+33 1 75 43 77 01info@ediware.netFree account: 1,000 emails per month FrançaisFR
Talk to an expert

HomeDeliverability & technicalGmail/Yahoo rules

New Gmail/Yahoo rules 2024-2025: what B2B senders must know

In brief: since February 2024, Google and Yahoo have required SPF, DKIM, DMARC, one-click unsubscribe and a spam complaint rate capped at 0.3% from any sender of more than 5,000 emails a day. Microsoft aligned its Outlook rules on 5 May 2025. And since November 2025, strict enforcement has hardened with 4xx and 5xx SMTP rejections. Compliance is no longer up for debate, it gets put in place.

Illustration: New Gmail/Yahoo rules 2024-2025: what B2B senders must know

The days when you could send an email campaign from a poorly configured domain and hope to land in the inbox are over. The joint announcements by Google and Yahoo in October 2023 marked a turning point. Microsoft followed suit a year later. And the period of tolerance that followed February 2024 closed in autumn 2025.

For French B2B emailing managers, the stakes are concrete. Your campaigns to Gmail, Yahoo, Outlook, Hotmail and Live contacts no longer get through if your DNS records are not in order. And the reality of the B2B market is that almost all of your targets use one of these mailbox providers, either directly or via Google Workspace or Microsoft 365. Here is what you need to understand, step by step, to stay in the race.

Where these new Gmail and Yahoo requirements come from

The announcement was made on 3 October 2023 by Neil Kumaran at Google and Marcel Becker at Yahoo, a few hours apart. Both providers announced the same rules, applicable from 1 February 2024 to any sender exceeding 5,000 emails a day to their respective accounts. The coordination was no accident. The M3AAWG, the international reference body in the fight against email abuse, had endorsed the approach by publishing a text that has remained famous in the industry: “In 2024, ‘No Auth, No Entry’ will be the rule for bulk senders.” No authentication, no entry. The phrase did the rounds of deliverability conferences for months.

The motivation is above all security. Email fraud, targeted phishing, BEC attacks that impersonate an executive to divert a bank transfer: all of this had been exploding for several years. Without systematic authentication, anyone could write a message pretending to be you. Your customers were exposed. So were your prospects. And your domain’s reputation could collapse overnight because of a fraudulent send you had never issued.

In terms of volume, the pressure on filters had become untenable. Gmail processes around 300 billion messages every month according to Google. With 75% to 90% of that traffic potentially unsolicited, the only viable response was to require cryptographic authentication from every serious sending source. Bulk senders, those who send in volume, are the primary target.

The three requirements imposed above 5,000 emails a day

The new rules rest on three pillars. No surprise for anyone who has practised deliverability for a long time, but this time enforcement is final.

SPF, DKIM and DMARC authentication

Any sender exceeding 5,000 emails a day to Gmail, Yahoo and now Outlook must have published the three authentication records in its DNS: SPF to declare authorised servers, DKIM to cryptographically sign each message, and DMARC to define the policy applied when one of the two checks fails. The set-up details are described in our complete guide to configuring SPF, DKIM, DMARC, which covers the DNS syntax, classic pitfalls such as the 10-lookup SPF limit, and the gradual ramp-up of the DMARC policy.

The minimum Google and Yahoo requirement is a DMARC policy at p=none. You are not obliged to go as far as rejection, but you must at least publish the record and agree to receive aggregate reports.

One-click unsubscribe

Second requirement: an unsubscribe link must be able to be activated in a single click, without the recipient going through a web page that asks them to enter their address or confirm their choice. Technically, this means adding the List-Unsubscribe and List-Unsubscribe-Post: List-Unsubscribe=One-Click header pair to the message, in accordance with RFC 8058. And the unsubscribe must be processed within two days.

Spam complaint rate below the threshold

Third pillar, and probably the trickiest to master: the spam complaint rate in Google’s Postmaster Tools must never exceed 0.3%. Beyond that, your messages are rejected or systematically classified as spam. And the official recommendation is to stay below 0.1%, which corresponds to 1 complaint per 1,000 messages delivered. That is strict.

The 0.3% spam complaint threshold: what it changes in concrete terms

Many B2B senders discover this threshold at the worst possible moment, when their inbox placement rate collapses for no apparent reason. The content has not changed, the list is qualified, the subject lines are sober. And yet opens plummet. The cause is almost always the same: chronically exceeding the 0.1% threshold, which eventually triggers aggressive filtering.

To measure this rate, only one tool counts: Google Postmaster Tools. There you will see your complaint rate broken down by day, compared with the volume sent, over 7, 30 or 90 days. For Yahoo, monitoring goes through their Sender Hub. And for Outlook, Microsoft’s SNDS provides the equivalent, with granularity by IP rather than by domain.

What drives up a complaint rate in B2B is rarely the content itself. It is poorly maintained lists. A list bought in bulk, imported without cleaning, will generate hundreds of complaints from the very first send. A prospecting file that has not been segmented by activity, by job title or by stage in the sales cycle will wear out its recipients within a few campaigns. And vague opt-in, such as a pre-ticked box in a download form, exposes you to immediate complaints because the person has no memory of ever having given you their consent.

