Email Deliverability News: Latest Updates and Changes

Stay up to date with the latest email deliverability news. Provider policy changes, authentication requirements, and industry developments that affect your inbox placement.

Email deliverability rules change constantly. Gmail tightens enforcement, Microsoft adds new requirements, Yahoo updates thresholds — and if you miss an update, your emails start bouncing.

This page tracks the changes that matter. Updated regularly with provider policy changes, authentication requirement updates, and industry developments that affect whether your emails reach the inbox.

Bookmark this page. When something breaks, check here first.

Don't wait for the news to find you

Monitor your SPF, DKIM, DMARC, and blacklist status automatically. Get alerts when something changes.


March 2026

Authentication is now table stakes everywhere

As of early 2026, SPF, DKIM, and DMARC are no longer optional for any sender at meaningful volume. Google, Yahoo, and Microsoft all enforce authentication requirements. The era of sending unauthenticated email to major providers is over.

If your domain doesn't have all three protocols configured and aligned, you're already losing mail. Use our free deliverability checker to test your setup.


May 2025

Microsoft enters the enforcement game

May 5, 2025 — Microsoft began enforcing bulk sender requirements for Outlook.com, Hotmail.com, and Live.com. Senders sending 5,000+ emails per day must now have:

  • SPF configured with accurate authorized IP addresses
  • DKIM signatures validating email integrity
  • DMARC published at minimum p=none, aligned with SPF or DKIM

Non-compliant messages go to Junk first. If left unaddressed, Microsoft will block them outright with error code 550 5.7.515.

This matters because Microsoft had been the last major provider without formal bulk sender enforcement. With Google, Yahoo, and now Microsoft all requiring authentication, there's nowhere left to hide.

What to do: Check your SPF, test your DKIM, and verify your DMARC. If you're sending to corporate Outlook/365 addresses, be aware that enterprise filtering (Mimecast, Proofpoint, Barracuda) may apply additional rules beyond Microsoft's baseline.


Late 2024 — Early 2025

Gmail ramps up enforcement to rejections

November 2024 onwards — Google escalated enforcement of its bulk sender requirements from warnings to active rejections. Messages from non-compliant senders that previously landed in spam now bounce with permanent failures.

Key thresholds Google enforces:

  • Spam complaint rate must stay below 0.3% (Google recommends below 0.1%)
  • SPF, DKIM, and DMARC all required for 5,000+ daily senders
  • One-click unsubscribe required in marketing emails
  • TLS encryption expected for message transmission

If your bounce rates spiked in late 2024, Gmail enforcement is the likely cause. Check your DMARC alignment and ensure all sending services are properly authenticated.

Yahoo mirrors Google's requirements

Yahoo and AOL aligned their sender requirements with Google's, requiring the same SPF, DKIM, DMARC authentication and spam rate thresholds. The 0.3% complaint rate ceiling applies across both providers.


September 2024

Apple Mail Privacy Protection continues to reshape metrics

Apple Mail Privacy Protection (MPP), active since iOS 15, now affects the majority of Apple Mail users — over 95% adoption. With Apple Mail representing roughly half of all email opens globally, open rates are fundamentally unreliable as a deliverability metric.

What this means in practice:

  • Open-based automations (re-engagement sequences, A/B tests on subject lines) produce misleading data
  • Click-through rates and conversions are now the reliable engagement signals
  • Sunset policies based on "last opened" dates will incorrectly suppress active subscribers on Apple devices

This isn't new, but many senders still haven't adapted their measurement. If you're still using open rates as your primary deliverability indicator, it's time to shift to clicks.

iOS 18 introduces AI-powered inbox changes

Apple's iOS 18 brought AI-generated email previews, new inbox categorization, branded sender icons, and digest-style views to Apple Mail. These changes affect how recipients interact with email — categorized inboxes mean your marketing emails compete for attention differently than before.


February 2024

Google and Yahoo announce bulk sender requirements

February 1, 2024 — Google and Yahoo's bulk sender requirements took effect, marking the biggest shift in email authentication enforcement in years. For the first time, major inbox providers formally required DMARC for high-volume senders.

The initial enforcement was soft — warnings and spam folder placement rather than outright rejection. This gave senders a runway to comply. That runway closed through 2024 and into 2025 as enforcement escalated.

The requirements that changed everything:

  • SPF authentication required
  • DKIM signing required
  • DMARC policy at minimum p=none
  • One-click unsubscribe for marketing email
  • Spam complaint rate under 0.3%

If you're still running p=none and haven't planned your progression to p=quarantine or p=reject, see our guide on DMARC policy progression.


What to watch in 2026

  • DMARC enforcement tightening — Expect providers to start penalizing p=none policies, pushing senders toward p=quarantine or p=reject
  • BIMI adoption growing — More inbox providers supporting brand logos via BIMI records, making VMC certificates more valuable
  • ARC (Authenticated Received Chain) — Becoming more important as email forwarding and mailing list scenarios need authentication preservation
  • MTA-STS adoption — More organizations requiring encrypted email transport, preventing downgrade attacks

This page is updated regularly. Last updated March 1, 2026.