Bulk Email Sender Requirements in 2026

What Google, Yahoo, and the law actually require of anyone sending email at volume — every claim linked to its primary source.

7 min read
July 20, 2026
Compliance

Requirements at a glance

Requirement Who requires it Applies to
SPF or DKIM authenticationGoogle, YahooAll senders
SPF and DKIM + aligned DMARCGoogle, YahooBulk senders (5,000+/day)
One-click unsubscribe (RFC 8058), honored ≤ 2 daysGoogle, YahooBulk senders
Spam-report rate under 0.3% (target < 0.1%)Google, YahooAll senders
Truthful headers & subject linesCAN-SPAM (US law)All commercial email
Valid physical postal address in every messageCAN-SPAM (US law)All commercial email
Opt-outs honored within 10 business daysCAN-SPAM (US law)All commercial email

Since February 2024, the rules of bulk email have been written by two groups: mailbox providers (Google, Yahoo, and later Microsoft) and lawmakers (CAN-SPAM in the US, GDPR in the EU, CASL in Canada). Providers enforce their rules technically — non-compliant mail is rejected or junked. The law enforces its rules financially. This page lists what each actually requires, with a link to every primary source.

The Google & Yahoo bulk sender rules

In October 2023, Google and Yahoo jointly announced new requirements for senders, enforced beginning February 2024 (Google's announcement). Google defines a bulk sender as any sender that sends around 5,000 or more messages to Gmail addresses within a 24-hour period — and once you qualify, you're treated as a bulk sender permanently (Email sender guidelines).

1. Authentication: SPF, DKIM, and DMARC

Every sender must authenticate with SPF or DKIM at minimum. Bulk senders must have both SPF and DKIM pass, plus a published DMARC policy (at least p=none) with the From: domain aligned to the authenticated domain. Messages must also come from infrastructure with valid forward and reverse DNS (PTR) records, and be transmitted over TLS. All of this is specified in Google's sender guidelines and Yahoo's sender best practices.

2. One-click unsubscribe (RFC 8058)

Bulk senders of marketing or promotional mail must support one-click unsubscribe — the List-Unsubscribe and List-Unsubscribe-Post headers defined in RFC 8058 — and must process unsubscribe requests within two days. This is separate from, and stricter than, the CAN-SPAM opt-out window below. A visible unsubscribe link in the message body is still required as well.

3. Spam-rate thresholds

Google instructs senders to keep their user-reported spam rate (measured in Postmaster Tools) below 0.10% and to never let it reach 0.30% or higher. Yahoo enforces the same complaint-rate ceiling. Cross the line and delivery degrades for the whole domain — authentication does not rescue a sender people are reporting.

Microsoft announced equivalent requirements for Outlook.com senders exceeding 5,000 messages per day in 2025, completing the alignment of the three major mailbox providers around the same baseline: authenticate fully, make leaving easy, and keep complaints near zero.

CAN-SPAM: the US legal baseline

The CAN-SPAM Act applies to all commercial email in the United States — B2B included. It is an opt-out regime: prior consent is not required, but every message must meet seven requirements, per the FTC's compliance guide:

Each separate violating email is subject to civil penalties that currently exceed $50,000 (the figure is adjusted for inflation; see the FTC guide for the current amount).

GDPR, ePrivacy, and CASL

Outside the US, the default flips from opt-out to consent-based:

Where purchased lists fit

The legal answer depends on jurisdiction: CAN-SPAM does not prohibit emailing purchased or third-party contacts, while consent-based regimes (GDPR, CASL) make most purchased-list sending non-compliant unless consent transfers. The practical answer is stricter than the legal one: mailbox providers evaluate recipient behavior, not list provenance — and most marketing ESPs (Mailchimp, Klaviyo, and similar) prohibit purchased lists in their terms of service outright.

What actually determines outcomes is list quality. Across 170,000+ cold emails sent on our infrastructure over the past 12 months, campaigns using verified addresses averaged a 0.8% bounce rate; the one list we deliberately sent without verification bounced 98.4% — a rate that would burn a sending domain in a single day. Whatever the source of a list, verify every address before it sees a send and keep complaint rates within the thresholds above.

Compliance checklist

  1. Publish SPF and DKIM for every sending domain; verify both pass and align
  2. Publish a DMARC record (start at p=none, monitor, then tighten)
  3. Confirm valid PTR (reverse DNS) records for sending IPs; send over TLS
  4. Implement RFC 8058 one-click unsubscribe headers; process opt-outs within 2 days
  5. Include a physical postal address and a visible unsubscribe path in every message
  6. Register in Google Postmaster Tools and watch the spam-rate dashboard (< 0.10%)
  7. Verify every list before sending; suppress bounces and unsubscribes globally
  8. Map recipients by jurisdiction — US (opt-out), EU (consent/legitimate interest by state), Canada (consent)

For the technical implementation details — DNS records, warm-up schedules, monitoring — see our cold email deliverability guide. For what results compliant sending actually produces, see our cold email statistics report covering 2M+ real sends.

Primary sources

Want Compliant Cold Email Done For You?

Sales.co runs fully managed, compliance-first outbound for 500+ B2B companies — authentication, list verification, and monitoring included.

Book Your Free Strategy Call

Related Articles