In February 2024, Google and Yahoo turned on a set of requirements for bulk senders that had been guidance for years and became enforcement overnight. Mail that does not meet them gets rejected or filed as spam. The list is short, and that is exactly why senders underestimate it: three requirements, each of which quietly assumes you already had your authentication in order. Most of the failures a year on are not new rules, they are the same three rules meeting mail streams that were never fully authenticated in the first place.

Who Counts as a Bulk Sender

Google draws the line at 5,000 messages a day to Gmail accounts, counted across your authenticated domain, not per-IP. Cross it once and you are a bulk sender in Google's eyes going forward. Yahoo publishes no equivalent threshold and applies the same expectations more broadly, so treating the 5,000 figure as universal is a mistake: it is Google's number alone. If you send marketing mail at any real volume, assume the rules apply to you.

The Three Requirements

1. Authenticate with SPF, DKIM, and DMARC.
2. Offer one-click unsubscribe, honored within two days.
3. Keep your spam complaint rate below 0.30%.

That is the whole list. Each one has a detail that decides whether you pass.

Authentication Has to Be Aligned, Not Just Present

The requirement is not "have SPF and DKIM." It is that they authenticate and that at least one of them aligns with the domain in your visible From: address, because that alignment is what DMARC checks. A message can pass SPF against the return-path domain and still fail DMARC if that domain does not match the From: header. You also need a DMARC record published, and it must be at least p=none:

_dmarc.example.com.  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"

p=none satisfies the letter of the requirement, but it is a monitoring policy, not an enforcing one. It tells receivers to do nothing on failure and just report. Start there to collect data, then move toward p=quarantine or p=reject once your reports show legitimate mail passing. Confirm where you actually stand with a DMARC check rather than assuming the published policy matches reality.

One-Click Unsubscribe Means RFC 8058, Specifically

An unsubscribe link in the body does not satisfy this. The requirement is a machine-readable header pair that lets the mail client render its own unsubscribe button and act on it with a single POST, no landing page:

List-Unsubscribe: <https://example.com/u/9f8c2a1b>, <mailto:unsub@example.com>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

Two things are non-negotiable. The List-Unsubscribe-Post value is fixed text, and both headers must be covered by your DKIM signature, otherwise a receiver cannot trust them and ignores the button. The two-day rule is a functional one: the endpoint has to actually suppress the recipient within two days, not just accept the request. CAN-SPAM's ten-day window is a legal minimum that these rules override in practice.

The 0.30% Rate Is a Ceiling You Feel Long Before You Hit It

Google's guidance is to stay under 0.10% and never reach 0.30%. Those two numbers do different jobs. 0.30% is the hard line where filtering turns punitive. 0.10% is where you should already be alarmed, because complaint rates do not creep, they spike, and by the time a daily average crosses 0.30% the damage to your reputation is done. Google Postmaster Tools reports the rate Google actually measures for your domain, so watch it there.

Signal Where you see it Act when
Spam complaint rate Postmaster Tools Trending toward 0.10%
Domain reputation Postmaster Tools Drops to "Low" or "Bad"
DMARC failures rua aggregate reports Legitimate sources failing alignment
Authentication rate Postmaster Tools Below ~99% for your own mail

Failing Quietly Is the Default

None of these rules produce a loud error. A message that fails authentication is not bounced with a helpful explanation; it lands in spam, or it does not land at all, and your open rates sag for reasons that take weeks to trace. That is the real cost of treating the list as a checkbox. The requirements are the floor for reaching the inbox, and the sender who set them up once in early 2024 and never looked again is the one most likely to have drifted below it.

Authentication is the foundation the other two rules stand on, so start there: our guide to SPF, DKIM, and DMARC covers getting all three aligned. Once mail is authenticated, the reputation of the IPs and domains behind it is what keeps you deliverable, and that is where Generator Labs blacklist monitoring watches for the listings that tank delivery no matter how clean your headers are. Start monitoring.

Back to Blog