# Gmail and Yahoo Bulk Sender Requirements: 2026 Host Checklist

Source: https://srvscripts.com/guides/gmail-yahoo-bulk-sender-requirements/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** If a domain sends close to 5,000 or more messages a day to personal Gmail accounts, Gmail treats it as a bulk sender for good. It must pass SPF and DKIM, publish a DMARC record (`p=none` is enough) with the From domain aligned, have matching forward and reverse DNS, use TLS, support one-click unsubscribe on marketing mail and keep the spam rate below 0.3%. Yahoo has the same list but no published volume threshold. Since November 2025 Gmail has been rejecting more non-compliant mail with 4.7.x and 5.7.x codes.

We ran the DNS, DKIM and Exim checks below on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138, and DirectAdmin 1.712, both with Exim 4.100.1) on 6 October 2026. The rules themselves were checked against the Google and Yahoo sender pages linked below on the same day.

## Who counts as a bulk sender

**Gmail:** a bulk sender is any sender that sends close to 5,000 messages or more to personal Gmail accounts (`@gmail.com` and `@googlemail.com`) within 24 hours. Gmail counts everything sent from the same primary domain, so 2,500 messages from `example.com` plus 2,500 from `news.example.com` make you a bulk sender. Once a domain qualifies, the status is permanent. It does not expire if your volume drops. Mail sent to Google Workspace accounts is not covered by these rules.

**Yahoo:** Yahoo says a bulk sender sends “a significant volume of mail” and will not publish a number. Its rules apply to every domain Yahoo Mail hosts, including AOL. In practice, treat any domain that sends newsletters or marketing as a bulk sender at both providers.

On a shared hosting server this matters even if no single customer is big. Gmail tracks volume per domain, but IP reputation is shared by every domain sending from that IP. One customer’s non-compliant campaign hurts everyone on the box.

## The requirements side by side

| Requirement | Gmail (all senders) | Gmail bulk | Yahoo bulk |
| --- | --- | --- | --- |
| SPF | SPF or DKIM | Required | Required |
| DKIM | SPF or DKIM | Required (key 1024 bits or longer, 2048 recommended) | Required |
| DMARC record | Recommended | Required, p=none is enough | Required, at least p=none, DMARC must pass |
| From domain aligned with SPF or DKIM | No | Required | Required (relaxed alignment is fine) |
| Forward and reverse DNS (PTR) for sending IPs | Required | Required | Required |
| TLS for SMTP | Required | Required | Not listed |
| RFC 5322 message format | Required | Required | Required (RFC 5321 and 5322) |
| Spam rate | Below 0.3% | Below 0.3% (aim for under 0.1%) | Below 0.3% |
| One-click unsubscribe (RFC 8058) on marketing mail | No | Required | Required (POST method “highly recommended”, mailto accepted) |
| Honour unsubscribes |  | Within 48 hours | Within 2 days |

Both providers exclude transactional mail such as password resets and order confirmations from the one-click unsubscribe rule. Gmail also says not to put a `@gmail.com` address in the From header of mail you send from your own servers, because Gmail’s DMARC policy is moving to quarantine.

## Enforcement timeline, including November 2025

| Date | What changed |
| --- | --- |
| February 2024 | Gmail and Yahoo start enforcing the rules, gradually. |
| June 2024 | Gmail: bulk senders with a spam rate over 0.3% lose eligibility for delivery mitigation; deadline for one-click unsubscribe on promotional mail. Yahoo starts enforcing its List-Unsubscribe rule. |
| 1 August 2024 | Yahoo Complaint Feedback Loop reports stop for domains not re-enrolled in the new Sender Hub. |
| November 2025 | Gmail “ramps up” enforcement: mail that fails the requirements gets temporary and permanent rejections, not only spam-folder placement. |

Gmail has also added a compliance status dashboard to Postmaster Tools. Use it as your scorecard: it shows which requirement a domain fails.