When the figures climb, the most effective response is to remove deeply inactive contacts, slow down the sending cadence, and restart the warm-up from a more modest volume. A properly sized platform, such as Ediware with its dedicated IPs and Power-MTA engine, lets you isolate your sends and measure precisely the impact of each adjustment, which is almost impossible on a shared service where your statistics are diluted among those of hundreds of other senders.

Enforcement timeline: from soft enforcement to the November 2025 crackdown

Entry into force happened in stages. Understanding the timeline helps you anticipate what is coming, and in particular what has already changed since last autumn.

Period Google/Yahoo behaviour Consequence for the sender
Before February 2024 Recommendation, no enforcement No automatic blocking
February 2024 Soft enforcement Non-compliant emails redirected to spam
April to October 2025 Gradual tightening Stricter filtering, degraded scoring
November 2025 Hard enforcement SMTP rejections 4xx (temporary) and 5xx (permanent)

The November 2025 turning point deserves a closer look. Until then, a non-compliant send ended up at best in the spam folder. The recipient could retrieve it if they thought to look. Since November, Google’s SMTP server simply rejects the message outright. You receive a 550 or 421 code in your logs, and the recipient never sees anything. The boundary between filtered and rejected has disappeared, and senders who had not yet migrated their configuration found themselves with exploding bounce rates overnight.

Proofpoint documented the phenomenon in several alerts sent to its customers at the end of 2025. The message is always the same: the period of tolerance is over, and the sanctions are no longer gradual.

Microsoft joins the dance in May 2025

On 5 May 2025, Microsoft aligned Outlook, Hotmail and Live with the Google and Yahoo requirements. The trigger threshold is identical, 5,000 emails a day, and the three pillars are taken over unchanged: SPF + DKIM + DMARC, one-click unsubscribe, controlled complaint rate. The industry greeted the event with a neologism that sums up the situation nicely: Yahooglesoft. Three players, a single set of rules.

For French B2B prospecting, Microsoft is far from anecdotal. A significant share of SMEs and mid-sized companies use Microsoft 365 and therefore professional Outlook mailboxes. If your configuration worked correctly towards Gmail but not towards Outlook, until spring 2025 you could still get through. Since the gradual enforcement of Microsoft’s rules, non-compliance also blocks this major share of the market.

What it changes for B2B senders in France

AFNIC publishes an annual review of email authentication on the .fr zone. The 2025 figures speak for themselves: SPF is present on 69% of active domains, DKIM on 40.7%, and DMARC on only 19.5%. In other words, barely one domain in five has a published DMARC policy. The progress is clear compared with 2024, but the majority of the French economic fabric remains exposed. And among the 19.5% of domains with DMARC, the overwhelming majority remain at p=none, that is to say in observation mode with no real protection.

For a serious B2B sender, this means two things. First, your prospects who have published a DMARC at p=reject will reject any fraudulent email sent under your identity. That is good news for the overall security of the market. Second, mailbox providers now use DMARC compliance as a strong quality signal in their reputation scoring. A domain without DMARC, even a legitimate one, starts with a handicap.

The classic mistake is to think the subject only concerns very large senders. That is wrong for two reasons. On the one hand, the 5,000-a-day threshold is calculated per mailbox provider, not on your total volume. If your campaigns target 30,000 contacts, 6,000 of them on Gmail, you are concerned. On the other hand, even below the threshold, Gmail has applied enhanced scoring to all senders since 2025. No SPF/DKIM/DMARC in order, no priority inbox placement.

The blind spot of shared platforms: shared IP reputation

Here is the point that sponsored comparisons and the guides of the big shared platforms generally pass over in silence. When your campaigns are sent from an IP shared with hundreds of other customers, the reputation that Gmail, Yahoo and Outlook servers assign to that IP depends on the behaviour of the whole pool. Not just yours.

In concrete terms, if one of your pool neighbours sends a poorly targeted campaign that triggers a spike in complaints, your inbox placement suffers the same day. You have done nothing wrong, you are not warned, and your ongoing campaigns bear the consequences of a decision that is not yours. In the context of the November 2025 crackdown, where filters react faster and harder, this risk has taken on another dimension.

This is precisely what dedicated IPs solve. Your reputation becomes strictly your own, measurable, isolated, controllable. At Ediware, dedicated IPs are included from the PRO plan, at no extra cost and with no option to activate. The Power-MTA engine handles warm-up, cadence regulation per recipient and rotation between several IPs in the pool when your volume justifies it. The dedicated tracking domain also prevents all your clicked links from pointing to a subdomain shared with other senders, which strengthens the consistency of your authentication signal.

To fully understand how these infrastructure choices translate into concrete security for your data and your brand image, the page dedicated to data security and GDPR compliance at Ediware details all the measures in place: hosting in France, continuous IP monitoring, SPF/DKIM/DMARC already configured on the tracking domain.

