← All posts post

Compliant Is Not Protected

DMARCOctober 2026 · 1 min read

Since February 2024, Gmail has required anyone sending more than 5,000 messages a day to personal Gmail accounts to authenticate with SPF, DKIM and DMARC. Yahoo set similar requirements. Outlook.com followed in May 2025 for senders over 5,000 a day.

And the minimum DMARC policy they accept? p=none.

Which is why "we meet the bulk sender requirements" and "we're protected from spoofing" are completely different sentences.

p=none with a reporting address: you get reports about spoofing.

p=quarantine / p=reject: you tell receivers to quarantine or reject mail that fails.

The requirements got a lot of senders to publish DMARC. Getting to enforcement is the part that actually protects your domain, and it's still where most orgs stall.

Sources

  1. Google: Email sender guidelines
  2. Yahoo Sender Hub: Best practices
  3. Outlook.com postmaster policies