All posts

Email Deliverability Checklist: 25 Checks Before You Send

··8 min read

Before a send, check six areas: authentication (SPF, DKIM, DMARC and alignment), sending infrastructure (reverse DNS, TLS, blocklists), the list itself (verified, bounces suppressed, no bought data), content basics, compliance (unsubscribe, address, honest headers) and monitoring (complaint rate and test sends). The 25 checks below cover all six, each with a way to verify it.

Each check is marked with whose rule it is, because that changes how much it matters. A Google, Yahoo or Microsoft requirement can get your mail rejected; a best practice mostly affects where it lands. Sources are the providers' own pages, fetched on 1 October 2026: Google's sender guidelines, Yahoo's sender best practices and Microsoft's Outlook high-volume sender announcement.

Replace example.com, the selector and the IP below with your own. For a fuller explanation of the provider rules, see Gmail and Yahoo bulk sender requirements.

Who requires what, at a glance

Google, Yahoo and Microsoft now agree on the core of what bulk senders must do; they differ on detail. This table summarises the hard requirements for senders above 5,000 messages a day, as each provider words them.

Requirement Google (Gmail) Yahoo Microsoft (Outlook.com)
SPF Required (with DKIM) Required (with DKIM) Must pass
DKIM Required, key at least 1024 bits Required Must pass
DMARC Required, p=none allowed Required, at least p=none, must pass At least p=none
Alignment From: aligned with SPF or DKIM From: aligned with SPF or DKIM Aligned with SPF or DKIM, preferably both
Reverse DNS Valid forward and reverse DNS Valid forward and reverse DNS Not listed
One-click unsubscribe Required for marketing and subscribed mail Required for marketing and subscribed mail Functional unsubscribe link recommended
Spam rate Below 0.3% (aim below 0.10%) Below 0.3% Not stated as a number
Unsubscribe deadline Not stated as a number on the page we read Within 2 days Not stated

Microsoft's scope is its consumer service (hotmail.com, live.com and outlook.com addresses). Its announcement says that from 5 May 2025 non-compliant high-volume mail is rejected with: 550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.

Authentication (checks 1-6)

Authentication proves the mail is really from your domain, and it is the one area where all three big providers set hard rules. Do these first.

1. One SPF record exists and lists every service that sends for you. Required by Google, Yahoo, Microsoft. Check: dig +short TXT example.com | grep spf1. You want exactly one line starting v=spf1. Two SPF records is an error, not a backup.

2. SPF stays within 10 DNS lookups. Required by the SPF standard. RFC 7208 says implementations "MUST limit the total number of those terms to 10". Every include:, a, mx and redirect counts, including nested ones. If you are close, read fixing too many DNS lookups.

3. DKIM is signing, with a key of at least 1024 bits. Required by Google, Yahoo, Microsoft. Check: find the selector in the s= tag of the DKIM-Signature header of a sent message, then dig +short TXT selector._domainkey.example.com. Google requires 1024 bits or longer for personal Gmail and recommends 2048.

4. A DMARC record is published. Required by Google, Yahoo, Microsoft for bulk senders. Check: dig +short TXT _dmarc.example.com. v=DMARC1; p=none is the minimum all three accept.

5. Your From: domain aligns with SPF or DKIM. Required by Google, Yahoo, Microsoft for bulk senders. Passing SPF on your email platform's domain is not enough; the From: domain has to match. Check: send a test message and look for dmarc=pass in the Authentication-Results header. See how to read email headers.

6. DMARC reports go to a mailbox someone reads. Best practice (Google recommends it). Check: the DMARC record contains rua=mailto:... at an address that exists. Reports are how you find a forgotten service sending as you.

Infrastructure (checks 7-10)

Infrastructure checks confirm the servers sending your mail are identifiable and trusted. If you use a major email platform it handles most of these, but they are still yours to confirm.

7. Sending IPs have matching forward and reverse DNS. Required by Google and Yahoo. Check: dig +short -x 203.0.113.10 returns a hostname; dig +short A on that hostname returns the same IP. Yahoo asks for "valid, meaningful, non-generic" PTR records.

8. Mail is sent over TLS. Required by Google. Check: in the received message's Received: headers, the hop into Gmail or Outlook should say with ESMTPS, where the S indicates TLS.

9. Marketing and transactional mail are separated. Best practice (Yahoo states it). Yahoo: "Don't send bulk/marketing email from the same IPs you use to send user mail, transactional mail, alerts, etc." A subdomain or separate stream per type keeps a bad campaign from delaying password resets.

10. Your IP and domain are not on a major blocklist. Best practice; a listing often causes rejections. Check: run your domain and sending IP through a blocklist and deliverability audit. If you are listed, fix the cause before requesting removal.

The list (checks 11-16)

List quality decides your bounce rate and your spam trap exposure, and it is the area most within your control before sending. Microsoft's guidance names it directly: "Remove invalid addresses regularly to reduce spam complaints, bounces, and wasted messages."

11. Every address was verified before its first send, and again if the list has sat unused. Best practice (Microsoft recommends list hygiene). Check: run the list through a verifier and remove invalid results. A single-address check is enough to spot-check a list you are unsure of.

12. No purchased, rented or scraped data is in the send. Best practice; Microsoft asks that recipients "have consented to receive your messages". Check: every segment has a known source. Unknown source means do not send.

13. Hard bounces are suppressed automatically. Best practice (Google recommends it). Google: "Automatically unsubscribe recipients who have multiple bounced messages." Check: your platform's suppression list grows after each send.

