Cold email deliverability in 2026: what Gmail, Yahoo and Outlook require

The short answer: authenticate every sending domain with SPF, DKIM and DMARC, keep your spam complaint rate under 0.1% and never let it reach 0.3%, give every recipient an easy way to opt out, send from separate domains warmed for two to three weeks, verify every address before it goes out, and keep daily volume per inbox low. Gmail and Yahoo have required this of bulk senders since February 2024. Microsoft began rejecting non-compliant mail to Outlook.com addresses on May 5, 2025, and Gmail began rejecting non-compliant traffic in November 2025.

The rules at a glance

Three mailbox providers set the rules most senders live by. Here is what each one requires today.

Sender requirements by mailbox provider
RequirementGmailYahooOutlook.com
Who it coversAll senders to personal Gmail accounts, with stricter rules above 5,000 messages a dayBulk senders to Yahoo addressesSenders of more than 5,000 messages a day to Outlook.com, Hotmail.com and Live.com addresses
SPF and DKIMSPF or DKIM for everyone. Both above 5,000 a dayBothBoth must pass
DMARCRequired above 5,000 a day, with the From domain aligned to SPF or DKIMRequired, at least p=none, and it must passRequired, at least p=none, aligned with SPF or DKIM
Spam complaint rateBelow 0.1%, and never 0.3% or higherBelow 0.3%No published threshold
UnsubscribeOne-click unsubscribe for marketing and subscribed messages above 5,000 a dayOne-click unsubscribe (RFC 8058), honored within 2 daysA clear, visible way to opt out (recommended)
EnforcementGradual since February 2024. Temporary and permanent rejections since November 2025Since February 2024Rejection since May 5, 2025, with error 550 5.7.515

Two details catch people out. First, Gmail's bulk sender status never expires: once you cross 5,000 messages a day to Gmail accounts, you're held to the stricter rules even if volume drops. Second, these rules are written for personal mailboxes. Business inboxes on Google Workspace and Microsoft 365 run their own filtering, but the same signals decide placement there, so we hold every sending domain to the strictest standard.

Does this apply to cold email?

Yes. Mailbox providers judge how mail is sent and how recipients react to it, not whether the recipient asked for it. A cold email that isn't authenticated, or that draws complaints, is filtered like any other mail.

In the US, cold email is also commercial email under the CAN-SPAM Act, and the Federal Trade Commission is explicit that the law makes no exception for business-to-business email. Every message needs accurate header information, a subject line that isn't deceptive, a valid physical postal address and a clear way to opt out, and opt-outs must be honored within 10 business days. Each email that breaks the rules can draw a penalty of up to $53,088. Rules are stricter in the EU, the UK and Canada, so check them before you send there.

Send from separate domains

Never send cold email from the domain your company uses every day. Register a few domains close to your brand, point them at your website, and send from those. If one of them runs into trouble, your invoices, support tickets and team email keep landing.

At Be Leaded we spread volume across several sending domains with a few inboxes each, so no single domain or inbox carries much of the load.

Set up SPF, DKIM and DMARC

These three DNS records prove that mail from your domain is really from you. Gmail, Yahoo and Microsoft all check them.

SPF

SPF lists the servers allowed to send for your domain. Publish one SPF record per domain and keep it under the limit of 10 DNS lookups. For a domain on Google Workspace it looks like this:

v=spf1 include:_spf.google.com ~all

DKIM

DKIM signs every message with a key published in your DNS, so receivers can tell the message wasn't altered. Use 2048-bit keys where your provider supports them, and turn signing on in your email admin console after the record is published.

DMARC

DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports. p=none is the minimum Gmail, Yahoo and Microsoft accept. Move to quarantine once reports show all of your legitimate mail passing.

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Alignment is the part most setups miss: the domain in your From address has to match the domain that passes SPF or DKIM. A message can pass SPF on a sending tool's domain and still fail DMARC because it isn't aligned.

Warm up every new inbox

New inboxes have no sending history, and providers treat them with suspicion. We warm every new inbox for two to three weeks before any real send, starting with a small daily volume and raising it steadily. Warmup keeps running at a low level after launch.

