You set up bulk-sender compliance in 2024. Here's what's actually changed since.
SPF, DKIM, DMARC, and unsubscribe were the checklist in 2024. By mid-2026: Microsoft joined, Gmail's enforcement hardened, and the spam-rate target tightened.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
If you did your bulk-sender compliance work when Gmail and Yahoo first announced their requirements back in October 2023 — SPF, DKIM, a DMARC record, one-click unsubscribe, keep spam complaints under 0.3% — and haven’t revisited it since, it’s worth a fresh look. The checklist itself hasn’t changed much. What’s changed is which mailbox providers enforce it, how hard they enforce it, and how much margin “meeting the requirement” actually gives you. None of that shows up if you’re just re-reading the original 2024 announcement.
The 2024 baseline, briefly
Google announced its bulk-sender requirements on October 3, 2023, phased in by February 2024,
with Yahoo matching on the same timeline. The requirements: authenticate with SPF and DKIM, publish
a DMARC record aligned to at least p=none, support RFC 8058 one-click unsubscribe, and keep spam
complaints under a 0.3% ceiling. Anyone sending 5,000+ messages a day to Gmail addresses was in
scope. Early enforcement was gradual — a share of non-compliant traffic got temporary deferrals,
and a larger share simply landed in spam rather than bouncing outright. If you set your domain up
to satisfy that checklist in 2024, you were, at the time, fully compliant with the entire
industry’s stated rules.
What’s different by mid-2026
Microsoft joined, and its rule didn’t exist at all in your 2024 checklist. Microsoft announced
its own requirements on April 2, 2025 — SPF and DKIM passing, DMARC aligned to at least p=none —
for anyone sending 5,000+ messages a day to Outlook.com, Hotmail.com, Live.com, or MSN addresses.
That’s a separate authentication requirement, checked separately, by a mailbox provider that
wasn’t enforcing anything comparable when you first set up compliance. If your domain’s DNS
records were tuned in 2024 with only Gmail and Yahoo in mind, there’s a reasonable chance nobody
has since confirmed they also satisfy Microsoft’s specific alignment checks.
Microsoft’s enforcement skipped the gradual phase Gmail started with. Gmail’s original 2024 enforcement leaned on spam-foldering and partial deferrals for close to two years before hardening. Microsoft went straight to permanent SMTP rejection from its May 5, 2025 enforcement date, with no comparable grace period. A domain that would have quietly lost some mail to spam under 2024-era Gmail enforcement can be outright rejected by Microsoft today for the same underlying gap.
Gmail’s own enforcement hardened too. Starting November 2025, per trade-press coverage of the change, Gmail moved from largely spam-foldering non-compliant bulk mail toward permanent, logged 5xx rejections for authentication failures and spam-rate breaches. That’s roughly 21 months after the original rule took effect — well past the point most teams considered the 2024 project “done” and moved on.
The safe spam-rate target is tighter than the number everyone remembers. The 0.3% figure from the original announcement is still the hard enforcement ceiling, but it functions as the point where consequences start, not a target to operate near. Deliverability practitioners now commonly recommend keeping well under it — often cited around 0.1% or lower — as the actual working buffer, since a single bad send can spike a small list’s complaint rate past 0.3% without much margin for error.
A meaningful share of senders are still catching up. Independent retrospective analysis of the two years since the original 2024 requirements describes a still-substantial share of bulk senders as partially non-compliant on at least one requirement — commonly authentication alignment or unsubscribe handling — well after the deadline most people assumed closed the topic. Non-compliant senders are described as seeing meaningfully more of their mail routed to spam than compliant senders, a real and measurable gap rather than a rounding error.
| 2024 baseline | Mid-2026 | |
|---|---|---|
| Providers enforcing | Gmail, Yahoo | Gmail, Yahoo, Microsoft |
| Gmail non-compliance consequence | Mostly spam-foldering, some deferrals | Permanent 5xx rejection for many cases |
| Microsoft requirement | None | SPF/DKIM/DMARC, 5,000+/day, enforced from day one |
| Microsoft's grace period | N/A | None — straight to rejection |
| Working spam-rate target | 0.3% treated as the real number | 0.3% is the ceiling; ~0.1% is the working target |
What actually broke for senders who didn’t revisit their setup
The senders this catches hardest aren’t the ones who ignored deliverability — they’re the ones who did the work correctly once and reasonably assumed it stayed done. A domain configured in early 2024 against Gmail and Yahoo’s requirements had every reason to be considered fully compliant at the time, because it was. Nothing about that configuration became technically wrong later; what changed is that a fourth requirement (Microsoft’s) appeared with no equivalent in the original checklist, and two of the three enforcement regimes got measurably less forgiving without announcing it as a headline change. A team that treats “we did our 2024 compliance project” as a closed, permanent task has no natural trigger to go check whether a new mailbox provider joined the list or whether the same published number now means something stricter in practice.
Norbelys checks all three of those continuously, per sending domain, rather than as a task someone has to remember to re-run — which is the actual point of the checklist above: this only needs to be a one-time scramble if nothing is watching it on an ongoing basis.
What to actually do about it
None of this requires starting over — the 2024 groundwork (authenticate, offer a real unsubscribe, watch complaints) is still the right foundation. What it requires is treating that groundwork as something that needs periodic re-verification against a moving target, not a project that was closed out once DNS records were published two years ago. The full current rundown of what Gmail and Microsoft both require is worth a re-read even if the individual pieces feel familiar, specifically because which pieces apply to which provider has changed since most teams last checked.
A useful forcing function is to treat this the way you’d treat any other infrastructure that was configured once and left alone: put a recurring calendar reminder on it, not a one-time task. Pull your current spam-complaint rate, confirm SPF/DKIM/DMARC still pass for every domain and subdomain you actively send from — including any added since 2024 — and re-check unsubscribe handling against the exact RFC 8058 header requirements rather than assuming a working link is enough. None of that takes long when you already have the DNS access and sending history; it’s mostly worth doing because “we set this up already” quietly stopped being true for at least one of the three major mailbox providers sometime in the last eighteen months, without most senders noticing the exact moment it happened.
Frequently asked questions
If I'm already compliant with Gmail, am I automatically compliant with Microsoft?
Not necessarily. Microsoft checks SPF, DKIM, and DMARC alignment independently against its own consumer domains, so a domain tuned only for Gmail and Yahoo can still fail Microsoft's checks if alignment or DNS records weren't specifically verified against Outlook, Hotmail, and Live addresses too.
Do I need to redo my DNS records, or just re-verify them?
For most senders whose original 2024 setup was done correctly, the records themselves don't need to change — the point of a re-audit is confirming they still pass against all three enforcing providers now, not rebuilding SPF, DKIM, and DMARC from scratch.
How often should this kind of re-audit happen going forward?
Treat it as recurring rather than one-time, since the pattern of the last two years has been mailbox providers adding or tightening requirements without a formal announcement — a quarterly check of authentication status and current spam-complaint rate is a reasonable cadence for most senders.
A Norbelys account keeps authentication status and spam-complaint trends visible per sending domain on an ongoing basis in the deliverability dashboard, which is the practical alternative to remembering to manually re-audit compliance every time a mailbox provider quietly raises the bar.