## Gmail rejection codes and what each one means

Gmail’s FAQ lists these codes. A `4.7.x` code is a temporary rate limit and your server will retry. A `5.7.x` code is a permanent block for that message.

| Code | Meaning | Where to look |
| --- | --- | --- |
| 4.7.23 / 5.7.25 | Sending IP has no PTR, or the PTR hostname does not resolve back to the IP | Reverse DNS at your IP provider |
| 4.7.27 / 5.7.27 | SPF did not pass | SPF record for the envelope (Return-Path) domain |
| 4.7.29 / 5.7.29 | Message not sent over TLS | MTA TLS settings and certificate |
| 4.7.30 / 5.7.30 | DKIM did not pass | DKIM signing and the published key |
| 4.7.31 | No DMARC record, or no policy in it | _dmarc TXT record |
| 4.7.32 | From domain not aligned with SPF or DKIM | Envelope domain and DKIM d= |

Paste the bounce or the message headers into our [Email Header Analyzer](/tools/email-header-analyzer/) to see which check failed.

## Checklist for hosting admins

### 1. Reverse DNS and HELO

Find the IP Exim really sends from (on cPanel, `/etc/mailips` can map domains to other IPs; it was empty on our lab, so mail used the main IP). Then check that the PTR and the A record point at each other:

```
dig +short -x 203.0.113.10
dig +short A server.example.com
```

On our cPanel lab the PTR was the server hostname and the A record matched the IP. If they do not match, ask your IP provider to set the PTR to the hostname Exim uses in HELO. Our [Reverse DNS Lookup](/tools/reverse-dns-lookup/) checks up to 25 IPs at once.

### 2. SPF for every envelope domain

Check the domain in the Return-Path, not just the From address. Keep it under 10 DNS lookups. Test with our [SPF Record Checker](/tools/spf-record-checker/).

### 3. DKIM with a 2048-bit key

cPanel signs with selector `default` and keeps keys in `/var/cpanel/domain_keys/`. DirectAdmin signs with selector `x` and reads `/etc/virtual/DOMAIN/dkim.private.key`. We confirmed both in the Exim configuration on our labs. To check the published key length:

```
dig +short TXT default._domainkey.example.com | sed -e 's/" "//g' -e 's/"//g' -e 's/.*p=//' -e 's/;.*//' | tr -d '[:space:]' | base64 -d | openssl pkey -pubin -inform DER -noout -text | head -1
```

On our cPanel lab this printed `Public-Key: (2048 bit)`. For DirectAdmin, replace `default` with `x`. Our [DKIM Checker](/tools/dkim-checker/) does the same lookup from the web.

### 4. DMARC with alignment

Start with a monitoring record and a report address you read:

```
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
```

Build one with our [DMARC Record Generator](/tools/dmarc-record-generator/) and check it with the [DMARC Checker](/tools/dmarc-checker/). Alignment means the DKIM `d=` domain or the SPF envelope domain shares the organizational domain of the From address. Mail sent by a plugin through `mail()` as `bob@server.example.net` with `From: shop@example.com` fails alignment even if SPF passes.

### 5. TLS on outbound SMTP

Exim on cPanel and DirectAdmin offers STARTTLS out of the box. Check that the server certificate is valid and that nothing forces plain-text delivery. Our [SMTP Test](/tools/smtp-test/) shows the STARTTLS result and certificate.

### 6. One-click unsubscribe

This is the sending application’s job, not Exim’s. Newsletter software must add `List-Unsubscribe` with an HTTPS URL plus `List-Unsubscribe-Post: List-Unsubscribe=One-Click`, and the DKIM signature must cover both headers. On our labs, Exim 4.100.1 had no `dkim_sign_headers` override and its built-in default list already includes `List-Unsubscribe` and `List-Unsubscribe-Post`, so the server signs them when the application adds them.

### 7. Complaint monitoring

- Gmail: add and verify each domain in Postmaster Tools and watch the spam rate and the compliance dashboard daily.

- Yahoo: create a Sender Hub account, verify the DKIM `d=` domains and enrol them in the Complaint Feedback Loop. Yahoo no longer offers IP-based feedback loops.

- Outlook.com: enrol your IPs in SNDS and JMRP. Microsoft has its own 5,000-a-day rules.

