Skip to main content
Email authentication protocols: What Gmail, Yahoo and Outlook.com require
Email Authentication

Email authentication protocols: What Gmail, Yahoo and Outlook.com require

SPF, DKIM, and DMARC are email authentication protocols. See what Gmail, Yahoo, and Outlook.com require, the bounce codes, and what to publish first.

Brain Lucas
Brain Lucas
Author

Three records count as email authentication: SPF, DKIM and DMARC. Gmail, Yahoo and Outlook.com each accept a DMARC policy of p=none as the minimum for bulk senders.

BIMI, ARC, MTA-STS and TLS RPT are not authentication, so leave them until the first three pass.

What each receiver requires

Google lists SPF, DKIM and a DMARC record with at least p=none for bulk senders of 5,000 or more messages a day.

Gmail has enforced the rule since November 2025, with temporary and permanent rejections.

Receiver

Authentication

DMARC minimum

Where the rule starts

Google

SPF and DKIM for bulk senders

A record with p=none

5,000 or more messages a day

Yahoo

SPF or DKIM for every sender, both for bulk

A valid policy of at least p=none, and DMARC must pass

No number stated

Outlook.com

SPF and DKIM both pass

A published record, with p=none as the example

5,000 or more messages to Microsoft consumer services from one From domain

Yahoo also requires bulk senders to keep the spam rate below 0.3%, and its page gives no volume number.

At Outlook.com, at least one of SPF or DKIM must also align with the From domain, and a message that fails returns 550 5.7.515.

What counts as authentication

SPF sits in a TXT record at the root of the sending domain. DKIM sits in a TXT record atselector._domainkey, and DMARC in one at _dmarc.

The three standards are RFC 7208 for SPF, RFC 6376 for DKIM, and RFC 9989 for DMARC.

What does not count

BIMI shows a logo next to authenticated mail, and Google's BIMI page requires p=quarantine or p=reject with pct=100.

RFC 9989 removes the pct tag, yet that page still lists it, so read the receiver's page before dropping a tag.

MTA STS (RFC 8461) and TLS RPT (RFC 8460) protect the connection between servers. ARC (RFC 8617) is Experimental and helps forward mail.

Who this page covers

This page covers mail sent from your own domain, whether you send under 5,000 messages a day, send at bulk volume, want BIMI, or run forwarders.

It leaves out SMTP login errors, email verification, and age checks, which are different problems.

The DKIM, SPF, and DMARC setup guide covers each record's syntax in more detail.

Before you start, gather three things:

  • DNS access to the sending domain

  • The name of every service that sends mail as that domain

  • A mailbox that can receive DMARC reports at the rua address

Build in this order: SPF, DKIM, then DMARC. A DMARC record can only pass when SPF or DKIM aligns with the From domain.

Stage 1: publish SPF

Steps:

  1. List every service that sends mail as your domain.

  2. Publish one TXT record at the root of the domain that names them.

  3. Keep the terms that cause DNS lookups at 10 or fewer.

Example record:

example.com.  TXT  "v=spf1 include:_spf.mailhost.example include:_spf.sender.example ip4:203.0.113.10 ~all"

Run dig TXT example.com to read the published record and count its terms.

In the example, two include terms add 2 lookups, while ip4 and all add none. RFC 7208 tells receivers to "limit the total number of those terms to 10" during evaluation.

Past 10 terms SPF returns permerror, and the RFC advises stopping at 2 void lookups.

Confirm: dig TXT returns exactly one record that starts with v=spf1.

Stage 2: publish DKIM

Steps:

  1. Create the key in the admin settings of the service that signs your mail.

  2. Choose a 1024 bit or 2048 bit key, which Google supports.

  3. Split a 2048 bit key into two quoted strings, because one TXT string stops at 255 characters.

  4. Publish the TXT record at selector._domainkey.example.com.

Example record:

selector1._domainkey.example.com.  TXT  "v=DKIM1; k=rsa; p=<first part of the key>" "<second part of the key>"

Google's DKIM page shows a 2048 bit key split into two quoted strings in the same TXT value.

Confirm: a test message shows dkim=pass in the Authentication-Results header.

