The requirements Gmail and Yahoo now enforce

The large mailbox providers spent years publishing best practice and then started enforcing it. The requirements are not new ideas, but the consequence changed: mail that fails them is rejected or filtered rather than quietly scored down.

4 min read

Three requirements checked before mail is accepted
Published as guidance for years, enforced as requirements now.

The good news for anyone running an email agent is that a conversational sender passes almost all of it by construction.

The three that matter

Authentication, properly. SPF and DKIM, plus a DMARC record on the sending domain, with alignment to the From address. The floor is that DMARC exists at all, even at p=none, and the sensible position is enforcement, per SPF, DKIM, and DMARC for an agent subdomain.

One-click unsubscribe on bulk mail. A List-Unsubscribe header supporting one-click, honoured within a couple of days. MCPmailer attaches a signed one-click link to sends classified as cold, and using it suppresses the address for your workspace immediately, so later sends are refused before they leave.

A complaint rate under the ceiling. Roughly a tenth of a percent as the target and a third of a percent as the line where enforcement starts, measured per provider. That is one complaint in a thousand messages, which sounds generous and is not, if your mail is unwanted.

Alongside those, the ordinary hygiene: valid reverse DNS, TLS in transit, and a From address that can receive mail. All standard with a competent provider, and the last one is a choice you make rather than a technical detail.

Why conversational mail passes

Look at what the requirements are aimed at. They target senders pushing large volumes of unrequested mail to lists they did not earn, and the ceiling on complaints is what catches them.

An agent answering people who wrote first sits at the opposite end of every one of those axes: the recipient started the conversation, the mail is expected, and complaints are close to structurally impossible because nobody reports a reply they asked for. Combine that with authentication done once on a dedicated subdomain, and the requirements stop being a project.

Where agent deployments get into trouble is the same place everyone else does, which is outbound to people who did not ask, per keeping an autonomous agent from becoming a spam problem.

RequirementConversational agentOutbound campaign
SPF, DKIM, DMARC alignedOne-time setupOne-time setup
One-click unsubscribeAttached to cold sendsRequired, and must work
Complaint rate under the ceilingNear zero by natureThe number to watch
Recipient asked for the mailYes, by definitionThe whole question

The complaint ceiling is per provider, and lagging

Two properties worth internalising.

It is measured per provider, so a rate that looks fine in your aggregate can be over the line at one of them. Watch it split, per knowing where your agent's mail actually lands.

And it lags. By the time a complaint rate is visible in postmaster tools, the mail that caused it went out days ago, and recovery takes longer than the damage did. That asymmetry is the argument for the alerting in what to monitor in production: a rising complaint rate is one of the few things worth waking someone up for.

Complaint rate crossing a ceiling at one provider while the average stays flat
Per provider, and visible only after the mail that caused it has gone.

The volume threshold is a red herring

The published requirements apply above a daily volume threshold, and it is tempting to conclude that a smaller sender can ignore them. Two reasons not to.

The requirements describe what the filters already reward, so meeting them below the threshold improves placement rather than merely avoiding enforcement. And thresholds move downward over time, in the direction of applying to everyone, which makes building to them now cheaper than retrofitting later.

Treat them as the baseline for any domain that sends at all, including the parked ones, per when someone sends email pretending to be you.

A short conformance check

  1. SPF, DKIM, and DMARC published and aligned on a real delivered message, not just in DNS.
  2. DMARC policy moving toward enforcement rather than parked at none.
  3. One-click unsubscribe on anything cold, honoured by suppression rather than by an agent remembering.
  4. Complaint rate watched per provider, with an alert rather than a monthly review.
  5. Hard bounces near zero, which means addresses that came from real conversations.
  6. A From address that receives mail and is read.

Six items, most of them one-time. The ongoing work is the two numbers.

Questions

What do Gmail and Yahoo require from senders?
Authenticated mail with SPF, DKIM, and an aligned DMARC record, one-click unsubscribe on bulk messages honoured promptly, and a complaint rate kept under roughly a tenth of a percent.
Do these apply to a small sender?
The published thresholds target higher volumes, but the requirements describe what filters already reward, and thresholds trend downward. Building to them is cheaper than retrofitting.
Does agent email meet them automatically?
Conversational mail largely does: the recipient wrote first, so complaints are near zero. Authentication still has to be set up once, and outbound is where the requirements bite.
What is the complaint rate ceiling?
Around a tenth of a percent as a target, with enforcement around a third, measured per provider rather than in aggregate.
Why does the per-provider split matter?
Because one provider can be over the line while your average looks healthy, and the average is the number most dashboards show you.
How fast does a complaint problem show up?
Slowly, which is the problem. It is visible after the mail that caused it has already gone, and recovery takes longer than the damage did.

Give your agent an address it can answer from.

Create an inbox