Microsoft Outlook's Bulk Sender Requirements, Read Closely
Microsoft requires domains that send more than 5,000 emails a day to Outlook.com, Hotmail.com and Live.com addresses to pass SPF, pass DKIM, and publish a DMARC policy of at least p=none aligned with one of them. Enforcement began on 5 May 2025. Failing mail is rejected with 550 5.7.515.
That is the summary everyone repeats. Reading Microsoft's own pages closely on 1 October 2026 turns up three things the summaries leave out: the rules cover consumer mailboxes only, Microsoft's pages disagree with each other about junk versus rejection, and there is no published spam-rate threshold at all.
What Microsoft actually announced
The source is a Microsoft Defender for Office 365 blog post, Strengthening Email Ecosystem: Outlook's New Requirements for High-Volume Senders, published 2 April 2025 and last updated 30 April 2025. Its first line sets the scope: "This applies to Outlook.com - our consumer service, which is supporting hotmail.com live.com and outlook.com consumer domain addresses."
For domains sending over 5,000 emails a day, the requirements are:
| Mechanism | Microsoft's wording |
|---|---|
| SPF | "Must Pass for the sending domain." |
| DKIM | "Must Pass to validate email integrity and authenticity." |
| DMARC | "At least p=none and align with either SPF or DKIM (preferably both)." |
Note the shape of that. SPF must pass and DKIM must pass, and DMARC alignment needs at least one of them to line up with the From domain. A setup where DKIM passes but SPF fails, which DMARC itself would accept, does not meet the stated SPF requirement.
The post then lists four "Additional Email Hygiene Recommendations". They are recommendations, not requirements, but Microsoft says it "reserves the right to take negative action, including filtering or blocking" against non-compliant senders:
- Compliant P2 (primary) sender addresses: the From or Reply-To address should be valid, reflect the true sending domain, and be able to receive replies.
- Functional unsubscribe links, particularly for marketing or bulk mail.
- List hygiene and bounce management: "Remove invalid addresses regularly."
- Transparent mailing practices: accurate subject lines, no deceptive headers, and recipients who consented.
Junk or reject? Microsoft's pages disagree
This is the part worth knowing before you plan around it.
The original announcement said non-compliant mail would first go to Junk and might later be rejected. On 29 April 2025 Microsoft added an update to the same post saying it had "made a decision to reject messages that don't pass the required authentication requirements," with the rejection text:
550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.
and that this would take effect on 5 May "as originally stated."
But the post still contains, a few lines below, the original paragraph: after 5 May 2025, Outlook "will begin routing messages from high volume non-compliant domains to the Junk folder," with rejection "in the future (date to be announced)." And the Outlook.com Postmaster site homepage, as we read it on 1 October 2026, says non-compliant messages "will be sent to the junk folder" and "Shortly we will reject the messages until the DNS records are corrected."
So Microsoft's two official pages give different answers. The safe reading is the stricter one: plan as though failing mail is rejected outright. A rejection is at least visible. You get a bounce with 5.7.515 and the name of the failing domain. Junk placement shows up only as falling engagement.
Who is in scope, and who isn't
| You send to... | Covered by these requirements? |
|---|---|
| @outlook.com, @hotmail.com, @live.com addresses | Yes, if your domain sends 5,000+ a day |
| Business domains hosted on Microsoft 365 | Not according to the announcement, which scopes it to the consumer service |
| Fewer than 5,000 a day | Not enforced, though Microsoft's FAQ says "all senders benefit" |
Microsoft's support article for the 5.7.515 error pins down what is counted: 5,000 or more messages to Microsoft consumer email services where "All of the messages use the same domain in the 5322.From address". It also adds MSN to the list of affected services, and repeats that "Both SPF and DKIM checks must pass." Two details are still not stated, and we would rather say so than guess:
- Subdomains. Unlike Google, Microsoft doesn't say whether
news.example.comandexample.comare counted together. If you split traffic across subdomains, assume they might be. - The time window. "Per day" is not defined as a calendar day or a rolling 24 hours.
Below the threshold you are not exempt from filtering, only from this particular enforcement. Outlook.com's ordinary spam filtering applies to everyone.
How Microsoft compares with Gmail and Yahoo
| Outlook.com | Gmail | Yahoo | |
|---|---|---|---|
| Threshold | 5,000+/day per domain | ~5,000+/day to personal Gmail, per primary domain | Not specified |
| SPF | Must pass | Required | Required |
| DKIM | Must pass | Required | Required |
| DMARC | p=none minimum, aligned | p=none minimum, aligned | p=none minimum, must pass |
| One-click unsubscribe (RFC 8058) | Not required; "functional unsubscribe" recommended | Required for marketing mail | Required for marketing mail |
| Published spam-rate limit | None | Below 0.3% (target 0.1%) | Below 0.3% |
| Failure response | 550 5.7.515 (or Junk) | 4.7.x / 5.7.x codes, spam foldering | Spam folder or rejection |
| Safe Senders override | "Won't be honored" | Not addressed | Not addressed |
The Gmail and Yahoo side of this table is explained in Gmail and Yahoo bulk sender requirements. If you already meet those, you meet Microsoft's stated requirements, with one check: make sure SPF passes on its own, not only DKIM.
