Google's bulk sender rules took effect on February 1, 2024, and Microsoft began enforcing its own on May 5, 2025. Both say the same thing to anyone sending around 5,000 or more messages a day to their consumer mailboxes: authenticate every message with SPF, DKIM, and DMARC, make opting out easy, and keep spam complaints very low. A cold email team should meet every one of those requirements on every sending domain, even though it will probably never send 5,000 a day to Gmail.
The reason is simple. The systems that enforce the rules on bulk senders score everyone else on the same signals. This post is for founders, SDR leads, and agencies running cold email into Gmail and Outlook inboxes. It sets out what each provider requires as of September 2026, what that means for a team sending 300 to 1,000 emails a day across a dozen secondary domains, and the two numbers that matter most: a spam rate under 0.1%, and never 0.3%.
What do Google's bulk sender rules require?
Google requires senders of 5,000 or more messages a day to Gmail accounts to set up both SPF and DKIM, publish a DMARC policy on the sending domain (p=none is acceptable), align the From header with the SPF or DKIM domain, support one-click unsubscribe on marketing and subscribed mail and honour opt-outs within two days, keep the spam rate shown in Postmaster Tools under 0.3%, keep valid forward and reverse DNS (a PTR record), and send over TLS.
The full list is on Google's Email sender guidelines page, and the sender guidelines FAQ explains how the threshold is counted. Both pages change. Read this post as our reading of them as of September 2026 and check the current version before you act on it.
Two things surprise people. First, Google's ceiling is 0.3% but its recommendation is to stay under 0.1%, and it describes 0.3% as a level you must never reach, not a budget to spend. Second, DMARC at p=none satisfies the rule. It is a monitoring policy that blocks nothing, but Google needs it published to check alignment. Google's page also lists a lighter set of requirements for every sender regardless of volume, including SPF or DKIM authentication, valid DNS records, and a low spam rate, which is why the bulk rules are best read as the standard rather than the exception.
What does Microsoft require for Outlook.com senders?
Microsoft requires senders of 5,000 or more messages a day to its consumer domains (outlook.com, hotmail.com, and live.com) to authenticate with SPF, DKIM, and DMARC, with DMARC at a minimum of p=none and aligned with either SPF or DKIM. Enforcement began on May 5, 2025. Non-compliant mail was routed to the Junk folder first, and Microsoft announced that rejection with the error 550 5.7.15 would follow.
The announcement, Strengthening Email Ecosystem: Outlook's New Requirements for High-Volume Senders on the Microsoft Tech Community blog, also recommends a valid From and Reply-To address, a visible unsubscribe, list hygiene with bounce management, and honest subject lines. Those are recommendations rather than rules, but they describe the hygiene Microsoft's filters reward.
Microsoft's list is shorter than Google's. In practice, if you meet Google's requirements you meet Microsoft's. The reverse is not true: a domain that passes Microsoft's three authentication checks can still fail Google on spam rate or opt-out handling, so build to the longer list.
Does the 5,000 a day threshold apply to a cold email programme?
Rarely by the letter, always in practice. Google counts messages sent from the same primary domain toward the 5,000, so spreading volume across many mailboxes does not change the count. But a well-run cold email programme sends 300 to 1,000 emails a day in total, split across 4 to 12 secondary domains at about 90 a day each. No single domain gets anywhere near the line. That is not a reason to relax.
The rules describe what Google and Microsoft consider a trustworthy sender, and their filters apply the same authentication checks and complaint signals to a domain sending 90 a day as to one sending 50,000. A missing DKIM signature or a 0.5% complaint rate on a small domain is not exempt. It is simply mail that goes to spam without anyone calling it non-compliant.
Two caveats. The threshold is about mail to consumer Gmail and Outlook.com accounts, and most B2B prospects sit on Google Workspace or Microsoft 365 business mailboxes, which the rules do not name but which run on the same filtering. And Google's FAQ explains how it defines a primary domain; if your sending domains are subdomains of one root, read that section before you assume you are under the line. How the per-mailbox and per-domain limits fit together is in how many cold emails you can send per day.
| Requirement | Google (Gmail) | Microsoft (Outlook.com) | What a cold email team does |
|---|---|---|---|
| SPF and DKIM | Both required | Both required | Set both on every secondary domain before warm-up |
| DMARC | Required; p=none accepted | Required; p=none minimum, aligned | Publish p=none with a reporting address; tighten later |
| From header | Must align with the SPF or DKIM domain | Aligned; valid From and Reply-To recommended | Send from the domain you authenticated; real reply address |
| Spam rate | Under 0.3%; stay under 0.1% (Postmaster Tools) | Not a stated number; complaints still filter | Target zero; pause a domain at 0.1% |
| Unsubscribe | One-click on marketing and subscribed mail; honour within 2 days | Visible unsubscribe recommended | Plain opt-out line in every email; suppress same day |
| DNS and TLS | Valid forward and reverse DNS (PTR); TLS | Not named in the announcement | Use a mainstream mailbox provider; never home-grown SMTP |
| List hygiene | Low bounce and spam rates expected | List hygiene and bounce management recommended | Verify before loading; re-verify after 60 to 90 days |
| Subject lines | Not a separate rule in the bulk list | Honest subject lines recommended | The subject says what the email is about |
| Enforcement | Effective February 1, 2024 | Junk from May 5, 2025; rejection (550 5.7.15) announced | Assume both are live; check the current pages |
What is the difference between the 0.1% target and the 0.3% ceiling?
