Updated: 28 September 2026 · Applies to: Sender requirements of Gmail, Yahoo and Outlook.com (2026)

Gmail, Yahoo and Microsoft (Outlook.com) publish rules for the mail that reaches their users. The rules are stricter for senders of more than 5,000 messages a day, but most of the basics apply to everyone. This checklist summarises what they ask, so that you can check your own server against it. It reflects the providers' published requirements when this article was written; read their pages for the current wording.

For every sender (Gmail)

  1. Set up SPF or DKIM for your sending domain (How to write an SPF record for a server with several IP addresses?, How to set up DKIM signing with OpenDKIM and Postfix for several domains?).
  2. The sending domain or IP address must have valid forward and reverse DNS records (How to set reverse DNS (PTR) for many IP addresses and check forward-confirmed rDNS?).
  3. Use a TLS connection when transmitting mail (How to install and configure Postfix for sending on Ubuntu?, smtp_tls_security_level = may).
  4. Keep the spam rate reported in Postmaster Tools below 0.3%.
  5. Format messages according to the Internet Message Format standard (RFC 5322) and do not impersonate Gmail From addresses.

Additionally for bulk senders (more than 5,000 messages a day to the provider)

  1. SPF and DKIM both, and DMARC for the sending domain (How to publish DMARC for your sending domains and tighten the policy safely?). Yahoo asks for a DMARC policy of at least p=none. Microsoft requires SPF, DKIM and DMARC for high-volume senders to Outlook.com, Hotmail and Live addresses, with the domain in the From address aligned with SPF or DKIM.
  2. One-click unsubscribe for marketing and subscribed messages, with the List-Unsubscribe and List-Unsubscribe-Post headers, and a visible unsubscribe link in the body (How to add a working unsubscribe link and one-click unsubscribe headers to your emails?). Honour unsubscribes within 2 days.
  3. Valid, meaningful, non-generic PTR records for all sending IP addresses (Yahoo).
  4. Spam rate below 0.3%, and both Google and Yahoo suggest staying well below that.
  5. Remove inactive and bounced addresses (How to process bounces and spam complaints and keep a suppression list?).
  6. Sign mail with DKIM so that you can use Yahoo's complaint feedback loop.

What happens if you do not comply

Providers use temporary refusals (421, 4xx), then permanent refusals and spam-folder placement. Yahoo enforces mainly through deferrals and blocks. Microsoft moves non-compliant mail to the Junk folder first and later rejects it.

Your own quick audit

dig -x YOUR-IP +short                       # PTR name
dig +short A mail1.example.com              # must return YOUR-IP
dig +short TXT example.com | grep spf1      # SPF present
dig +short TXT s2026._domainkey.example.com # DKIM key present
dig +short TXT _dmarc.example.com           # DMARC present

Then send a test message to a Gmail address and look at the authentication results in "Show original" (How to test authentication and deliverability of your outgoing email?).

Ucartz's own rules

The Acceptable Use Policy asks for valid SPF and DKIM (DMARC recommended), correct rDNS or PTR for every mail-sending server, consent capture, bounce processing and unsubscribe links for bulk or marketing mail. It allows several IP addresses and automation to manage delivery (an address per domain or customer, IP pools with a fixed assignment, warm-up schedules, per-provider rate limits, health checks and automatic pausing), and asks for a stable sending identity for each stream. It prohibits unsolicited commercial email, purchased or harvested lists, header forgery, list washing, opt-out-only mail and mailing role accounts without consent, and it prohibits using addresses, domains or automation to evade blocks, filters, complaint handling or provider rate limits, including snowshoe sending and moving a stream to other addresses after a block or complaints instead of fixing the cause. See the Acceptable Use Policy.

Frequently asked questions

I send fewer than 5,000 messages a day. Do I need all this?
The basics (authentication, reverse DNS, TLS, low complaints, easy unsubscribe) are still what keeps mail out of spam. The strict enforcement thresholds apply to larger senders, but nothing here is wasted effort.

Does the limit count per IP address?
The providers count mail sent to their users from your domain and addresses; splitting the same mail over more addresses does not remove the requirements.

Sources: Google: Email sender guidelines, Yahoo: Sender best practices and Microsoft's announcement of requirements for high-volume senders on the Microsoft Tech Community blog.

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)