Email Marketing & AutomationDeliverability · Lesson 4 of 16

Google, Yahoo and Microsoft sender rules, one-click unsubscribe and BIMI

Article · 16 min · 8 min lecture

Video lecture

The bulk-sender rules: one-click unsubscribe, spam rates and BIMI

11 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 11

Bulk-sender rules

  • Who counts as bulk
  • Gmail, Yahoo, Microsoft requirements
  • One-click unsubscribe
  • Spam-rate thresholds
  • BIMI logos

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

The rules changed – and are now enforced

Since February 2024, Gmail and Yahoo have required bulk senders to meet stricter standards, and Gmail stepped up enforcement from November 2025 with temporary and permanent rejections of non-compliant traffic. Microsoft introduced similar rules for high-volume senders to Outlook.com, Hotmail and Live addresses, rejecting non-compliant mail from 5 May 2025. If you send marketing email at any scale, treat these as the minimum standard.

Who counts as a bulk sender?

  • Gmail: a sender that has sent close to 5,000 or more messages in a day to personal Gmail accounts. Google says that once you reach this level, you are treated as a bulk sender permanently.
  • Microsoft: domains sending over 5,000 emails a day to Outlook.com consumer addresses.
  • Yahoo: applies similar bulk-sender standards; its requirements page does not rely on a single public threshold for all rules.

Small senders should follow the same practices anyway – they are what good deliverability looks like.

The requirements side by side (as of September 2026 – check each provider's page)

RequirementGmail (bulk)Yahoo (bulk)Microsoft (high-volume)
SPF and DKIMRequiredRequiredRequired
DMARC policy (at least p=none)Required, with From-domain alignment (SPF or DKIM)RequiredRequired, aligned with SPF or DKIM
One-click unsubscribe (RFC 8058) for marketingRequired, plus a visible unsubscribe linkRequiredRecommended: clear, easy unsubscribe
Honour unsubscribesWithin 48 hoursWithin 2 daysPromptly
Spam complaint rateKeep below 0.1%; never reach 0.3%Keep below 0.3%Keep lists clean
OtherValid forward and reverse DNS, TLS, RFC 5322-compliant messagesValid DNS and standards complianceValid From/Reply-To, list hygiene

Microsoft rejects non-compliant messages with an error along the lines of 550 5.7.515 Access denied, sending domain ... does not meet the required authentication level. Gmail's user-reported spam rate is visible in Google Postmaster Tools; if it exceeds 0.3%, Google says you lose eligibility for its mitigation help until you have stayed below 0.3% for seven consecutive days.

One-click unsubscribe: what it actually is

"One-click unsubscribe" means mailbox providers can show their own Unsubscribe button next to your sender name, and a single click unsubscribes the person without visiting a page. It works through two email headers defined in RFC 8058:

List-Unsubscribe: <https://example.com/u/abc123>, <mailto:unsubscribe@example.com?subject=unsubscribe>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
  • The HTTPS URL must accept a POST request and unsubscribe the recipient immediately – no login, no confirmation page.
  • Both headers must be covered by your DKIM signature.
  • Keep a visible unsubscribe link in the email body too.

Most reputable email platforms add these headers automatically when you use their unsubscribe feature. If you send from your own system, implement them yourself. A minimal handler (Python/Flask, illustrative):

from flask import Flask, request, abort

app = Flask(__name__)

@app.post("/u/<token>")
def one_click_unsubscribe(token):
    # Body will be "List-Unsubscribe=One-Click" for RFC 8058 requests
    subscriber = lookup_subscriber_by_token(token)   # your data layer
    if subscriber is None:
        abort(404)
    suppress_everywhere(subscriber.id, reason="one_click")  # email + synced tools
    return "", 200

BIMI: your logo in the inbox

BIMI (Brand Indicators for Message Identification) lets supporting mailbox providers show your verified logo next to your emails. It rewards strong authentication and helps recognition.

Requirements:

  1. DMARC at enforcement: p=quarantine or p=reject, applied to 100% of mail (no reduced pct).
  2. A logo in SVG Tiny Portable/Secure (SVG Tiny PS) format, square, hosted over HTTPS.
  3. A mark certificate from an authorised certificate authority: - VMC (Verified Mark Certificate): requires a registered trademark; enables logo display and, in Gmail, a blue verified checkmark; also used by Apple Mail. - CMC (Common Mark Certificate): no trademark needed, but the logo must have been in use for at least 12 months; Gmail supports it for logo display (without the checkmark).
  4. A BIMI DNS record:
default._bimi.example.com.  TXT  "v=BIMI1; l=https://example.com/brand/logo.svg; a=https://example.com/brand/vmc.pem"

Support differs by mailbox provider and changes over time – check current support before promising a logo in every inbox. Certificates are paid, annual products; budget for them like any brand-protection cost.

Worked example: a UK retailer's compliance sprint

Illustrative. A Manchester fashion retailer sends 40,000 emails a week. Google Postmaster Tools shows a spam rate around 0.25% and some rejections after enforcement tightens. The sprint: (1) confirm SPF, DKIM and aligned DMARC for its email platform and for its transactional provider; (2) switch on the platform's one-click unsubscribe and remove the "log in to manage preferences" requirement; (3) suppress subscribers with no clicks or orders in 12 months after a re-engagement series; (4) reduce frequency for low-engagement segments. Within weeks, spam rate drops below 0.1%, rejections stop, and the retailer moves DMARC to p=reject and applies for a VMC for BIMI.

Worked example 2: a Dubai B2B newsletter under the threshold

A Dubai consultancy sends 1,500 newsletters a month – far below bulk thresholds. It still sets up SPF, DKIM, DMARC and one-click unsubscribe because the same filters judge all senders, and because clients' corporate mail systems increasingly check DMARC. Its newsletter now lands reliably in partners' inboxes.

Common mistakes

  • Unsubscribe links that require a login or several steps.
  • DKIM not covering the List-Unsubscribe headers when self-hosting.
  • Processing unsubscribes weekly in a batch.
  • Assuming "we're under 5,000" means the rules do not matter.
  • Starting BIMI with DMARC at p=none.

How to measure success

  • Google Postmaster Tools: spam rate consistently below 0.1%, authentication passing, compliance status healthy.
  • Yahoo Sender Hub and Microsoft SNDS data reviewed monthly.
  • Unsubscribes processed within 48 hours (ideally instantly) across all tools.
  • BIMI logo showing in supported inboxes after DMARC reaches enforcement.

Key takeaways

  • Gmail and Yahoo (since 2024) and Microsoft (since May 2025) require bulk senders to use SPF, DKIM and aligned DMARC; Gmail tightened enforcement in November 2025.
  • One-click unsubscribe uses RFC 8058 List-Unsubscribe and List-Unsubscribe-Post headers; process unsubscribes within 48 hours.
  • Keep Gmail's user-reported spam rate below 0.1% and never reach 0.3%; monitor Postmaster Tools, Yahoo Sender Hub and Microsoft SNDS.
  • BIMI needs DMARC at quarantine or reject, an SVG Tiny PS logo, a VMC or CMC and a BIMI DNS record.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Which pair of headers implements one-click unsubscribe under RFC 8058?
  2. What spam complaint rate does Google advise bulk senders to stay below?
  3. Which DMARC policy is required before BIMI will work?

Put it into practice

Check one of your marketing emails in Gmail's 'Show original': confirm SPF, DKIM and DMARC pass and that List-Unsubscribe and List-Unsubscribe-Post headers are present. List any gaps and the fix.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.