0.3% is the spam rate Google says you must never reach; 0.1% is the rate it recommends staying under. Both are measured in Postmaster Tools as the share of your mail that Gmail users mark as spam. At 1,000 sends a day, 0.3% is three complaints a day. On one secondary domain sending 90 a day, a single complaint is 1.1% for that day. That is why we treat 0.1% as the pause line and zero as the target.
Postmaster Tools reports by domain and only shows data once a domain sends enough mail, so a small secondary domain often shows nothing at all. An empty dashboard is not a clean bill of health. Watch the numbers that move before complaints do: bounces above 2% to 3%, a reply rate falling on one domain while its siblings hold, and a rise in curt 'not interested' replies. Those are the signs a domain needs a rest before Google tells you. The full early-warning list is in how to keep your domains off spam blacklists.
How do you handle the unsubscribe rule in a one-to-one cold email?
Put a plain opt-out line in every email, process every opt-out the same day, and add List-Unsubscribe headers where your sending tool supports them. Google's one-click rule is written for marketing and subscribed mail, and a one-to-one prospecting email is neither, but the two-day rule for honouring opt-outs is the standard any outbound team should hold itself to anyway. Ignored opt-outs turn into spam complaints, and complaints are the metric that kills domains.
The line does not need to be a link. 'If this is not relevant, reply no and I will not write again' gets read and produces replies rather than complaints. Whatever wording you use, the reply has to actually stop the sequence across every mailbox and every domain in the campaign. A suppression list that lives in one tool while another tool keeps sending is the most common way we see this go wrong.
When do these rules not change what you do?
If you already run cold email the disciplined way, the rules change nothing except your monitoring. Secondary domains bought for outreach, SPF, DKIM, and DMARC published before warm-up, 20 to 40 sends per mailbox per day, verified lists, an opt-out line, and a weekly look at Postmaster Tools already meet every row in the table above. The rules bite teams that send from their primary domain, skip authentication, or blast a raw list from a cheap tool.
They are also not law. Google and Microsoft set conditions for delivering mail to their own users, which is a commercial decision, not a statute. The legal side of cold email (CAN-SPAM, GDPR, India's rules) is a separate question with separate answers, and nothing here is legal advice. Meeting the bulk sender rules does not make a campaign lawful, and a lawful campaign that ignores them still lands in spam. The setup that satisfies both is in our cold email deliverability checklist.
How MarginSales approaches bulk sender compliance
MarginSales provides sales outreach services for companies that want to extend their outbound capacity without building the entire sales development function internally. Every programme starts with sending domains bought in the client's name, SPF, DKIM, and DMARC published before the first warm-up email, and a 3 to 4 week warm-up before a prospect sees anything. We hold each mailbox to 20 to 40 sends a day, verify every list before it loads and again after 60 to 90 days, and put an opt-out line in every email with same-day suppression across every domain in the campaign.
Postmaster Tools is checked weekly per domain. A domain that shows a spam rate at or above 0.1%, or bounces above 2% to 3%, is paused and rested rather than pushed. That discipline is why reply rates hold: disciplined outreach runs 8% to 11% raw in our campaigns, and none of it reaches an inbox if the authentication is wrong. The mechanics of inbox rotation and SPF, DKIM, and DMARC are in their own post, and the full stack from domains to reporting is in our guide to outbound sales infrastructure.
Frequently asked questions
Do Google's bulk sender rules apply to cold email?
By the letter they apply to senders of 5,000 or more messages a day to Gmail accounts, counted per primary domain. Most cold email programmes send far less. In practice the same authentication and spam-rate signals decide whether any cold email reaches the inbox, so treat the rules as the minimum standard for every sending domain you own.
What spam rate does Gmail allow?
Google's stated ceiling for bulk senders is 0.3%, measured in Postmaster Tools, and it recommends staying under 0.1%. At cold email volumes a single complaint on a small domain can exceed both, so the practical target is zero complaints, with a pause on any domain that reaches 0.1%.
What happens if you ignore Microsoft's requirements?
For senders over 5,000 a day to Outlook.com, Hotmail, and Live addresses, Microsoft began routing mail without SPF, DKIM, and DMARC to the Junk folder from May 5, 2025, and announced that outright rejection with error 550 5.7.15 would follow. Below the threshold there is no formal penalty, but unauthenticated mail into Microsoft mailboxes filters badly regardless.
Is DMARC at p=none enough for cold email?
Yes, for both Google and Microsoft as of September 2026. p=none is a monitoring policy that blocks nothing, but it satisfies the rule and gives you reports on what is sending as your domain. Once the reports are clean, moving to p=quarantine protects the domain against spoofing without affecting your own mail.
Get one sending domain checked against both rule sets
Send us one of your sending domains and a screenshot of its Postmaster Tools dashboard, and we will check it against every row in the table above: SPF, DKIM, DMARC alignment, PTR, TLS, opt-out handling, and per-mailbox volume. You get a written list of what would fail and the order to fix it in, whether or not you work with us. Book the domain check.