The bulk sender requirements, and which parts bite
Three receivers, one shared list of requirements, and rejections rather than filtering when you miss them. Here is what each one asks for.
Google, Yahoo and Microsoft now publish requirements for anyone sending in volume, and they enforce them with rejections rather than filtering. A message that fails does not land in spam. It bounces.
Who this applies to
Roughly five thousand messages a day to a single provider. Google counts across your domain to Gmail accounts, and once you cross the line you are treated as a bulk sender from then on.
Below that threshold the requirements are still the right configuration. They are simply not enforced against you yet.
What all three require
SPF and DKIM. Both, not either. This is stricter than DMARC itself, which passes on one.
A DMARC record. At minimum p=none. The record has to exist and be valid.
Alignment. The domain in your From header has to line up with the domain that passed SPF or DKIM. A message can pass both and still fail this, which is the most common reason a technically authenticated sender is rejected.
Valid forward and reverse DNS. Your sending IP needs a PTR record, and the name in it has to resolve back to the same IP. If you send through a provider this is their job and it is usually already right. Check it.
TLS on transmission. Opportunistic TLS is enough; nothing here requires MTA-STS, though publishing it is the stronger position.
One-click unsubscribe. For promotional mail, a List-Unsubscribe header supporting one-click, honoured within two days. A link in the footer alone is not sufficient.
A spam complaint rate under 0.3 percent. The number they act on most directly, with 0.1 percent as the stated target.
The two you cannot check from DNS
Complaint rate and unsubscribe handling are invisible from outside. Nothing that reads your DNS can tell you either, and any tool claiming to score them is guessing.
Complaint rate comes from Google Postmaster Tools for Gmail, and from your sending platform for the rest. Unsubscribe handling you verify by sending yourself a message and using the header.
The sender readiness test checks everything that is visible in DNS and states plainly which requirements it cannot see, rather than implying a pass.
What to do first
Get authentication right, because it is the largest block of requirements and the only part that is provable. Run the checkup.
Then confirm reverse DNS on your sending IP, add one-click unsubscribe to promotional mail, and look at your complaint rate in Postmaster Tools.
If your complaint rate is the problem, no DNS record will fix it. That is a list and content question, and it is the one worth an hour with somebody who has read a lot of aggregate reports.
Common questions
What counts as a bulk sender?
Roughly five thousand messages a day to a single provider. Google counts per Gmail account across your domain, and once you cross the threshold you are treated as a bulk sender from then on, whether or not you drop back below it.
What happens if I do not comply?
Rejection rather than filtering. Non-compliant bulk mail gets a permanent SMTP error, so the message never arrives and your sending system records a bounce. This is deliberately louder than a spam folder.
What complaint rate do they require?
Under 0.3 percent, with 0.1 percent as the stated target. It cannot be read from DNS by anyone, so no checking tool can tell you yours. Google Postmaster Tools reports it for Gmail.
Do these rules apply to transactional email?
The authentication, TLS and DNS requirements apply to everything. One-click unsubscribe applies to promotional mail, not to password resets and receipts, though the line is not always obvious and receivers judge it by content.
Run the test on your own domain
Sender Readiness
Will the bulk-sender rules reject you? Find out before they do.
DMARC Test
Tree-walk discovery, inheritance, test mode and the policy receivers really apply.
SPF Test
Full chain walk with the exact 10-lookup count, plus the void lookups nobody else checks.
Reverse DNS
Do your sending IPs resolve back to a name, and does that name resolve forward again?
Read next
Why your mail lands in spam, in the order worth checking
GuideDeliverability problems have a small number of causes and a reliable order to work through them. Authentication first, because it is the only part you can prove.
Why are my emails going to spam?
Six causes, in the order worth checking. The first two you can prove in about a minute; the rest take longer and matter less often.
How to set up DMARC
From no record to enforcement, in five steps. The first takes ten minutes; the rest are mostly waiting and reading.
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.