### 8. Message hygiene

One address in `From:`, a valid `Message-ID`, no duplicated single-instance headers, no fake `Re:` subjects, and send marketing and transactional mail from different addresses (ideally different subdomains).

## Check that it worked

- Send a test from each sending system (webmail, WordPress, the newsletter tool) to a personal Gmail address.

- In Gmail, open **Show original**. You want `SPF: PASS`, `DKIM: PASS` and `DMARC: PASS`, and the DKIM domain should be yours, not the hosting server’s.

- Repeat to a Yahoo mailbox and read the `Authentication-Results` header.

- For marketing mail, confirm the unsubscribe headers are present and listed in the DKIM `h=` tag.

- Check Postmaster Tools after a few days of volume, since data needs enough daily traffic to appear.

## Common problems

- **DMARC passes for webmail but fails for the website.** PHP `mail()` often uses the cPanel username or server hostname as the envelope sender. Send through authenticated SMTP with the domain’s own mailbox instead.

- **DKIM signed by the wrong domain.** A relay or smarthost may sign with its own domain. That passes DKIM but does not align. Configure the relay to sign with your domain, or keep SPF aligned.

- **Shared IP blocked although your domain is clean.** Gmail’s IP quotas are shared by every domain on that IP. Find and stop the noisy sender, or move bulk mail to a dedicated relay.

- **Unsubscribe button not shown in Gmail.** Gmail only shows it for messages that pass its eligibility checks and come from senders with good reputation, even when the headers are right.

**Official documentation:** [Gmail email sender guidelines](https://support.google.com/a/answer/81126) · [Gmail email sender guidelines FAQ](https://support.google.com/a/answer/14229414) · [Yahoo Sender Best Practices](https://senders.yahooinc.com/best-practices/) · [Yahoo Sender FAQs](https://senders.yahooinc.com/faqs/)

**Related:** [SPF, DKIM and DMARC in cPanel DNS: Setup and Checks](/guides/spf-dkim-dmarc-cpanel-dns/) · [Warm Up New Mail Server IP Without Spam Problems](/guides/warm-up-new-mail-server-ip-domain/) · [Email Deliverability Test (Spam Score)](/tools/email-deliverability-test/) · [DMARC Record Generator](/tools/dmarc-record-generator/) · [Mail server IP blacklisted: delisting runbook](/guides/runbook-ip-blacklisted/)

**See also:** [One-Click Unsubscribe (RFC 8058) for Exim, Postfix, WordPress](/guides/one-click-unsubscribe-rfc-8058/) · [Outlook 550 5.7.515: Fix the High-Volume Sender Rejection](/guides/outlook-550-5-7-515-high-volume-senders/) · [Emails Going to Junk in Outlook and Hotmail: Sender-Side Fix](/guides/outlook-junk-folder-sender-fix/) · [Microsoft SNDS and JMRP Setup: 2026 Portal, Access and Reports](/guides/microsoft-snds-jmrp-setup/) · [IP Warm-Up Schedule Generator for New Mail Servers](/tools/ip-warmup-schedule/)

## Frequently asked questions

### What is the Gmail bulk sender threshold?

Close to 5,000 or more messages to personal Gmail accounts in 24 hours, counted across the whole primary domain including subdomains. Once reached, the bulk sender status is permanent.

### Does Yahoo use the same 5,000 a day limit?

No. Yahoo does not publish a threshold. It says bulk senders send a significant volume and applies the rules based on authenticated domain, content and IP.

### Is p=none enough for DMARC?

Yes for Gmail and Yahoo bulk sender rules. The record must exist and DMARC must pass through aligned SPF or DKIM. A stricter policy is better for protection but not required.

### Do password reset emails need one-click unsubscribe?

No. Gmail and Yahoo require one-click unsubscribe only on marketing and promotional mail. Transactional messages are excluded.

### What changed for Gmail in November 2025?

Gmail said it was ramping up enforcement, so messages that fail the sender requirements now see more temporary and permanent rejections instead of only spam placement.

### Do the rules apply to mail sent to Google Workspace addresses?

No. Google says the sender guidelines apply only to personal Gmail accounts, although Workspace users sending to Gmail must meet them.
