Key takeaways
- Bulk senders need SPF and DKIM, a DMARC record (p=none is enough) and a From domain aligned with them.
- Marketing mail needs RFC 8058 one-click unsubscribe, processed within two days, plus a visible body link.
- Keep the spam complaint rate in Google Postmaster Tools below 0.3%, and ideally well under it.
- Meet the bulk-sender standard even at low volumes, because once you are classified as a bulk sender the status is permanent.
Since February 2024, Gmail and Yahoo have required anyone sending email to their users to authenticate their mail, keep spam complaints low and make unsubscribing easy. Bulk senders have the strictest rules. They need SPF and DKIM on the sending domain, a published DMARC policy and a From address aligned with those checks, plus one-click unsubscribe honoured within two days and a spam complaint rate below 0.3%. Miss them and more and more of your email will end up in spam or be rejected outright.
Below we go through what each requirement means, who counts as a bulk sender, and how to check and fix your own setup.
What changed and why it matters
Google and Yahoo announced joint sender requirements in late 2023, and they began applying them from February 2024, with enforcement phased in through that year. One-click unsubscribe had a later deadline of June 2024. Google has continued to tighten enforcement since, moving from temporary delivery errors towards rejecting mail that does not comply.
The aim was to make it harder for spammers and impersonators to reach inboxes, and to give recipients an easy way out of mail they no longer want. Most of the rules were already good practice. The difference now is that your mail may not be delivered if you ignore them.
Microsoft has since introduced similar authentication requirements for high-volume senders to its consumer Outlook.com addresses, so the same standard now applies across the largest consumer mailbox providers. If your customers use Gmail, Yahoo, AOL or Outlook personal addresses, which most UK consumer lists do, these rules affect you.
Who counts as a bulk sender?
Google defines a bulk sender as one that sends close to 5,000 or more messages to personal Gmail accounts within a 24-hour period. Four details catch people out.
- It is measured per sending domain, and messages from subdomains count towards the total for the primary domain.
- Once you are classified as a bulk sender, the status is permanent. A single large send, such as a seasonal promotion, can tip you over the threshold for good.
- It counts all mail from the domain. Order confirmations, password resets and newsletters are added together.
- Yahoo does not publish a fixed number, so it is safer to assume the stricter rules apply to any sizeable programme.
Even if you are well below the threshold, our advice is to meet the bulk-sender requirements anyway. They cost little to set up and protect your domain from spoofing. They also mean a busy Black Friday or a large one-off send will not suddenly land you in trouble.
The requirements at a glance
| Requirement | All senders | Bulk senders |
|---|---|---|
| SPF or DKIM authentication | At least one | Both SPF and DKIM |
| DMARC record | Recommended | Required (policy can be p=none) |
| From domain aligned with SPF or DKIM | Recommended | Required |
| Valid forward and reverse DNS for sending IPs | Required | Required |
| TLS connection for sending | Required | Required |
| Spam complaint rate | Keep below 0.3% | Keep below 0.3% |
| One-click unsubscribe (RFC 8058) for marketing mail | Recommended | Required, honoured within two days |
| Visible unsubscribe link in the message body | Good practice | Required for marketing mail |
| Correctly formatted messages (RFC 5322) | Required | Required |
If you use a reputable email service provider, it will handle some of these for you, such as TLS, reverse DNS on its own sending IPs, message formatting and, usually, the unsubscribe headers. The part you nearly always have to do yourself is adding DNS records to your own domain.
How SPF, DKIM and DMARC work
SPF
Sender Policy Framework is a DNS TXT record listing the servers and services allowed to send email for your domain. When a message arrives, the receiving server checks whether it came from one of those sources.
Common pitfalls include having more than one SPF record on a domain (there must only be one), exceeding the limit of ten DNS lookups as you add services, and forgetting a tool that sends on your behalf, such as a CRM, helpdesk or invoicing system.
DKIM
DomainKeys Identified Mail adds a digital signature to each message. The receiving server uses a public key published in your DNS to confirm that the message was authorised by your domain and not altered on the way. Your email platform gives you the record to publish, and Google recommends keys of at least 2048 bits where your provider supports them.
The thing to get right is signing with your own domain. Many platforms sign with their own domain by default. That technically passes DKIM, but it does nothing for your alignment or your reputation. Set up custom DKIM so the signature uses your domain.
