which brings us to the number that matters most.",[28,252,254],{"id":253},"keep-spam-complaints-below-03","Keep spam complaints below 0.3%",[21,256,257],{},"Google wants the spam rate shown in its Postmaster Tools kept below 0.3%, and recommends staying under 0.1%. Yahoo uses the same 0.3% line. Google measures the rate against mail that reached the inbox, so 0.3% is three complaints for every thousand messages delivered there. On 20,000 Gmail inbox deliveries, that's 60 people.",[21,259,260],{},"Over the line, more of your mail goes to spam, and Google has said senders above it lose eligibility for its mitigation help until the rate comes back down. Postmaster Tools is free: you verify your domain with a DNS record, though it only shows data once you send enough mail to Gmail each day. Yahoo offers a complaint feedback loop through its Sender Hub.",[21,262,263],{},"The levers are unglamorous: confirm signups, make leaving easy, stop mailing people who never open.",[28,265,267],{"id":266},"the-plumbing-reverse-dns-and-tls","The plumbing: reverse DNS and TLS",[21,269,270,271,274],{},"Every IP address you send from needs ",[151,272,273],{},"forward and reverse DNS",": a PTR record mapping the IP to a hostname, and that hostname resolving back to the same IP. Send through SendGrid, Mailgun, Postmark or Amazon SES on their shared IPs and the provider handles this. Run your own mail server and it's on you.",[21,276,277,278,280],{},"Google also requires mail to arrive over ",[151,279,137],{},". Mainstream providers do this by default. In Gmail, a message's details read \"Standard encryption (TLS)\"; mail that arrived without it gets a red open padlock.",[28,282,284],{"id":283},"how-to-check-where-you-stand","How to check where you stand",[21,286,287],{},"Two checks cover most of it.",[21,289,290,291,296],{},"First, the DNS: SPF, DMARC, your DKIM key at its selector, and MX. MX isn't on Google's list, but replies and bounces need somewhere to go, and some receiving servers turn away mail whose return-address domain can't receive any. The ",[292,293,295],"a",{"href":294},"\u002Ftools\u002Fsender-check","sender check"," looks up all four for a domain in one go.",[21,298,299],{},"Second, a real message. Send an issue to a Gmail address, open it and choose \"Show original\". The summary at the top shows SPF, DKIM and DMARC each as PASS or FAIL. DNS tells you the records exist; only a received message tells you they line up. If DMARC says PASS, alignment is working, and the raw headers underneath show whether both unsubscribe headers made it through.",[28,301,303],{"id":302},"where-carrier-crow-fits","Where Carrier Crow fits",[21,305,306],{},"Carrier Crow isn't an email service provider. It connects to the SMTP provider you already use (SendGrid, Mailgun, Postmark, Amazon SES or any SMTP relay), so SPF, DKIM, DMARC and reverse DNS stay with your domain and your provider. The part that lives inside the message, it handles: every campaign carries the one-click List-Unsubscribe headers, whichever provider sends it.",[28,308,310],{"id":309},"try-it","Try it",[21,312,313,314,316],{},"Put your sending domain into the ",[292,315,295],{"href":294},". It runs the SPF, DKIM, DMARC and MX lookups for you, which beats reading TXT records by hand before the next issue goes out.",{"title":200,"searchDepth":318,"depth":318,"links":319},2,[320,321,322,323,324,325,326,327,328],{"id":30,"depth":318,"text":31},{"id":146,"depth":318,"text":147},{"id":179,"depth":318,"text":180},{"id":231,"depth":318,"text":232},{"id":253,"depth":318,"text":254},{"id":266,"depth":318,"text":267},{"id":283,"depth":318,"text":284},{"id":302,"depth":318,"text":303},{"id":309,"depth":318,"text":310},"2026-10-07","What Gmail and Yahoo have required of bulk senders since February 2024, what breaks if you miss a rule, and how to check your own setup.","md",{},true,"\u002Fblog\u002Fgmail-yahoo-bulk-sender-rules",{"title":15,"description":330},"blog\u002Fgmail-yahoo-bulk-sender-rules",[338,339,340,341],"deliverability","authentication","gmail","yahoo","sender-check",null,"xY1l3JQTmylDRYi-KNi2hbOChyPuNbZDKFtakNJ4xqU",1791479469524]