Fixing a 5.7.515 rejection
The domain in the bounce text is the one Microsoft evaluated. Work through it in order:
- Look at a message that reached an Outlook.com mailbox (send one to a test account) and read the
Authentication-Resultsheader. You wantspf=pass,dkim=passanddmarc=pass. Microsoft's post links to its own guide on reading these headers. - If SPF fails, find the envelope sender (
Return-Path) domain. It is often your sending platform's bounce domain rather than yours. Make sure that domain's SPF record authorises the sending IP and stays within 10 DNS lookups. Microsoft's FAQ warns about this specifically: "If you exceed 10 DNS lookups, your SPF check might fail." Our SPF checker counts them, and this guide explains how to get back under. - If DKIM fails or signs with the wrong domain, set up DKIM for your own domain in the sending platform. A signature from the platform's domain passes DKIM but does not align with your From address. Check yours with the DKIM checker.
- If DMARC is missing, publish one.
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.commeets the minimum. Microsoft says it sends aggregate (rua) reports and has no plans to send forensic (ruf) reports. - Resend a test and confirm the headers before resuming volume.
Microsoft's FAQ also recommends ARC for anyone forwarding mail or running mailing lists, because forwarding can break DMARC alignment, and it supports separate DKIM selectors per mail system so each stream can be managed on its own.
The tools Microsoft gives senders
Microsoft has no Postmaster Tools equivalent with a compliance dashboard. What it offers through the Outlook.com Postmaster site is:
- SNDS (Smart Network Data Services): traffic and complaint data for IP ranges you can prove you own. Because it is IP-based, it is most useful with dedicated IPs and of little use on shared ESP infrastructure.
- JMRP (Junk Mail Reporting Program): a copy of each message an Outlook.com user marks as junk, forwarded to an address you choose.
- Sender support: a form for delivery problems. Include the exact SMTP response you received.
If your problem is placement in Junk rather than rejection, that is a different diagnosis, covered in why emails land in Outlook's junk folder.
A note for cold emailers on Microsoft 365
These requirements are about mail arriving at Outlook.com. If you send from Microsoft 365 mailboxes, a separate set of limits applies, published in Microsoft's Exchange Online limits documentation: 10,000 recipients per user per day, 30 messages per minute, and a tenant-wide external recipient limit (TERRL) that depends on licence count, capped at 5,000 external recipients a day for trial tenants. Mail from the default onmicrosoft.com domain is limited to 100 external recipients per organisation per day. Microsoft's own advice for legitimate bulk commercial email is to use a provider that specialises in it.
The practical takeaway
Treat Microsoft's requirements as Gmail's authentication rules with no tolerance for a failing SPF check, and plan for outright rejection rather than Junk, whatever the older paragraphs say. Make sure SPF and DKIM both pass for your own domain, publish DMARC, and keep an Outlook.com test inbox you can send to whenever you change anything in your sending setup. Bounce management is on Microsoft's list too, so verify any list you did not build yourself before it goes out. Our free deliverability audit checks the DNS side in one pass.
Common questions
What are Microsoft's requirements for high-volume senders?
Domains sending more than 5,000 emails a day to Outlook.com, Hotmail.com and Live.com addresses must pass SPF, pass DKIM, and publish a DMARC policy of at least p=none that aligns with SPF or DKIM. Microsoft announced this on 2 April 2025, with enforcement from 5 May 2025.
What does 550 5.7.515 mean?
It is the rejection Microsoft attaches to mail from high-volume domains that fail its authentication requirements. The full text in Microsoft's announcement is '550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.' Fix SPF, DKIM and DMARC for the domain named in the message.
Do Microsoft's sender requirements apply to Microsoft 365 business mailboxes?
Microsoft's announcement says it applies to Outlook.com, its consumer service covering hotmail.com, live.com and outlook.com addresses. It does not describe these rules as applying to mail sent to Microsoft 365 business tenants, which have their own filtering.
Does adding a sender to Safe Senders bypass the requirement?
No. Microsoft's FAQ on the announcement answers this directly: 'Safe Sender list won't be honored.' Recipients cannot whitelist their way around a failing domain.
Verify unlimited addresses for $29.99/month
Real SMTP mailbox checks. No credits, no per-email fees.
Get Started