Stage 3: publish DMARC

Steps:

  1. Publish a TXT record at _dmarc.example.com.

  2. Keep p=none unless you want BIMI. All three receivers accept it.

Example record:

_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:reports@example.com"

RFC 9989 replaced RFC 7489 in May 2026. It removes the pct, rf and ri tags and adds np, psd and t. A record that cannot be evaluated bounces as 554 5.7.5.

Confirm: dig TXT _dmarc.example.com returns one record that starts with v=DMARC1.

Confirm each record

Say a record has a TTL of 3,600 seconds. A resolver that cached the old answer can keep serving it for up to an hour, so retest after that hour.

Open a delivered test message in Gmail and choose Show original.

Three PASS results at the top show all three records work for that message.

  • Show original lists SPF, DKIM and DMARC as PASS

  • dig TXT Returns one SPF record with 10 or fewer lookup terms

  • The rua address accepts mail

Fix a failure by its code

Read the code in the bounce, then change the record named next to it.

Every other SMTP reply code is listed in the reference.

550 5.7.26 and 421 4.7.26

Google returns 421 4.7.26 when it rate limits unauthenticated mail. 550 5.7.26 has three triggers: an unauthenticated sender, an SPF hard fail and a DMARC policy rejection.

If SPF and DKIM both pass and the code still returns, check alignment, because Google needs one of them to match the From domain.

4.7.31

Google returns 4.7.31 when the sending domain has no DMARC record or the record sets no policy. Publish the Stage 3 record.

The temporary codes 4.7.27, 4.7.30 and 4.7.32 point to SPF, DKIM, and alignment, and 5.7.27 and 5.7.30 are the permanent forms.

550 5.7.515

Outlook.com returns it when a From domain sending 5,000 or more messages to Microsoft consumer services fails the authentication level.

Pass SPF and DKIM, publish a DMARC record, and align one of them with the From domain. The message blocked in the Gmail page covers the Gmail side of a block notice.

SPF permerror

Past 10 lookup terms SPF returns permerror. Remove includes for services that no longer send, then switch fixed servers to ip4 or ip6, which add no lookups.

Records to copy by sending volume

Sending volume

Records to publish

DMARC policy

Also needed

Under 5,000 a day

SPF, DKIM, DMARC

p=none

Spam rate below 0.3% at Yahoo

5,000 or more a day

SPF, DKIM, DMARC

p=none

Spam rate below 0.3% at Yahoo, with 0.1% as the preferred rate at Google

BIMI logo

SPF, DKIM, DMARC, BIMI

p=quarantine or p=reject, with pct=100

A VMC or CMC certificate

Where SPF, DKIM and DMARC come configured

TrueEmailer configures SPF, DKIM and DMARC together at setup for every domain it sends from. Stages 1 to 3 above are already in place on those domains.

It does not change the spam rate, the sending volume or the limits each receiver sets.

The Confirm checks above still apply to those domains, because a test message and dig TXT read the same records.

FAQ

Do I need all of SPF, DKIM and DMARC?

Yes for bulk senders at Google and Yahoo, and above 5,000 messages at Outlook.com.

Yahoo requires at least SPF or DKIM from every sender, so publish all three even at low volume.

Is DMARC p=none enough?

Yes at the three receivers in the table above. BIMI is the exception, because Google's page requires p=quarantine or p=reject.

Which record comes first?

SPF, then DKIM, then DMARC. A DMARC record can only pass when SPF or DKIM aligns with the From domain, per Microsoft's requirements.

Can a domain have two SPF records?

No. If a domain publishes more than one, RFC 7208 produces permerror. Merge them into one record.

Does authentication guarantee inbox placement?

No. Yahoo requires a spam rate below 0.3%, and Google rates 0.1% to 0.3% as already harmful to delivery.

Start with three TXT records

Publish SPF, DKIM and a p=none DMARC record, send a test message to Gmail and read the three results in Show original. Move to p=quarantine or p=reject only for BIMI.

When a bounce still carries one of the codes above, the code names the record to fix.

Requirements, error codes and record syntax verified 7 October 2026 against Google, Yahoo and Microsoft documentation and the RFC Editor.

About the author TrueEmailer Team writes the guides on this blog. Error strings, records and setup steps are checked against RFCs and Google and Microsoft documentation, with every source dated.