Compliance checklist for a B2B sender

If you are new to the subject or if your last check dates from before 2024, here is the procedure to follow, in order. Allow two to four weeks to complete it properly, the time needed for records to propagate and reports to be analysed.

  1. List every sending source for your domain: emailing platform, CRM, helpdesk, email signatures, invoicing tool, prospecting platform. There is always at least one you forget.
  2. Publish a single SPF record that includes each of these sources, while staying strictly below the limit of 10 DNS lookups.
  3. Enable DKIM at each sending service, with 2048-bit RSA keys. Most platforms provide the records to copy and paste into the DNS.
  4. Publish a DMARC record at p=none with a rua address that collects aggregate reports. Read these reports for two to four weeks to identify forgotten sources.
  5. Ramp up the DMARC policy: move to p=quarantine with pct=25, then 50, then 100, then switch to p=reject once all flows are aligned.
  6. Check that your campaigns include List-Unsubscribe-Post in RFC 8058 format. Any professional emailing platform does this by default. If yours does not, it is a clear signal of its technical backwardness.
  7. Monitor your complaint rate in Postmaster Tools, Yahoo Sender Hub and Microsoft SNDS. Set yourself an internal alert threshold at 0.1%, not 0.3%.
  8. Document your configuration in a document shared between IT, marketing and support. When a new email service arrives in the company, the reflex must be to update SPF immediately.

This discipline is not negotiable if you want to maintain decent inbox placement over time. And at Ediware, with the figures to back it up, accounts that follow this progression towards p=reject generally see their open rates climb back in the weeks following stabilisation.

FAQ — New Gmail, Yahoo and Outlook rules

Do the Gmail rules apply to B2B emails?

Yes, without exception. Google’s requirements make no distinction between B2B and B2C. All that counts is the volume sent to Gmail accounts, whether personal (@gmail.com) or professional accounts hosted on Google Workspace. And the majority of French companies use Workspace for their professional email. Your @company.fr prospects therefore almost all go through Gmail’s filters, and your sends are subject to the same authentication rules.

How do you configure DMARC for a business domain?

DMARC is configured via a TXT-type DNS record placed on _dmarc.yourdomain.fr. The minimum recommended syntax is v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.fr;. This observation-mode policy lets you collect the daily XML reports sent by Gmail, Yahoo and Outlook, without blocking any sends. Once the reports have been analysed and all your sending sources identified, you gradually move up to p=quarantine then p=reject. The full technical detail is covered in our SPF, DKIM, DMARC guide.

What if you send fewer than 5,000 emails a day?

The threshold of 5,000 messages a day to Gmail triggers the strictest requirements, but the reality is more nuanced. Since 2025, Google has applied enhanced scoring to all senders, including those below the threshold. A domain without SPF, without DKIM or without DMARC starts with a reputation handicap, regardless of volume. For a serious B2B sender, treating these three protocols as mandatory from the very first send is the only viable approach.

How do you measure your spam complaint rate?

Three free tools are enough. For Gmail, Google Postmaster Tools gives the complaint rate per domain, per day, over 7, 30 or 90 days. For Yahoo, the Yahoo Sender Hub provides the equivalent with slightly less granularity. For Outlook, Microsoft offers SNDS, which measures by IP rather than by domain, particularly useful if you operate on a dedicated IP. Sign up to all three and check your figures once a week. Above 0.1% complaints, act without waiting for the 0.3% threshold.

Shared IP or dedicated IP: what difference does it make under the new rules?

On a shared IP, your reputation with Gmail depends on the behaviour of all the senders sharing the same infrastructure. A pool neighbour who sends a bad campaign degrades your placement the same day, without you being able to intervene. On a dedicated IP, your reputation is strictly your own, which has become decisive since the November 2025 crackdown. Not all platforms offer a dedicated IP by default. At Ediware, it is included from the entry-level plan, which makes a real difference in terms of deliverability control.

Does Microsoft Outlook apply the same rules?

Since 5 May 2025, yes. Microsoft announced the alignment of its Outlook.com, Hotmail.com and Live.com servers with the same requirements as Google and Yahoo: SPF, DKIM, DMARC, one-click unsubscribe, complaint control, triggered at 5,000 messages a day. The strict enforcement phase is gradual, with classification as spam first, then outright rejections. If your prospects make heavy use of Outlook or Microsoft 365, your compliance must cover these three axes simultaneously.

What does the November 2025 crackdown phase change?

Before November 2025, a non-compliant email ended up at best in spam. The recipient could always retrieve it manually. Since November, Gmail’s servers reject non-compliant messages at SMTP level, with 4xx (temporary rejection, retry possible) or 5xx (permanent rejection) return codes. The recipient never sees the message, and your platform records a bounce. For a sender whose configuration was not up to date, the transition translated into a brutal explosion in the bounce rate and a collapse in inbox placement rates.