Guide to email sender requirements in 2026
- Matteo
- 4 min. read
Since 2024, email service providers have started to require stricter email standard compliance from email senders. This shift was initially pushed by Google and Yahoo but many other popular providers like Microsoft and Apple soon followed.
Today, the vast majority of email providers require that you have protocols like DMARC, SPF and DKIM properly configured, especially if you’re sending to consumer accounts like Gmail and Outlook.
In this article we break down these requirements for each provider.
Google (Gmail)
Starting February 2024, all email senders who send email to consumer Gmail mailboxes must comply with the following rules:
- SPF or DKIM authentication must be configured.
- Spam complaints must be kept below 0.3%.
- The sending IP must match the IP associated to the reverse domain (forward-confirmed reverse DNS).
Google also recommends requires TLS for email delivery and recommends the usage of ARC for mailing lists. Read more in our dedicated article.
Bulk senders, which are senders who send more than 5,000 emails per day to Gmail accounts, are subject to stricter requirements. Bulk senders must:
- Implement both SPF and DKIM.
- Set up DMARC authentication and alignment, and publish a record with a policy of at least
p=none. - Enable one-click unsubscribes with the List-Unsubscribe header.
Learn more about how the bulk sender threshold is calculated, and how Google ramped up enforcement of these requirements in late 2025).
Messages failing any of these requirements may be rejected with the SMTP error 550 5.7.26.
Yahoo
Beginning in Februrary 2024, Yahoo also started to roll out stricter sending requirements. The new rules are almost identical to the Google ones, and you can read the details here in Yahoo’s Sender Hub.
Microsoft
Starting May 2025, bulk email senders who send email to Outlook accounts are subject to stricter email standard requirements.
Like with Google, the bulk sender threshold is set at 5,000 emails per day sent to consumer Outlook addresses, namely addresses ending with outlook.com, live.com, and hotmail.com.
Bulk senders are subject to the following requirements:
- SPF must be configured and pass.
- Email messages must be signed with valid DKIM signatures.
- Either SPF or DKIM must be aligned with the From domain.
- DMARC must be set up, although a
p=nonepolicy is enough.
Messages failing any of these requirements will be rejected by Microsoft with the SMTP error 550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level..
For the full list of Outlook sender requirements and recommendations, read this dedicated article.
Apple
In late 2023, Apple announced a new set of requirement for bulk senders. What constitues a bulk sender is not stated exactly, but Apple is clear that emails are rejected if they fail to comply with the rules.
Apple requires bulk senders to:
- Use SPF and DKIM to authenticate emails.
- Set up DMARC.
- Add ARC headers to forwarded emails.
Find the full list of requirements in this page.
La Poste
The French postal service La Poste announced that effective September 2025 stricter sender requirements are now in place for email delivered to its email service.
La Poste didn’t provide many details, but the core concept is that email authentication is no longer optional and either SPF or DKIM alignment is now required, honoring DMARC.
Emails that don’t present SPF, DKIM nor DMARC are delivered to the junk folder in the best case, or rejected outright.
Learn more about La Poste new sender requirements in our dedicated article.
Cloudflare
Starting July 2025, emails going through Cloudflare’s Email Routing platform must be authenticated with at least SPF or DKIM.
Cloudflare Email Routing also supports and honors DMARC, but this additional rule requiring that either SPF or DKIM pass regardless of DMARC.
Learn more about Cloudflare’s new sender requirements in our dedicated article.
GMX, WEB.DE, mail.com
In May 2026, popular email providers GMX, WEB.DE and mail.com announced the rollout of DMARC enforcement across their infrastructure.
This change is expected to affect about 42 million active users of these three providers, which are all under the parent company 1&1 Mail & Media.
In practice, if you publish a DMARC policy of p=reject for your domain, GMX/WEB.DE/mail.com now reject email messages from that domain if they fail authentication and/or lack DMARC alignment.
Failing messages are rejected at the SMTP session level with the following error message: 554 Reject due to sender domain's DMARC policy.
How to check your compliance
With the vast majority of popular email providers enforcing these email sender requirements, compliance is no longer optional.
At DMARCwise we offer a set of monitoring tools to make your life easier. You can test your email setup for free and get started with the platform to understand your SPF, DKIM, DMARC, and TLS data and protect your domain.
