Try for Free

by Ula Chwesiuk Apr 30, 2025

Since February 2024, Google and Yahoo have required email authentication for bulk senders. Microsoft followed suit, enforcing its own authentication requirements for high-volume senders (domains sending over 5,000 emails per day) starting May 5th, 2025. What used to simply be good practice is now a firm requirement across all three providers, and by 2026 these standards are treated as the industry baseline for reaching the inbox. These changes are intended to ensure email recipients only receive valuable and wanted mail. If you want your emails to always reach the inbox, even after all these changes, check out more details about email authentication and our recommendations.

Table of Contents

TL;DR

Since 2024, Google, Yahoo, and Microsoft have all required proper email authentication from senders, and by 2026 these rules are the industry baseline for reaching the inbox rather than optional best practice. The core requirements: authenticate your sending domain with SPF and DKIM, add a DMARC policy (Microsoft requires at minimum p=none with SPF or DKIM alignment), keep your Postmaster Tools spam rate below 0.3% (ideally under 0.1%), include an easy one-click unsubscribe link and honor opt-outs within 2 days, maintain valid forward and reverse DNS records, and use TLS encryption for all email transmission. Domains sending over 5,000 emails per day to Outlook.com face the strictest enforcement, with non-compliant mail first routed to Junk and, for repeat offenders, ultimately rejected outright.

What are the new requirements for?

Email authentication helps prevent others from impersonating our domain(s), keeping both senders and recipients safer. The more your sending domain or IP address is authenticated, the less likely someone will send malicious emails on your behalf, protecting email recipients from spoofing and phishing attacks. And that is why Google, Yahoo, and Microsoft chose to make their requirements stricter. They want to take care of email recipients, but at the same time, they want to help protect you and your company from being impersonated. Also, if you send relevant and wanted messages, the new rules will make your emails less likely to be rejected or marked as spam.

New email authentication requirements and what you should do to meet them

Let's now go through all the new email authentication requirements - including what you should do about each of them and how to make sure your Elastic Email account is ready for these changes.

Set up SPF and DKIM email authentication for your domain

SPF record was already mandatory, but now DKIM has changed from recommended to necessary as well. SPF (Sender Policy Framework) allows you to list all email servers authorized to send mail for your domain. It is used to prevent spammers from sending mail with fraudulent From addresses in that domain. In turn, DKIM (Domain Keys Identified Mail) allows receiving servers to sign and verify your email address as the sending domain.

Both these records can be authenticated through the domain verification process within your Elastic Email account.

Provide your subscribers with an easy unsubscribe option

All marketing and subscription emails must include an unsubscribe link that can be easily found when someone decides they no longer want to receive emails from you. When someone unsubscribes, you should remove them from your list within 2 days.

You can learn more about the unsubscribe settings in our help center.

Keep your spam rate in Postmaster Tools below 0.3%

Postmaster Tools is a product offered by Google that analyzes your email performance and helps Gmail route your email to the right place. It gives you valuable information, including spam rates with Gmail subscribers. Ideally, your spam rate should be below 0.1%, but more realistically, it should never reach 0.3% or higher.

Set up DMARC authentication of your sending domain

Domain-based Message Authentication, Reporting, and Conformance (DMARC) is built on top of SPF and DKIM records and ensures proper authentication of your domain. It checks if the records of incoming emails are properly authenticated. If yes, the message goes through. If not, the DMARC policy is executed. Meaning if either SPF, DKIM, or both checks fail, the sender chooses via the DMARC policy if the email goes to the spam folder or is bounced. Microsoft will require at least a DMARC policy of p=none and alignment with either SPF or DKIM (preferably both). You can implement DMARC in many ways and our DMARC Generator will help you create and customize a DMARC policy suited for your needs. You can then check, when verifying your domain in your Elastic Email account, if this record was properly verified.

Ensure valid forward and reverse DNS records

Forward and reverse DNS records, also referred to as PTR records, verify that the sending hostname is associated with the sending IP address. It allows email clients to verify the sender of an email via the reverse DNS lookup.
You can add entries to your DNS settings during the process of verifying your domain in your Elastic Email account. As for adding reverse DNS, or rDNS, this option is available for private IPs with our Email Marketing Pro plan and Email API Pro plan. If you want to set up rDNS, please contact our Customer Support team.

Use a TLS connection for transmitting email

TLS (Transport Layer Security) is a standard security protocol that encrypts emails for privacy. It evolved from a previous encryption protocol - SSL (Secure Sockets Layer). TLS was designed to provide security for data sent between applications. Any email transmitted to Gmail or Yahoo will have to have secure TLS connections.

At Elastic Email, we support standard SSL and TLS encryption for all SMTP traffic.

New email authentication requirements - takeaways

As you can see, there is a lot going on to improve the safety of email recipients and email authentication. The most important things to take care of are:

  1. Authenticating your emails with SPF, DKIM and DMARC
  2. Providing easy unsubscription
  3. Keeping your SPAM rate below 0.3%

If you’d like to know more about the new requirements, check out email sender guidelines prepared by Google, Yahoo and Microsoft. Let us remind you, the changes in Google and Yahoo were introduced in February 2024, whereas Microsoft's enforcement will begin after May 5th, 2025. Initially, messages from high-volume, non-compliant domains were routed to the Junk folder. Since then, Microsoft has moved to actively rejecting non-compliant messages from repeat offenders, so treating SPF, DKIM, and DMARC as optional is no longer a safe assumption. If you use Elastic Email to send your mail and need assistance in meeting the new email authentication requirements, do not hesitate to reach out to our Customer Support team. 

FAQ

What are Google, Yahoo, and Microsoft's email authentication requirements?

All three now require senders to authenticate with SPF and DKIM, publish a DMARC policy, keep spam complaint rates low, provide an easy unsubscribe option, maintain valid DNS records, and use TLS encryption. High-volume senders (over 5,000 emails/day) face the strictest enforcement.

What happens if I don't meet these authentication requirements?

Non-compliant messages are typically routed to the recipient's Junk/Spam folder first. For high-volume senders who remain non-compliant, mail can ultimately be rejected outright rather than delivered at all.

What spam rate do I need to stay under?

Below 0.3% in Google Postmaster Tools is the hard requirement; realistically, you should aim to stay under 0.1% to leave a safety margin.

What DMARC policy does Microsoft require?

At minimum, a DMARC policy of p=none with alignment to either SPF or DKIM (ideally both).

How quickly do I need to process unsubscribe requests?

Within 2 days of someone unsubscribing, they should be removed from your sending list.

What counts as a "high-volume sender" under these rules?

A domain sending more than 5,000 emails per day to a given mailbox provider (such as Outlook.com).

Do I need SPF, DKIM, and DMARC, or just one of them?

All three work together: SPF authorizes which servers can send on your domain's behalf, DKIM lets receiving servers verify your emails weren't altered in transit, and DMARC ties the two together with a policy telling receivers what to do if authentication fails.

author default image

Ula Chwesiuk

Ula is a content creator at Elastic Email. She is passionate about marketing, creative writing and language learning. Outside of work, Ula likes to travel, try new recipes and go to concerts.

If you like this article, share it with friends:

Related Articles