Skip to main content
Compliance

Google DMARC Mandate: What You Need to Know

Vysiro Team · January 10, 2026 · Updated March 2026 · 14 min read

The New Rules for Email Senders

If your organization sends email to anyone with a Gmail address — and that includes nearly two billion users worldwide — there is a mandate you cannot afford to ignore. Google now requires DMARC authentication for any domain sending 5,000 or more messages per day to Gmail accounts. This is not a recommendation or a best practice. It is an enforced requirement, and non-compliant senders are already seeing their emails rejected or routed to spam.

The mandate affects every business that relies on email for marketing, transactional notifications, customer communications, or internal operations through Google Workspace. Whether you are a SaaS company sending onboarding emails, an e-commerce brand running promotional campaigns, or an enterprise using Google Workspace for day-to-day communication, these requirements apply to you.

In this guide, we break down exactly what changed, who is affected, what the technical requirements are, and how to achieve compliance step by step. If you want to check your current status right now, you can scan your domain for free and get results in seconds.

What Changed and When

In October 2023, Google and Yahoo jointly announced new email sender requirements that would take effect in February 2024. This was a watershed moment for email security. For the first time, the two largest consumer email providers in the world were making DMARC authentication a hard requirement rather than an optional best practice.

The rollout was phased. Starting in February 2024, Google began issuing temporary errors (HTTP 4xx responses) on a small percentage of non-compliant bulk email traffic. This gave senders a signal that something was wrong without immediately blocking all their email. Over the following months, the enforcement tightened. By April 2024, Google began rejecting a progressively larger percentage of non-compliant messages. By June 2024, full enforcement was in place.

Microsoft followed suit. In May 2025, Outlook.com and Hotmail announced similar requirements for bulk senders, signaling that DMARC enforcement is becoming an industry standard, not just a Google policy.

The message from the inbox providers is clear: if you want your emails to reach their destination, you need to authenticate them properly. The era of unauthenticated bulk email is over.

Who Is Affected

The mandate specifically targets “bulk senders,” which Google defines as any domain that sends 5,000 or more messages per day to Gmail accounts. But the impact extends far beyond that threshold. Here is who needs to pay attention:

  • Marketing teams sending newsletters, promotional emails, or drip campaigns through platforms like Mailchimp, HubSpot, or SendGrid.
  • SaaS platforms sending onboarding sequences, feature announcements, and user notifications.
  • E-commerce businesses sending order confirmations, shipping updates, and promotional campaigns.
  • Transactional email senders using services like Amazon SES, Postmark, or SparkPost for password resets, invoices, and system alerts.
  • Enterprises and agencies managing multiple domains and sending on behalf of clients.

Even if you send fewer than 5,000 messages per day, Google still recommends SPF, DKIM, and DMARC for all senders. Domains without these records increasingly face deliverability issues regardless of volume, because inbox providers use authentication signals as trust indicators in their spam filtering algorithms.

Requirements Breakdown

Google's sender requirements cover five key areas. All five must be met for full compliance.

1. SPF or DKIM Authentication (Both Recommended)

Every email you send must pass either SPF (Sender Policy Framework) or DKIM (DomainKeys Identified Mail) authentication. SPF verifies that the sending server is authorized by your domain's DNS records. DKIM adds a cryptographic signature to each message that receiving servers can verify. Google requires at least one, but strongly recommends both. Having both SPF and DKIM is also necessary for DMARC alignment, which is the next requirement.

2. DMARC Policy at Minimum p=none

Your domain must have a published DMARC record in DNS. The minimum acceptable policy is p=none, which means receiving servers will still deliver messages that fail DMARC checks but will send you reports about those failures. While p=none satisfies the mandate, it provides no enforcement. The recommended path is to start at p=none, monitor your reports, then progress to p=quarantine and eventually p=reject for full protection.

