Google and Yahoo sender requirements
Google's bulk sender requirements bind any domain sending close to 5,000 messages or more a day to personal Gmail accounts, and a shorter list binds every sender at any volume. Yahoo runs the same two tiers and refuses to publish a threshold at all. Every published requirement is below, with who it binds and what happens if you miss it.
By Rahul Bageria, co-founder · Updated August 2026 · 14 min read
The requirements, at a glance
Every published requirement at the three mailbox providers that matter for B2B, split by whether it binds every sender or only bulk senders.
| Requirement | Gmail (personal accounts only) | Yahoo (and AOL, all Yahoo-hosted brands) | Outlook.com (Hotmail, Live, MSN) |
|---|---|---|---|
| SPF or DKIM | Every sender | Every sender | Not stated separately |
| SPF and DKIM, both | Bulk senders only | Bulk senders only | High-volume senders only, both must pass |
| DMARC record, p=none is enough | Bulk senders only | Bulk senders only, and DMARC must pass | High-volume senders only |
| From: aligned with SPF or DKIM | Bulk senders, direct mail only | Bulk senders, relaxed alignment accepted | High-volume senders only, at least one must align |
| Spam complaint rate below 0.3% | Every sender | Every sender, measured on inbox-delivered mail | No number published |
| Forward and reverse DNS (PTR) | Every sender | Every sender, and non-generic | Not published as a requirement |
| TLS connection | Every sender | Not stated | Not published as a requirement |
| RFC 5322 message format | Every sender | Every sender, RFC 5321 named too | Not published as a requirement |
| One-click unsubscribe on marketing and subscribed mail | Bulk senders only, transactional excluded | Bulk senders only, mailto also accepted | Recommended, not required |
| Unsubscribes honored fast | Within 48 hours, bulk senders | Within 2 days, bulk senders | No number published |
| The volume that makes you bulk | Close to 5,000 a day to personal Gmail accounts, counted per primary domain, permanent once crossed | No threshold published. Yahoo says it will not specify a volume threshold | 5,000 or more to Microsoft consumer mailboxes from one From: domain |
Every row was read on the provider's own page on 15 August 2026: Google's Email sender guidelines and its bulk sender FAQ; Yahoo's sender best practices and its sender FAQ; Microsoft's Outlook.com requirements, alongside its high-volume sender announcement on techcommunity.microsoft.com (posted 2 April 2025, updated 30 April 2025).
Apple's iCloud Mail guidance (published 25 February 2025) has a bulk list with no threshold and rejects non-compliant bulk mail outright. This page gets re-checked and restamped whenever a provider moves a requirement.
Who these rules actually bind
There are two tiers, not one, and which one binds you is decided by how much mail you send to personal Gmail accounts in a day.
- •SPF or DKIM, where one of the two is enough
- •Valid forward and reverse DNS on the sending IP
- •A TLS connection for transmitting the mail
- •Spam rate in Postmaster Tools below 0.3%
- •RFC 5322 formatting, and no Gmail From: address you do not own
- •SPF and DKIM, both this time
- •A DMARC record, where p=none is enough
- •From: aligned with either the SPF or the DKIM domain
- •One-click unsubscribe plus a visible link in the body
- •Unsubscribe requests honored within 48 hours
A bulk sender, in Google's words, is any sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period. Yahoo declines to define it numerically.
Three of the all-sender items are not really yours. If you send through Google Workspace or Microsoft 365, the PTR record and the TLS connection belong to their infrastructure, and any competent cold email tool already emits standards-compliant messages. What is yours is the DNS at your sending domain and the behavior of your list.
If you send 40 emails a day to work addresses, the bulk rules do not bind you. The all-sender floor does, and so does the law where your recipients sit.
How the 5,000 is counted
The number is real, and the rules about how it is counted are what decide whether it can ever reach you.
Only personal Gmail counts
Google counts mail to addresses ending @gmail.com or @googlemail.com. Mail to Google Workspace accounts does not count, and Google says the sender guidelines do not apply to it. A B2B list of work addresses contributes nothing.
Counted per primary domain
The 5,000 is not per inbox and not per mailbox. Google counts every message sent from the same primary domain, so splitting a send across ten inboxes on one domain changes nothing about the total.
Subdomains roll up into it
Google's own worked example: 2,500 messages from solarmora.com plus 2,500 from promotions.solarmora.com is a bulk sender. A separate sending domain, though, is its own primary domain and is counted on its own.
Crossing it once is forever
Senders who meet the criteria at least once are permanently bulk senders, and Google states the status has no expiration date. One migration blast to a consumer-heavy list classifies the domain for good.
Workspace caps a user at 2,000
A Google Workspace user can send 2,000 messages a day, after which Google stops them for up to 24 hours. One user cannot reach 5,000, which is the arithmetic that settles this for most founders.