14. Catch-all and risky addresses are sent separately. Best practice. Catch-all domains accept every address, so nothing can be confirmed. Send them in smaller batches after your confirmed addresses, and watch bounces.

15. Role and disposable addresses are reviewed, not just mailed. Best practice. info@, admin@, abuse@ and throwaway domains carry more complaint and trap risk. Decide deliberately whether each belongs on the list.

16. Long-inactive contacts are suppressed or re-confirmed. Best practice (Google suggests it). Google: "Consider unsubscribing recipients who don't open or read your messages." A written sunset rule stops dormant addresses ageing into recycled spam traps.

Content (checks 17-19)

Content checks here are the ones with a written rule behind them, not spam-word folklore. Keep the message honest and well formed.

17. The From: header holds one real address that can receive replies. Google formatting guidance; Microsoft recommendation. Google says From: "should include only one email address". Microsoft asks that the From or Reply-To address "is valid, reflects the true sending domain, and can receive replies". Check: reply to your own test message.

18. The message is correctly formatted. Required by Google (RFC 5322) and Yahoo (RFC 5321 and 5322). Check: send through a reputable platform rather than a hand-rolled script, and if you write HTML, validate it. Include a plain-text part.

19. Subject line and headers are accurate. US law (CAN-SPAM) and Microsoft recommendation. The FTC's guide: "The subject line must accurately reflect the content of the message", and From, To, Reply-To and routing information "must be accurate".

Compliance (checks 20-22)

These checks cover unsubscribe mechanics and the legal basics. This is not legal advice; the rules depend on where you and your recipients are, so read the regulator's own text for your case.

20. One-click unsubscribe headers are present on marketing mail. Required by Google and Yahoo for bulk senders. Check the raw source of a test message for both:

List-Unsubscribe: <https://example.com/unsubscribe/abc123>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

The POST endpoint must actually unsubscribe the recipient without a login. Details in one-click unsubscribe (RFC 8058).

21. A visible unsubscribe link is in the body, and requests are honoured fast. Required by Google and Yahoo; CAN-SPAM in the US. Yahoo says "Honor unsubscribes within 2 days". The FTC's CAN-SPAM guide sets an outer limit of 10 business days and requires the opt-out to keep working "for at least 30 days after you send your message". Check: unsubscribe from your own test and confirm you are suppressed.

22. Your physical postal address is in the message. CAN-SPAM in the US. The FTC's compliance guide: "Your message must include your valid physical postal address." A registered PO box qualifies.

Monitoring (checks 23-25)

Monitoring tells you whether the other 22 checks are working once real mail flows. Set these up before the send so you have a baseline.

23. Google Postmaster Tools is set up and your spam rate is low. Required by Google and Yahoo (0.3% ceiling). Google's guidance is to stay "below 0.10% and avoid ever reaching a spam rate of 0.30% or higher". Check: verify your domain in Postmaster Tools and read the spam rate after each send.

24. Complaint feedback from Yahoo and Microsoft is connected. Best practice (Yahoo points bulk senders to its feedback loop). Yahoo's Complaint Feedback Loop tells you who marked you as spam; Microsoft's Smart Network Data Services (SNDS) shows data for your sending IPs. Check: complaints flow back into your suppression list.

25. A test send to Gmail and Outlook passes all three checks. Best practice. Check: send to accounts you own at both, open the original source, and confirm spf=pass, dkim=pass and dmarc=pass in Authentication-Results, plus where it landed (inbox or junk). DNS can look right while the live message still fails, which is why this is last.

The order to work through them

If you cannot do all 25 before a send, do them in this order:

  1. Checks 1-5 (authentication). These are hard requirements, and failing them gets mail rejected rather than filtered.
  2. Checks 11-13 (verify, no bought data, suppress bounces). The commonest cause of bounce problems, fixable in an afternoon.
  3. Checks 20-21 (unsubscribe). Required for bulk senders, and the easiest way to keep complaints down.
  4. Check 25 (test send). Confirms the first three groups actually work on a real message.
  5. Everything else as routine: monitoring, separation of streams, content hygiene.

Treat the list as a pre-flight routine rather than a one-off project. Authentication rarely breaks once it works, but lists decay and new sending tools get added, so checks 1, 11 and 25 are worth repeating before every significant campaign.

Common questions

What is the minimum I need before sending bulk email to Gmail, Yahoo and Outlook?

If you send more than about 5,000 messages a day to any of them, you need SPF and DKIM passing, a DMARC record of at least p=none with alignment, valid forward and reverse DNS, and one-click unsubscribe on marketing mail. Google and Yahoo also set a spam complaint ceiling of 0.3%, and Microsoft says it rejects non-compliant high-volume mail with error 550 5.7.515.

Which checks matter most if I only have an hour?

Authentication and the list. Check that SPF, DKIM and DMARC pass on a real test message, and verify the list so you are not mailing dead addresses. Those two cover the hard requirements of the big mailbox providers and the most common cause of high bounce rates.

Do these rules apply if I send fewer than 5,000 emails a day?

Some do. Google and Yahoo require SPF or DKIM, valid reverse DNS and a spam rate under 0.3% from all senders, regardless of volume. The DMARC and one-click unsubscribe requirements are written for bulk senders, but meeting them at lower volume costs little and avoids surprises as you grow.

How do I check whether my email passed SPF, DKIM and DMARC?

Send a message to a Gmail or Outlook account you control, open the original message source and find the Authentication-Results header. It lists spf=, dkim= and dmarc= results with pass or fail for that specific message, which is more reliable than checking DNS records alone.

Verify unlimited addresses for $29.99/month

Real SMTP mailbox checks. No credits, no per-email fees.

Get Started