Cold email deliverability used to be a spam folder problem. Now it is a rejection problem. The big consumer mailbox providers spent 2024 and 2025 tightening what they will accept, and mail that fails their checks does not get filed in junk anymore, it gets refused at the door. Your sequencing tool still logs it as sent. Here is what Gmail, Yahoo and Outlook actually require, what to fix first, and why a technically perfect setup can still get filtered.
The short version:
- Gmail, Yahoo and Outlook all require SPF, DKIM and DMARC from anyone sending real volume to their users.
- Microsoft began refusing non-compliant bulk mail on 5 May 2025 with a hard error rather than a junk folder placement.
- Google's guidance is to keep reported spam complaints under 0.30 percent and to aim below 0.10 percent.
- One-click unsubscribe headers are a requirement for bulk mail, not a courtesy.
- Authentication only gets you accepted. Reputation decides whether anyone reads you.
What is cold email deliverability, and what changed?
Deliverability is the share of your mail that reaches a human being instead of being blocked or filtered. There are two separate gates. The first is acceptance: will the receiving server take the message at all. The second is placement: inbox or spam.
For years outbound teams treated this as a copywriting problem. Avoid trigger words, keep it short, do not use three exclamation marks. That advice was never wrong, but it only touches the second gate. The first gate is where sales email dies now.
In February 2024 Google and Yahoo published matching sender requirements. In April 2025 Microsoft announced its own version for Outlook.com, Hotmail.com and Live.com, effective 5 May 2025. All three landed in roughly the same place: authenticate properly, make unsubscribing easy, keep complaints low.
The word that matters is reject. Microsoft's announcement was explicit that non-compliant high volume mail would be refused with a 550 error. A rejected message never reaches a folder at all. Nobody sees it, and nobody can dig it back out later.
What do Gmail, Yahoo and Outlook require now?
Three things, and above the volume line none of them are optional.
Authentication that passes and aligns
SPF lists which servers may send for your domain. DKIM signs each message so the receiver can prove nothing was altered on the way. DMARC ties those two results back to the domain your reader actually sees in the From line, and tells the receiver what to do when a check fails.
Alignment is the piece most teams miss. You can pass SPF cleanly and still fail DMARC, because the domain that passed was your sending platform's domain rather than yours. Gmail and Microsoft both expect bulk senders to publish a DMARC record, and a policy of p=none is an acceptable place to start.
One-click unsubscribe
Bulk senders have to include the List-Unsubscribe and List-Unsubscribe-Post headers so the mailbox provider can render its own opt-out button at the top of the message. Yahoo's guidance says opt-out requests need to be honored within two days. A link buried in your footer does not satisfy this by itself.
A complaint rate you can defend
Google's sender guidelines set the ceiling at 0.30 percent reported spam and tell senders to stay below 0.10 percent. Three complaints per thousand delivered messages sounds generous until you send to a list somebody bought.
The 5,000 a day threshold is worth understanding properly. It counts messages to one provider's consumer addresses, and Google counts by the domain in your From line rather than by individual mailbox. Ten reps on the same domain sending 600 each are one 6,000 message sender, not ten small ones.
How do you set up SPF, DKIM and DMARC without breaking your real mail?
Order matters here, and the risk is to your ordinary business email rather than your outreach.
- Inventory everything that sends as your domain. Mailbox provider, CRM, invoicing tool, helpdesk, payroll, e-signature. Anything you forget starts failing the moment you tighten policy.
- Publish exactly one SPF record. Two SPF records is a permanent fail, and it is the most common mistake we see on a domain that used to work.
- Turn on DKIM signing everywhere it is offered, with a different selector per service.
- Publish DMARC at p=none with a reporting address and then actually read the reports for two to four weeks. You are hunting for legitimate mail that fails.
- Move to p=quarantine, then p=reject once the reports come back clean.
Step four is the one people skip, and skipping it is why DMARC rollouts take down invoice notifications on a Friday afternoon.
Why does clean authentication still land in the spam folder?
Because authentication answers the question "is this really you," and placement answers a different one: "does anyone want mail from you." Passing the first tells the provider nothing about the second.
Once you are accepted, the provider scores behaviour. Replies, messages dragged out of spam, mail that gets opened on real accounts instead of deleted unread. Cold outreach starts with none of that history, which is exactly why it is held to a stricter standard than your newsletter.
The things that hurt you at this gate:
- Dead addresses. Every hard bounce says you did not check your list before sending.
- Shared tracking domains. A redirect domain used by thousands of other senders carries whatever the worst of them did last week.
- Identical copy at volume. Providers cluster near-duplicate messages and score them together.
- Dumping the whole list at once from a domain with no history.
That last one is why our own bulk email and SMS sending runs at a deliberately steady rate instead of firing everything in one burst. It is the same reasoning behind pacing a dialer rather than blasting a list, and the same failure mode as sales texts that never deliver: the software reports success while the carrier or the mailbox provider quietly refuses the traffic.
How long does warming a new sending domain take?
There is no published number from any provider here, so treat what follows as practitioner convention rather than a rule you can point at. Deliverability specialists generally start a fresh domain at five to ten messages a day, raise volume over four to six weeks, and then hold a mature mailbox somewhere in the range of thirty to fifty sends a day.
The logic behind those numbers is simple enough. A new domain has no reputation, and reputation gets built by people replying to you. Volume without replies builds the wrong kind.
Two practical notes:
- Send cold outreach from a separate domain that still reads as yours. Something like getacme.com next to acme.com. If outreach damages the reputation, contracts and password resets on your main domain keep working.
- Do not spread the same volume across twenty mailboxes and call it warmed up. Providers score the domain.
What should a sales team fix this week?
In this order:
- Check whether your outreach domain publishes SPF, DKIM and DMARC today. A free lookup tool answers this in about ten seconds.
- Find and remove the second SPF record.
- Turn on one-click unsubscribe headers in whatever sends your bulk mail.
- Clean the list. Drop role addresses like info@ and anything that has already bounced.
- Cut per-mailbox volume until replies come back.
- Only then go argue about subject lines.
Most teams work that list from the bottom up, rewriting copy for a month while the mail is being refused before a filter ever reads it. The fix is boring and it takes an afternoon.
None of this makes email the whole plan. It works best as the rail around a conversation, which is why how fast you respond to a new lead still beats how many messages you send, and why the follow-up sequences worth automating are the ones that get somebody on the phone. Email is the cheapest channel you have and the easiest one to break without noticing. Worth the afternoon.
If you would rather have the dialer, the CRM, the texting and the email in one place at one published price, that is what we built.
See it on your own calls.
SellifyGPT puts the dialer, CRM, and an AI coach in one place. 14-day free trial, cancel before it ends.
Start free