One nuance sits outside the counting rules. Google puts a new domain, meaning one that has not sent more than 5,000 emails a day to personal Gmail accounts since 1 January 2024, on an accelerated enforcement timetable. That is different from warming a domain up: warmup builds reputation, and no amount of it makes an unauthenticated domain compliant. Domain and inbox architecture belongs to the cold email infrastructure guide.
Yahoo publishes no threshold
The 5,000 a day figure is Google's, and separately Microsoft's, and Yahoo has never published one of its own.
Yahoo's bulk sender rules kick in at 5,000 messages a day, the same threshold as Gmail.
- ✕Borrows Google's number and relabels it as Yahoo's
- ✕Now repeating itself through AI answer summaries
- ✕Tells a small sender they are exempt from something Yahoo never scoped
A bulk sender is an email sender sending a significant volume of mail. We will not specify a volume threshold.
- ✓Yahoo's own sender FAQ, read 15 August 2026
- ✓Judged at the authenticated or From: header domain level
- ✓Unchanged since February 2024, snapshot for snapshot
That refusal has a practical effect. Without a published number you cannot prove you sit under Yahoo's line, so the part you can be sure of is its all-sender floor: SPF or DKIM, a spam rate below 0.3%, valid forward and reverse DNS, and compliance with RFCs 5321 and 5322. Yahoo scopes all of it to every Yahoo-hosted brand, AOL included, and says Yahoo Japan is a separate entity.
The enforcement timeline, dated
Four dated moments, each traceable to the announcement or the provider page that carried it.
The requirements take effect
Both of Google's requirement lists still open with the same sentence: starting 1 February 2024. Senders to Gmail accounts must meet the all-sender section, and senders above 5,000 a day the bulk section. Yahoo's enforcement began the same month.
Apple publishes its own list
Apple's iCloud Mail bulk sender page is dated 25 February 2025. It names no volume threshold, requires explicit opt-in rather than purchased lists, and says that if the requirements are not met the email will be rejected. No allow list, no feedback loop.
Microsoft joins, and rejects
Microsoft's high-volume sender post went up on 2 April 2025 and was updated on 30 April. The post itself wavers between junk foldering and outright rejection; its live support article settles it as rejection, with the code 550 5.7.515.
Gmail ramps enforcement up
Google's line about ramping up enforcement, with temporary and permanent rejections, is absent from the 2 October 2025 archived snapshot of its FAQ and present in the 2 November one. That dates the addition to late October or early November 2025.
What changed, and what did not
Two things the pages ranking for this query still get wrong.
Postmaster Tools v1 lives on
Google's deprecation page now opens by saying it is postponing the deprecation of the legacy Postmaster Tools web interface, which will eventually be retired. Any page telling you v1 was retired in October 2025 is wrong.
Yahoo has not moved at all
Yahoo's requirements block is identical to its April 2024 archived snapshot. That is information, not an oversight: if a page claims Yahoo tightened something in 2026, ask which Yahoo page says so.
Neither one adds work for a small sender. One postponed a retirement, and one is a provider standing still. They matter because they date a page, not because they cost you anything.
Want the two of us to look at your sending setup before you scale it?
Book a Fit CheckWhat happens if you miss one
Google publishes a consequence per requirement, and they are not all the same consequence.
| What you missed | What the provider says happens | The code that tells you |
|---|---|---|
| SPF or DKIM not set up | Temporary or permanent failure codes, or spam foldering | 4.7.27 and 5.7.27 for SPF, 4.7.30 and 5.7.30 for DKIM |
| No valid forward and reverse DNS | Temporary or permanent failure codes, or spam foldering | 4.7.23, and 5.7.25 once it is permanent |
| No TLS connection | Temporary or permanent failure codes, or spam foldering | 4.7.29 and 5.7.29 |
| Message not formatted to RFC 5322 | Temporary or permanent failure codes, or spam foldering | No dedicated code |
| From: not aligned, bulk senders | Temporary failure on delivery | 4.7.32 |
| Spam rate at or above 0.3% | Delivery support or mitigations unavailable, and eligibility returns after 7 days below 0.3% | No code. It shows in Postmaster Tools |
| No DMARC record, bulk senders | Delivery support or mitigations unavailable | 4.7.31 |
| No one-click unsubscribe, or not honored in 48 hours | Delivery support or mitigations unavailable | No code |
| Microsoft: SPF, DKIM or DMARC failing at high volume | Rejected outright, and the Safe Sender list is not honored | 550 5.7.515 |
Consequence column from Google's requirement and consequence table, plus Microsoft's NDR article; code column from Google's SMTP error codes. Both read 15 August 2026. A 4.x.x code is a temporary failure and gets retried; a 5.x.x is a rejection and does not. Current explainers flatten two things on the spam-rate row: 0.3% is the requirement, 0.10% is Google's separate recommendation, and crossing 0.3% costs you delivery support and mitigations, not an outright block.