3. Valid Reverse DNS (PTR Records)

Every IP address used to send email must have a valid reverse DNS (PTR) record. This means the IP address must resolve to a hostname, and that hostname must resolve back to the same IP address (forward-confirmed reverse DNS). Most reputable email service providers handle this automatically, but if you run your own mail servers, you need to verify this with your hosting provider.

4. One-Click Unsubscribe for Marketing Emails

All marketing and promotional emails must include a one-click unsubscribe mechanism using the List-Unsubscribe header (RFC 8058). This is not just a visible link in the email body — it must be implemented as an email header that allows mail clients to show an unsubscribe button directly in the inbox interface. Unsubscribe requests must be honored within two days.

5. Spam Complaint Rate Below 0.3%

Your domain's spam complaint rate (as reported by Google Postmaster Tools) must stay below 0.3%. Google recommends keeping it below 0.1% for optimal deliverability. If your spam rate exceeds 0.3%, Google will begin throttling or rejecting your emails regardless of your authentication setup. You can monitor your spam rate through Google Postmaster Tools.

How to Comply: Step by Step

Here is a practical, step-by-step guide to bringing your domain into compliance with Google's DMARC mandate.

1Audit Your Current Email Authentication

Before making any changes, you need to understand where you stand. Run a free scan with Vysiro to get an instant assessment of your domain's SPF, DKIM, DMARC, and overall email security posture. The scan will identify missing records, misconfigurations, and alignment issues in seconds.

Pay attention to whether you have existing SPF and DKIM records, whether they are correctly configured, and whether a DMARC record exists at all. Many domains have partial configurations that need to be completed rather than built from scratch.

2Set Up Your SPF Record

SPF tells receiving mail servers which IP addresses and services are authorized to send email from your domain. Create a TXT record at your domain's root with a value like:

v=spf1 include:_spf.google.com include:sendgrid.net ~all

Replace the include: entries with the services you actually use. Be sure to include every third-party service that sends email on your behalf: your ESP, CRM, helpdesk, invoicing software, and any other tools that send from your domain.

3Configure DKIM Signing

DKIM adds a cryptographic signature to your outgoing emails. Each email service provider has its own process for generating DKIM keys. Typically, you will generate a public/private key pair in your ESP's dashboard, then publish the public key as a DNS TXT record at a selector subdomain (e.g., google._domainkey.yourdomain.com).

Make sure you configure DKIM for every service that sends email from your domain, not just your primary mail provider. A common oversight is setting up DKIM for Google Workspace but forgetting about Mailchimp, Zendesk, or other third-party senders.

4Publish Your DMARC Record

Create a TXT record at _dmarc.yourdomain.com with a value like:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; ruf=mailto:dmarc@yourdomain.com; fo=1

This sets a monitoring-only policy that satisfies Google's mandate while sending you aggregate (rua) and forensic (ruf) reports. You can use our free DMARC record generator to create a correctly formatted record for your domain.

Start with p=none and monitor the reports for at least 2 to 4 weeks before tightening your policy. This lets you identify any legitimate email sources that might fail authentication before you start blocking anything.

5Monitor and Enforce

Once you have been at p=none for a few weeks and resolved any alignment issues revealed in your DMARC reports, progressively tighten your policy:

  • Move to p=quarantine; pct=10 to quarantine 10% of failing messages
  • Gradually increase pct to 25%, 50%, then 100%
  • Once stable at p=quarantine; pct=100, move to p=reject for full enforcement

This graduated approach protects you from accidentally blocking legitimate email while moving toward the strongest possible protection for your domain.

Common Pitfalls to Avoid

Even technically competent teams run into these issues when implementing email authentication. Here are the most common mistakes and how to avoid them.

SPF 10-Lookup Limit

SPF records are limited to 10 DNS lookups (RFC 7208). Each include:, a, mx, and redirect mechanism counts as one lookup. When you exceed 10, your entire SPF record fails, and all emails fail SPF authentication. Use SPF flattening to resolve nested includes into direct IP addresses and stay under the limit.