Keep volume per inbox low

Deliverability problems usually start when one inbox carries too much. When a program needs more reach, add inboxes and domains rather than pushing harder through the ones you have, and ramp every new inbox gradually. It costs a little more in infrastructure and saves the domain.

Verify every address

Bounces tell providers your list is old or bought. Verify every address before it sends and remove anything invalid. Catch-all domains accept every address, so verification can't confirm them: check them with a second tool or hold them for later, smaller sends. Suppress everyone who opted out across every campaign and every sending domain.

Write like a person

Filters and people react to the same things. Emails that read like a note from one person to another get replies, and replies are one of the strongest signals a sender can earn.

  • Plain text, short, and about the recipient's business rather than yours
  • No images, attachments or link shorteners, and few or no links in the first email
  • One clear question the recipient can answer in a line
  • An honest subject line and a real name in the From field
  • If you track opens, use a custom tracking domain rather than a shared one

Monitor every day

Deliverability changes quietly. Every morning we check each sending domain for:

  • SPF, DKIM and DMARC records still resolving and passing
  • Listings on blocklists such as Spamhaus, SURBL and URIBL
  • Bounce and spam complaint rates by domain and inbox
  • Domain reputation and spam rate in Google Postmaster Tools
  • DMARC aggregate reports for mail failing authentication

At the first sign of trouble, pause the affected domain, find the cause, and resume slowly.

Checklist

  • Separate sending domains that point to your website
  • SPF, DKIM and DMARC on every sending domain, with alignment
  • Two to three weeks of warmup on every new inbox
  • Low daily volume per inbox, with more inboxes when you need reach
  • Every address verified, catch-alls handled separately
  • A physical postal address and a clear opt-out in every email
  • Opt-outs suppressed everywhere, and honored well within 10 business days
  • Spam complaints under 0.1%
  • Daily checks on DNS, blocklists, bounces and complaints

Want a second pair of eyes? Send your sending domains to sales@beleaded.com before your call and we'll check SPF, DKIM, DMARC and blocklists for you.

FAQ

What spam complaint rate do Gmail and Yahoo allow?

Gmail asks senders to keep the spam rate reported in Postmaster Tools below 0.1% and never to reach 0.3% or higher. Yahoo asks bulk senders to stay below 0.3%.

Do I need DMARC for cold email?

If you send more than 5,000 messages a day to Gmail or Outlook.com addresses, DMARC is required, with a policy of at least p=none. In practice every sending domain should have it, because it's one of the first things filters check.

How long does inbox warmup take?

We warm every new inbox for two to three weeks before real sends, starting small and raising volume steadily, and keep warmup running at a low level afterward.

Can I send cold email from my company domain?

You can, but we don't recommend it. If the domain's reputation drops, every email your company sends suffers. Separate sending domains keep cold outreach away from your invoices, support and day-to-day email.

What happens if I don't meet Microsoft's requirements?

Since May 5, 2025, Outlook.com rejects mail from senders of more than 5,000 messages a day that fail SPF, DKIM or DMARC, with the error 550 5.7.515.

Is cold email legal in the US?

Yes, if it follows CAN-SPAM: accurate headers, an honest subject line, a physical postal address, a clear opt-out and opt-outs honored within 10 business days. The law applies to business-to-business email too.

Sources

  1. Google, Email sender guidelines
  2. Google, Email sender guidelines FAQ
  3. Yahoo Sender Hub, Sender best practices
  4. Microsoft, Outlook's new requirements for high-volume senders
  5. dmarcian, Microsoft enforces SPF, DKIM and DMARC for high-volume senders
  6. DMARCwise, Gmail ramps up enforcement of the sender requirements
  7. Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business
  8. RFC 8058, One-click unsubscribe
  9. RFC 7208, Sender Policy Framework

Tell us who you want to meet.

Thirty minutes with the founder. You'll leave with a clear picture of your market, what a campaign would look like and what it would cost.