Treat every bounce as a block
Our mail is bouncing, so we bought fresh domains and started the whole setup again.
- ✕Throws away a working domain
- ✕Ignores the code the server sent
- ✕Fixes nothing, because nothing was diagnosed
Read the code it handed you
The bounce said 4.7.31, which is the missing DMARC record, so we published one.
- ✓The code names the failed requirement
- ✓4.x.x will retry, 5.x.x will not
- ✓One DNS change, not a rebuild
None of this is the same as deliverability. Every requirement above can pass while your mail still lands in spam, and if that is where you already are, start with why cold emails go to spam.
How to tell whether you comply when you are small
Postmaster Tools will often show you nothing at low volume, and Google says so on the page itself.
- 1 Your DNS answers the compliance question faster than any dashboard.
- 2 An empty chart at low volume is expected, not a fault to fix.
- 3 Spam rate is the only rule you can pass Monday and fail Friday.
- 4 At 200 sends a day, one complaint is already half a percent.
Two of those four are ongoing work, not a one-time check. Complaints and bounces track list quality, which is what an email verification tool is for, and publishing the records is a setup job covered in the infrastructure guide. Holding the rate down once you are sending is a discipline, not a check, and belongs to the deliverability guide.
The other rulebook depends on who you email
Google's rules follow the mailbox. The law follows the recipient, so which regime binds a send is decided by where the person you are emailing sits, not by where you sit.
CAN-SPAM does not exempt B2B email
Email someone in the United States and CAN-SPAM covers the message. The FTC says the law reaches all commercial email and makes no exception for business-to-business. In the US, its guide sets penalties of up to $53,088 for each email in violation, current as of August 2026, a ceiling the FTC attaches to knowing violations.
For a US recipient, the FTC's compliance guide sets the contents: accurate headers, an honest subject line, the message identified as an ad, a valid physical postal address, and an opt-out honored within 10 business days and kept working for at least 30.
For a European recipient, a different pair applies: the GDPR governs the personal data you hold on them, and the ePrivacy rules, implemented country by country, govern whether you may send at all. The UK runs PECR alongside its own data protection law.
We are operators, not lawyers, so take the binding word from someone you pay for it. Our page on whether cold email is legal takes the permission question country by country.
That opt-out is not the same thing as Google's one-click unsubscribe header, which is a bulk-sender requirement scoped to marketing and subscribed messages, with transactional mail explicitly excluded. A reply-based or single-page opt-out satisfies CAN-SPAM. What that line does to the last three sentences of a cold email belongs to the cold email copywriting guide.
What this means at 40 a day
Our answer, offered as judgment rather than measurement: the rules asked a small B2B sender for one thing they should have had already.
- 1 The bulk tier was written for senders three orders of magnitude larger.
- 2 The all-sender floor binds you today, at any volume, with no exemption.
- 3 Email into the US and CAN-SPAM binds you, however little you send.
- 4 Publishing DMARC anyway is sensible, and it is not a requirement.
The noise was worse than the rules. Between late 2023 and mid 2024 a wave of pages told small senders they would be blocked unless they bought a product; the published rules never said that. Running signal-based outbound at low volume to a verified list, February 2024 asked you for a DNS record and nothing else. If you would rather not own any of this, a deliverability-focused agency is the other route.
Compliance is not deliverability. Every requirement on this page can pass while your mail still lands in spam, because not one of them measures whether the person wanted to hear from you. That part is earned, not configured.
Questions founders ask
Do Google's bulk sender requirements apply to cold email?
What is the 5,000 email threshold exactly?
Do these rules apply when I email someone at a company that uses Gmail for work?
Does Yahoo have a 5,000 a day threshold too?
Do I need a one-click unsubscribe link in a cold email?
What spam complaint rate is allowed?
Co-founder of Real Good GTM. He has been the first business hire and Chief of Staff at seed-stage B2B startups, building outbound pipeline before any playbook existed. He wrote this page because founders keep being told they are bound by rules written for senders a thousand times their size, and the provider documentation says otherwise.
Connect on LinkedInThe pages that do the setup and the discipline
This page states the rules. Landing the mail is a different job, and it splits into two.
Cold email deliverability
The parent guide: keeping the complaint rate low, reading reputation, and the recovery playbook when it slips.
Read the guideCold email infrastructure
Where the records actually get published: domains, inboxes, SPF, DKIM and DMARC, and why sending domains stay separate.
Read the guideCold email infrastructure tools
The providers that set up domains and inboxes with the records already published, compared on price and control.
See the toolsWant outbound that lands, without owning the plumbing?
Book a fit check. We'll look at how your domains and inboxes are set up, where your outbound is losing mail before anyone reads it, and tell you straight if outbound is not the right motion for you yet.
Book a Fit CheckNo hard sell. No fake numbers. Real good work speaks for itself.