Email Marketing

How SPF, DKIM and DMARC decide whether a marketing email gets rejected

Gmail and Yahoo can now reject noncompliant bulk mail outright. Here is what each authentication record checks and why alignment decides delivery.

For years, the worst outcome of sloppy email authentication was the spam folder. A campaign might underperform, but it usually still arrived somewhere. That is no longer guaranteed. Gmail and Yahoo now apply bulk sender rules that can cause noncompliant marketing and lifecycle email to be refused at the server level before it reaches any folder.

The rules run on three technical records: SPF, DKIM and DMARC. Each checks something different, and DMARC is the one that decides what happens when the other two do not agree with the address a recipient actually sees. Understanding what each record verifies is the fastest way to diagnose why a campaign or flow is failing to land.

What SPF actually checks

SPF, or Sender Policy Framework, is a text record published in a domain's DNS that lists the IP addresses and servers allowed to send mail on that domain's behalf. When a message arrives, the receiving mail server looks up the sending domain's SPF record and checks whether the server that delivered the message is on the approved list.

This is useful for catching an unauthorized server pretending to be a brand's domain, but it has a narrow blind spot: SPF checks the server, not the message content, and it breaks when mail is forwarded through a system not on the original list.

What DKIM adds

DKIM, or DomainKeys Identified Mail, attaches a cryptographic signature to each outgoing message using a private key held by the sending domain. The receiving server retrieves the matching public key from the domain's DNS record and verifies the signature. A valid match confirms the message came from a server holding that domain's private key and that its signed contents were not altered in transit.

DKIM matters beyond spoofing prevention. Under RFC 8058, the IETF standard for one-click unsubscribe published in January 2017, a message must carry a valid DKIM signature covering its List-Unsubscribe and List-Unsubscribe-Post headers before a mailbox provider will offer one-click unsubscribe at all. Without that signature, the RFC states, receivers should not offer the one-click option, which is itself now a delivery requirement at Gmail and Yahoo.

How DMARC ties both records to the From address

SPF and DKIM can both pass while checking a domain the recipient never sees, since neither is required to match the visible From: address on its own. DMARC, or Domain-based Message Authentication, Reporting and Conformance, closes that gap. According to DMARC.org, the industry body behind the standard, DMARC lets a domain owner publish a policy telling receiving servers what to do when a message fails to align, and it exists specifically because receivers were otherwise forced to guess whether an unauthenticated message was a legitimate quirk of the sender's infrastructure or a forgery.

A DMARC record sets one of three policies: p=none, which requests reporting only and takes no action on failing mail; p=quarantine, which asks receivers to route failing mail to spam; and p=reject, which asks receivers to refuse it outright. Alignment itself has a specific, narrower meaning than many marketers assume. Google's own guidance on its sender requirements states that only one of SPF or DKIM needs to align with the From: domain for a message to pass DMARC, not both, though the company recommends aligning both to ensure reliable authentication.

Why the bulk sender threshold changes the stakes

Google's sender guidelines classify any domain sending more than 5,000 messages a day to personal Gmail accounts as a bulk sender, a threshold that has applied since February 2024. That tier faces requirements beyond casual senders: SPF and DKIM must both be configured, a DMARC record must exist for the sending domain, marketing messages must support one-click unsubscribe, and spam complaint rates must stay under 0.3% as measured in Postmaster Tools. Google's own guidance goes further, advising senders to stay under 0.1% rather than treat 0.3% as a safe operating ceiling.

Yahoo runs a parallel program through its Sender Hub, and its published best practices require the same core elements: SPF and DKIM implemented together, a DMARC policy of at least p=none that must pass, a spam rate held below 0.3%, and unsubscribe requests honored within two days. Yahoo's own documentation does not spell out a specific daily volume figure that triggers bulk sender classification, unlike Google's explicit 5,000-message threshold, so senders operating near that range should not assume Yahoo applies an identical cutoff.

A DMARC record with no aligned SPF or DKIM behind it will fail regardless of the policy set.

What changed with enforcement in late 2025

Google's authentication requirements themselves date to February 2024, but the company's own FAQ states that enforcement against noncompliant traffic intensified starting in November 2025. The FAQ describes the consequence for a violation as either temporary or permanent failure codes at the SMTP level, or spam foldering, with the outcome depending on which specific requirement was violated rather than a single uniform penalty.

The spam-rate rule carries its own enforcement mechanic worth noting precisely. Google's FAQ states that any bulk sender whose user-reported spam rate exceeds 0.3% becomes ineligible for delivery mitigation, and that ineligibility does not lift the moment the rate drops back below the line. A sender must hold the rate below 0.3% for seven consecutive days before mitigation eligibility is restored, which means a single bad send from a poorly segmented list can suppress deliverability for more than a week even after the underlying problem is fixed.

What to check first

Because DMARC only needs one aligned record to pass, the first diagnostic step for a delivery problem is confirming which domain actually appears in the visible From: address and whether the email service provider is authenticating that exact domain, not a subdomain or a shared sending domain the provider uses by default. A DMARC record with no aligned SPF or DKIM behind it will fail regardless of the policy set.

After alignment, the two figures worth checking on a fixed schedule are the spam complaint rate reported in Google Postmaster Tools or Yahoo's Sender Hub, and whether the one-click unsubscribe header is present and actually processes requests within Yahoo's stated two-day window. Both platforms' own guidance treats these as the levers that move a domain between compliant and noncompliant, rather than authentication records alone.

Sources

  1. Email sender guidelines — Google
  2. Email sender guidelines FAQ — Google
  3. Yahoo Sender Hub: Best Practices — Yahoo Inc.
  4. DMARC Overview — DMARC.org
  5. RFC 8058: Signaling One-Click Functionality for List Email Headers — IETF / RFC Editor

More from Insights