Missing DKIM for Third-Party Senders

Many domains set up DKIM for their primary email provider (Google Workspace, Microsoft 365) but forget about third-party services. If you use Mailchimp, SendGrid, HubSpot, Zendesk, or any other tool that sends email from your domain, each one needs its own DKIM configuration. Without it, those messages will fail DKIM checks and will not align with your DMARC policy.

DNS Propagation Delays

DNS changes do not take effect instantly. Depending on your DNS provider and the TTL (Time to Live) values of your records, changes can take anywhere from a few minutes to 48 hours to propagate globally. Do not make a DNS change and immediately test it. Wait at least 30 minutes, and use tools like our DNS propagation checker to verify that your records are visible across multiple DNS resolvers.

Jumping Straight to p=reject

One of the most dangerous mistakes is publishing a DMARC record with p=reject without first monitoring with p=none. If any legitimate email source is not properly authenticated (which is almost always the case initially), those emails will be silently rejected by receiving servers. Start with monitoring, fix alignment issues, then gradually enforce.

What Happens If You Don't Comply

Google's enforcement is not theoretical. It is already in effect and has measurable consequences for non-compliant senders:

  • Temporary delivery errors: Gmail returns 4xx temporary errors on a percentage of your email traffic, causing retries and delays.
  • Spam folder routing: Unauthenticated emails are increasingly routed to recipients' spam folders instead of their inbox, even if the content is legitimate.
  • Outright rejection: At full enforcement, non-compliant messages are rejected with 5xx permanent errors. The email never reaches the recipient.
  • Reputation damage: Repeated delivery failures damage your domain's sender reputation, making it harder to recover even after you fix your authentication. Rebuilding reputation can take weeks.
  • Revenue impact: For businesses that rely on email for sales, marketing, or customer communication, deliverability drops translate directly to lost revenue. Transactional emails like password resets and order confirmations not reaching customers creates support burden and erodes trust.

The cost of non-compliance is not just technical. It is a business risk that compounds over time. The longer you wait, the more damage accumulates and the harder it becomes to recover.

Frequently Asked Questions

Does Google require DMARC for all senders?

Google requires DMARC for bulk senders who send 5,000 or more messages per day to Gmail accounts. However, even senders below this threshold benefit from DMARC, and Google strongly recommends it for everyone.

What DMARC policy does Google require?

Google requires at minimum a DMARC record with p=none. This is the monitoring-only policy. While p=none satisfies the mandate, Google recommends progressing to p=quarantine and eventually p=reject for full protection.

What happens if I don't comply with Google's DMARC mandate?

Non-compliant bulk senders will experience temporary errors (4xx) on a percentage of their email traffic to Gmail. Over time, the rejection rate increases. Eventually, non-compliant messages may be outright rejected or routed to spam.

Does this apply to Google Workspace users too?

Yes. If your organization uses Google Workspace and sends bulk email (5,000+ messages per day to Gmail accounts), you still need to comply. Google Workspace does not automatically exempt you from the sender requirements.

Do I need both SPF and DKIM, or just one?

Google requires that bulk senders authenticate with either SPF or DKIM. However, both Google and industry best practice strongly recommend implementing both SPF and DKIM together, as this provides redundant authentication and is required for DMARC alignment.

How do I check if my domain is compliant?

You can use a free domain scanner like Vysiro to instantly check your SPF, DKIM, and DMARC records. The scan will show whether you meet Google's requirements and highlight any issues that need to be fixed.

Does Yahoo have the same requirements?

Yes. Yahoo announced identical requirements alongside Google in October 2023, also effective February 2024. The requirements for SPF/DKIM authentication, DMARC records, one-click unsubscribe, and low spam complaint rates are the same.

How long does it take to become compliant?

Publishing a basic DMARC record at p=none takes about 5 minutes. However, full compliance including SPF, DKIM, reverse DNS, and one-click unsubscribe can take a few hours to a few days depending on your email infrastructure and DNS provider.

Secure Your Domain Today

Scan your domain for free. Get a TrustScore across 30 security categories in under 60 seconds.

More in Industry News

1 article

Related Articles