DMARC
Domain-based Message Authentication, Reporting and Conformance ties SPF and DKIM to the domain people see in the From line. A DMARC record tells receiving servers what to do with mail that fails, and where to send reports. A minimal starting record looks like the one below.
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.co.uk
A policy of p=none satisfies the Gmail and Yahoo requirement. It asks receivers to monitor rather than act, while sending you aggregate reports. Over time, once you are confident all your legitimate mail is authenticated, you can move to p=quarantine and then p=reject, which protects your domain from being spoofed by scammers.
Take the move between DMARC policies slowly. Start by reviewing the aggregate reports, which show which servers are sending mail using your domain and whether each passed. Unknown sources are either tools you forgot or someone spoofing you. Once every legitimate source passes consistently, step up the policy. Keep reading the reports afterwards too, because someone will eventually sign up for a new tool that sends as your domain.
Alignment
Alignment means the domain in your visible From address matches the domain that passed SPF or DKIM. If your newsletter says it is from news@yourbusiness.co.uk but is only authenticated as your email platform’s domain, it is not aligned. Custom DKIM on your own domain is usually the easiest way to get aligned. Under DMARC’s default relaxed mode, organisational alignment means a subdomain such as news.yourbusiness.co.uk aligns with yourbusiness.co.uk.
One-click unsubscribe and the two-day rule
For marketing and subscribed messages, bulk senders must support one-click unsubscribe as defined in RFC 8058. That comes down to two email headers.
- List-Unsubscribe, containing an HTTPS address (and optionally a mailto address) for unsubscribing.
- List-Unsubscribe-Post, with the value List-Unsubscribe=One-Click, which lets the mailbox provider unsubscribe the recipient with a single request and no further steps.
These headers power the “Unsubscribe” option that Gmail and Yahoo display near the sender name. Your provider must process the request within two days, and you also need a clearly visible unsubscribe link in the body of the email. A link that leads to a login page or a multi-step survey does not meet the spirit of the rule.
Transactional messages, such as receipts and password resets, do not need one-click unsubscribe. Be careful about adding promotions to them, though, because a receipt with a discount banner may be treated as marketing.
Making it easy to leave can feel like working against yourself, but it protects you. Someone who cannot find a quick way out is far more likely to press “report spam”, and complaints damage your reputation much more than unsubscribes do.
Keeping spam complaints below 0.3%
Google asks senders to keep the spam rate reported in Postmaster Tools below 0.3%, and recommends aiming below 0.1%. That rate is calculated from complaints by users at Gmail, so it reflects how real recipients feel about your mail.
Complaints rarely have a single cause. These are the ones we come across most.
- Sending to people who did not knowingly sign up, or who signed up long ago and have forgotten you.
- A sudden increase in frequency, or a send to a segment you rarely email.
- Misleading subject lines or From names.
- Hidden or awkward unsubscribe links.
- Content that does not match what people were promised at sign-up.
Most of the fixes come down to list quality and setting expectations. Get clear consent at sign-up, use confirmed opt-in where you can, send on a predictable schedule and regularly remove people who have not engaged for months. Good email segmentation also helps, because relevant messages generate fewer complaints than generic blasts.
How the rules fit with UK consent law
The Gmail and Yahoo requirements are technical conditions set by private companies. They sit alongside UK law rather than replacing it. Marketing email to individuals in the UK is governed by the Privacy and Electronic Communications Regulations (PECR) and UK GDPR, which generally require consent, or the soft opt-in for existing customers buying similar products, plus a simple way to opt out in every message.
The two sets of rules support each other. A list built on recorded consent tends to produce fewer complaints, which keeps your spam rate down. A one-click unsubscribe that is processed promptly helps you honour opt-outs, which PECR requires anyway. Authentication also stops scammers sending fake emails in your name to your customers.
Where they differ is scope. A business with a small list may never be classed as a bulk sender, but it is always subject to PECR. And a perfectly authenticated campaign sent to a bought list is still unlawful, and will still draw complaints.
How to check your setup in eight steps
- List every service that sends email as your domain. Include your email platform, CRM, ecommerce store, booking system, helpdesk and accounting software.
- Check your SPF record. Make sure there is exactly one, that it includes every legitimate sender and that it stays within the lookup limit.
- Set up custom DKIM for each sending service, so mail is signed with your own domain.
