The short version

Since February 2024, Gmail and Yahoo have required every sender to authenticate their mail, keep spam complaints low, and send properly formatted messages. Bulk senders must also publish DMARC, align their From address with SPF or DKIM, and offer one-click unsubscribe. Microsoft applied the authentication part to Outlook.com, Hotmail and Live.com in May 2025. Gmail began ramping up enforcement in November 2025, with temporary and permanent rejections.

Requirement Gmail, everyone Gmail, bulk Yahoo, everyone Yahoo, bulk Outlook.com, over 5,000 a day
SPF or DKIM Required Required
SPF and DKIM both Required Required Both must pass
DMARC record At least p=none At least p=none At least p=none
From domain aligned with SPF or DKIM Required Required Required (both preferred)
One-click unsubscribe Marketing and subscribed mail Marketing and subscribed mail A working unsubscribe link recommended
Spam rate Under 0.3% (aim for 0.1%) Under 0.3% (aim for 0.1%) Under 0.3% Under 0.3% Not stated
Valid forward and reverse DNS for sending IPs Required Required Required Required
TLS for sending Required Required

Sources: Google's email sender guidelines and FAQ, Yahoo's sender requirements and FAQ, and Microsoft's announcement for high-volume senders. Read 7 October 2026.

Check the DNS part now

SPF, DKIM and DMARC are DNS records, so they can be checked from outside. The checker below tests all three and the rest of your setup. Alignment, spam rate and unsubscribe headers depend on each message, so it cannot confirm those (see "Which rules you can check" below).

Check your domain's email setup

Runs in your browser. Lookups go straight from your browser to Cloudflare's public DNS resolver (Google Public DNS if Cloudflare fails). MailSetupCheck has no server and never sees the domain you check.

The part after the @ in your email address. You can paste a website address or an email address too.

Options: DKIM selector and DMARC report address

Where to find your selector: open a message you sent, view the original or raw message, and read s= in the DKIM-Signature line. The checker also tries 34 common selectors.

Used only to fill in the DMARC record the checker suggests. It is not looked up or sent anywhere.

Who counts as a bulk sender

A small business that sends a few hundred messages a day is not a Gmail bulk sender today. One newsletter to a large list can make it one for good, so set up the bulk requirements before you need them. They cost nothing but a few DNS records and the right settings in your sending tools.

What every sender needs

Gmail's list for all senders, quoted from its guidelines, with Yahoo's equivalents:

  1. "Set up SPF or DKIM email authentication for your sending domains." Yahoo: "Implement SPF or DKIM at a minimum."
  2. "Ensure that sending domains or IPs have valid forward and reverse DNS records, also referred to as PTR records." Your email provider handles this if you use Google Workspace, Microsoft 365 or a major sending service. If you run your own mail server, the server's IP address must have a PTR record naming a host that resolves back to the same IP.
  3. "Use a TLS connection for transmitting email." Again, handled by mainstream providers.
  4. "Keep spam rates reported in Postmaster Tools below 0.3%." Yahoo: "Keep your spam rate below 0.3%."
  5. "Format messages according to the Internet Message Format standard, RFC 5322."
  6. "Don't impersonate Gmail From: headers." Do not send as an @gmail.com address through other servers.

Gmail also requires DKIM keys of at least 1024 bits and recommends 2048: "Sending to personal Gmail accounts requires a DKIM key of 1024 bits or longer. For security reasons, we recommend using a 2048-bit key if your domain provider supports this." Yahoo also asks for a minimum of 1024 bits.

What bulk senders need on top

What happens when you miss

Which rules you can check from outside

Rule Visible in DNS? How to check it
SPF published and valid Yes The checker above
DKIM key published Mostly The checker, with your selector if it is unusual
DMARC published Yes The checker above
Alignment No Send yourself a message at Gmail, choose "Show original", look for dmarc=pass
Reverse DNS and TLS of sending servers No Gmail's "Show original" view shows TLS; your provider handles both if you use a major one
Spam rate No Google Postmaster Tools, and Yahoo's Sender Hub
One-click unsubscribe No Look for List-Unsubscribe-Post in a marketing message you sent

The order to fix things in

  1. SPF: one record that lists every service sending as your domain. Keep it under 10 DNS lookups.
  2. DKIM: turn it on in every sending service, with your own domain, using 2048-bit keys where offered.
  3. DMARC: publish v=DMARC1; p=none; rua=mailto: plus an address you read or a report service. The checker writes the record for you.
  4. Alignment: confirm dmarc=pass in a test message from each sending service.
  5. Unsubscribe: turn on one-click unsubscribe in your newsletter or marketing tool, and make sure opt-outs are processed within two days.
  6. Watch: register your domain in Google Postmaster Tools and keep the spam rate under 0.1%.
  7. Enforce: once reports show all your real mail passing, move DMARC to quarantine and then reject.

If you send cold email, the same rules apply, and US law adds its own: see cold email that stays legal.

Also available as Markdown.