Google & Yahoo Email Sender Requirements: What You Need to Know
Google and Yahoo now require SPF, DKIM, DMARC, and one-click unsubscribe for bulk senders. Here's what changed, who's affected, and how to comply.
What changed and why
In October 2023, Google and Yahoo jointly announced new requirements for email senders, effective February 2024. These requirements mandate email authentication (SPF, DKIM, DMARC), easy unsubscription, and spam rate thresholds for anyone sending email to Gmail and Yahoo users.
The goal is straightforward: reduce spam, phishing, and spoofing by requiring senders to prove they are who they claim to be. These aren't suggestions — emails that don't comply are increasingly likely to be rejected or sent to spam.
Requirements for all email senders
Every sender, regardless of volume, must:
1. Set up SPF or DKIM authentication: At minimum, one of these protocols must be properly configured for your sending domain.
2. Have valid forward and reverse DNS: Your sending IP must have a PTR record that resolves to a hostname, and that hostname must resolve back to the same IP.
3. Use a TLS connection: All email must be sent over an encrypted connection.
4. Keep spam rates below 0.3%: Google's Postmaster Tools shows your spam complaint rate. Stay below 0.3% to avoid throttling. Ideally, keep it below 0.1%.
5. Don't impersonate Gmail From: headers: Don't send email with a gmail.com address in the From: header from a non-Google server.
Additional requirements for bulk senders (5,000+ emails/day)
If you send more than 5,000 emails per day to Gmail or Yahoo users, you must also:
1. Set up SPF AND DKIM: Both are required, not just one.
2. Set up DMARC: You need a published DMARC record. It can start at p=none (monitoring only), but it must exist.
3. Pass DMARC alignment: The domain in your From: header must align with either your SPF domain or your DKIM signing domain.
4. Support one-click unsubscribe: Include both a List-Unsubscribe header and a List-Unsubscribe-Post header that support RFC 8058 one-click unsubscribe. Process unsubscribe requests within 2 days.
5. Include a visible unsubscribe link: Every marketing email must have a clearly visible unsubscribe link in the message body.
How to check your compliance
Checking compliance is straightforward:
1. Validate your DNS records: Use a free SPF, DKIM, and DMARC checker to verify all three protocols are set up correctly.
2. Check Google Postmaster Tools: Register at postmaster.google.com to see your domain's spam rate, authentication rates, and reputation. This is the definitive source for how Google sees your email.
3. Verify unsubscribe headers: Send a test email and examine the raw headers. Look for List-Unsubscribe and List-Unsubscribe-Post headers.
4. Monitor blacklist status: Being on blacklists is a strong signal of poor sending practices. Run a blacklist check to ensure you're clean.
5. Check your DMARC reports: If you've set up DMARC with a rua tag, review the aggregate reports to identify any authentication failures or unauthorized senders.
What happens if you don't comply
The consequences are real and getting stricter:
- Temporary failures: Gmail may temporarily reject emails with 4xx errors, giving you time to fix issues. - Spam folder placement: Non-compliant emails increasingly go to spam rather than the inbox. - Outright rejection: Persistent non-compliance can lead to 5xx permanent rejections. - Domain reputation damage: Even if you fix compliance issues, a damaged reputation takes time to rebuild.
Google has been gradually tightening enforcement throughout 2024 and 2025, and the trend is toward stricter requirements. Yahoo has followed a similar trajectory. Other providers (Microsoft, Apple) are watching closely and likely to implement similar rules.
Getting compliant: A quick action plan
If you're not yet compliant, here's your action plan:
1. Run a comprehensive email health check to see your current status 2. Set up SPF with all your authorized sending services 3. Enable DKIM signing for every service that sends email on your behalf 4. Publish a DMARC record (start with p=none) 5. Verify your reverse DNS is correctly configured 6. Check that your email platform supports one-click unsubscribe headers 7. Register for Google Postmaster Tools and monitor your spam rate 8. Set up ongoing monitoring to catch any future issues
Most of these can be done in an afternoon. The ongoing monitoring is what keeps you compliant long-term.
- ·SPF record published and includes all sending services (required for all senders)
- ·DKIM signing enabled for all services — 2048-bit key recommended (required for bulk senders)
- ·DMARC record published at _dmarc.yourdomain.com — p=none minimum (required for bulk senders)
- ·DMARC alignment passes — From: domain aligns with SPF or DKIM domain (required for bulk senders)
- ·One-click unsubscribe: List-Unsubscribe and List-Unsubscribe-Post headers present (required for bulk senders)
- ·Visible unsubscribe link in every marketing email body (required for bulk senders)
- ·Unsubscribes processed within 2 days (required — Google/Yahoo mandate)
- ·Valid forward and reverse DNS for sending IP (required for all senders)
- ·TLS used for all connections (required for all senders)
- ·Spam rate below 0.10% at Gmail (required — monitor via Postmaster Tools)
- 5,000/day
- Bulk sender threshold
- 0.10%
- Spam rate limit
- 2 days
- Unsubscribe deadline
- Feb 2024
- Rollout start date
Emails to Gmail addresses that trigger additional requirements
Gmail threshold; sustained above 0.30% causes blocking
Google/Yahoo require processing within 2 days of request
Google and Yahoo began enforcement February 1, 2024
Check your domain's email health
Run a free scan against 60 blacklists. Validate SPF, DKIM, DMARC, and MX records in seconds.
Related free tools