- Publish a DMARC record with at least p=none and a reporting address you or your provider will actually monitor.
- Send a test message to a Gmail account, open “Show original” and confirm SPF, DKIM and DMARC all show as passing.
- Confirm one-click unsubscribe headers are present on marketing mail and that a visible unsubscribe link sits in the body.
- Register your domain in Google Postmaster Tools and Yahoo’s Sender Hub, then check spam rate, reputation and compliance status regularly.
- Review DMARC reports after a few weeks to find any legitimate senders you missed, before tightening your policy.
Google Postmaster Tools is free and tells you more about how Gmail sees your mail than anything else available. It sits well alongside the other options in our round-up of free marketing tools for small businesses.
Common mistakes we see
- Sending from a free webmail address. A From address at a free consumer mailbox cannot be aligned with your platform, because you do not control that domain’s DNS. Use your own domain.
- Forgetting the “other” senders. Invoices from accounting software or notifications from a booking system can fail DMARC if nobody set them up.
- Jumping straight to p=reject. Enforcing DMARC before auditing all your senders can block your own legitimate mail.
- Relying on the platform’s shared domain. Mail authenticated only as your provider’s domain does not build reputation for your own.
- Mixing marketing and operational mail on one domain. A poorly received campaign can affect delivery of order confirmations. A dedicated subdomain for marketing keeps reputations separate.
- Ignoring complaint data. Many businesses set up Postmaster Tools and never look at it again.
Building a sender reputation that lasts
Meeting the requirements gets you through the door, but it does not promise you the inbox. Mailbox providers still weigh how recipients engage with your mail, and senders with steady volumes and lists of people who actually read their emails generally fare best.
The habits below make the biggest difference.
- Warm up new domains and IP addresses gradually rather than sending a large campaign on day one.
- Keep a steady sending pattern instead of long silences followed by bursts.
- Run a re-engagement series for inactive subscribers and suppress those who still do not respond.
- Monitor bounces and remove invalid addresses promptly.
- Track clicks and conversions to judge relevance, through solid email marketing analytics, rather than relying on open rates.
Where to start if your emails are landing in spam
Start with the Gmail “Show original” test on one marketing email and one invoice or order confirmation. If either fails SPF, DKIM or DMARC, fix that before anything else, then work through the rest of the checklist above.
The rules are not hard once you know what to check, but DNS changes and DMARC reports from half a dozen sending tools can get fiddly. We audit and fix authentication and then keep watch on reputation through our email deliverability service, and our email marketing team can help with what goes in the emails themselves.
How Eigme can help
Turn this into results.
We can help you put this into practice with a clear plan, hands-on delivery and reporting in plain English.
Book a free strategy call →Frequently asked questions
Do the Gmail and Yahoo rules apply to small businesses?
Yes. Every sender to Gmail must meet the basic rules, including SPF or DKIM authentication, valid DNS, secure connections and a low spam rate. The stricter bulk-sender rules apply to those sending close to 5,000 or more messages a day to Gmail accounts, but following them anyway is simple and protects your domain.
Is a DMARC policy of p=none enough?
For the Gmail and Yahoo bulk-sender requirement, yes. A p=none policy asks receivers to monitor without acting and sends you reports. It is a sensible first step. Once reports show that all your legitimate mail passes, moving to quarantine or reject gives stronger protection against people spoofing your domain.
What is one-click unsubscribe?
One-click unsubscribe, defined in RFC 8058, uses the List-Unsubscribe and List-Unsubscribe-Post email headers so mailbox providers can unsubscribe someone with a single action. Gmail and Yahoo show it as an unsubscribe option near the sender name. Bulk senders must support it on marketing mail and process requests within two days.
How do I check whether my emails pass SPF, DKIM and DMARC?
Send a message to a Gmail address, open it, and choose Show original from the message menu. Gmail displays whether SPF, DKIM and DMARC passed. Repeat this for every tool that sends as your domain, such as your CRM or shop, as each needs its own correct setup.
What happens if I do not meet the requirements?
Non-compliant mail is more likely to be delayed, sent to spam or rejected. Google has phased in enforcement and tightened it over time, so problems that once caused occasional temporary errors can now lead to messages not being delivered at all. Fixing authentication and unsubscribe handling is usually the quickest remedy.



