Who requires DMARC now? Google, Yahoo, Outlook and beyond
For its first twelve years, DMARC was a best practice — recommended everywhere, required almost nowhere outside government. That ended in February 2024, when Google and Yahoo made it a condition of delivery for bulk senders. Microsoft followed in 2025. Mail that doesn't meet the bar now lands in spam or bounces outright.
This page maps who requires what as of July 2026: the mailbox-provider requirements and their volume thresholds, the government and compliance mandates around them, what enforcement actually looks like in practice — and the catch: every one of these requirements stops at p=none, which satisfies the letter of the rule while stopping no spoofed mail at all.
Google and Yahoo: the requirements that started the era
Announced on the same day — October 3, 2023 — and in force since February 1, 2024 (Google's sender guidelines, Yahoo's sender best practices).
Every sender, any volume, must have at Gmail: SPF or DKIM on the sending domain, valid forward and reverse DNS (a PTR record) on the sending IP, TLS in transit, and a user-reported spam rate in Postmaster Tools below 0.3% — Google's own guidance is to stay under 0.1% and "avoid ever reaching" 0.3%.
Bulk senders must additionally have: SPF and DKIM, a DMARC policy on the From: domain — p=none is explicitly sufficient — From: alignment with the SPF or DKIM domain, and one-click unsubscribe on commercial mail.
Two details of Google's bulk-sender definition are widely missed (Google's FAQ):
- The threshold is about 5,000 messages in 24 hours to personal Gmail accounts, counted across all mail from the same primary domain — subdomains don't reset the counter.
- Crossing it once is permanent: "senders who meet the above criteria at least once are permanently considered bulk senders." There is no path back to the lighter rules.
Yahoo's requirements are the same shape — SPF and DKIM, DMARC at p=none minimum with alignment, one-click unsubscribe honored within two days — but Yahoo deliberately publishes no numeric threshold. Its product director's phrasing: "The number is not 5,000, or 6,000, or 4,000… If you're sending the same email to a lot of people, you're a bulk sender."
Microsoft Outlook: the same bar since May 2025
Microsoft announced matching requirements on April 2, 2025 for domains sending 5,000+ messages a day to its consumer services (Outlook.com, Hotmail, Live, MSN): SPF pass, DKIM pass, and DMARC at p=none minimum, aligned with SPF or DKIM — preferably both (Microsoft's announcement).
Enforcement is genuinely muddled — Microsoft edited its own timeline more than once. The live announcement says non-compliant mail is routed to Junk, with outright rejection at a "date to be announced." At the same time, Microsoft maintains a support page for the rejection code, and bounces are observed in the wild. The honest summary: non-compliant high-volume mail to Outlook is junked or rejected, and you should not plan around which. If you're seeing the bounce, we cover it step by step in 550 5.7.515: what Microsoft's bounce means.
Apple's quiet postmaster rules
Apple never announced anything, and there is no volume threshold or enforcement date. But its postmaster page for iCloud Mail states that bulk mail must meet all listed requirements "or the email will be rejected" — and the list includes SPF, DKIM, and a published DMARC policy on the sending domain, plus ARC headers on forwarded mail. Call it postmaster rules rather than a mandate; the practical effect for a bulk sender is the same: authenticate or gamble.
The floor is still p=none — the penalty keeps rising
As of July 2026, no mailbox provider requires more than p=none. What has escalated is what happens when you fail the bar. Google's FAQ, since November 2025: "Gmail is ramping up its enforcement on non-compliant traffic. Messages that fail to meet the email sender requirements will experience disruptions, including temporary and permanent rejections." The era of "it just goes to spam a bit more" is over — non-compliance is now bounces.
That escalation pattern — requirements frozen, enforcement tightening — is worth reading correctly. The providers picked p=none as the floor because it's the safe entry point: it collects data without risking anyone's legitimate mail. Nothing about the trajectory suggests the floor stays there forever.
Mandates beyond the mailbox providers
- US federal agencies have been required to run DMARC at
p=rejectsince October 2018 under DHS Binding Operational Directive 18-01 — which, notably, also required an aggregate-report (rua=) recipient from day one: the directive's authors understood you can't enforce what you don't watch. - The UK required DMARC for government services back in October 2016, and current NCSC guidance is to reach
p=reject. - The Netherlands has had DMARC on its comply-or-explain standards list for government organizations since 2018; Denmark and New Zealand require
p=rejectfor government domains per industry mandate trackers. - PCI DSS 4.x made automated anti-phishing controls mandatory for organizations handling card data from March 31, 2025. The standard names DMARC, SPF and DKIM as example controls rather than mandating them by name — "PCI DSS effectively pushes DMARC" is accurate; "PCI DSS requires DMARC" is not.
- NIS2 — despite what some compliance marketing claims — does not name DMARC at all.
Where adoption actually stands (mid-2026)
Adoption numbers in this space come with different denominators, so here they are separately:
- Among the top 1.8 million domains by traffic, 52.1% now publish a valid DMARC record — up from 29.1% in 2023, the before/after of the requirements era (EasyDMARC's 2026 adoption report). But roughly 56% of those sit at
p=none, and only 8.9% combinep=rejectwith aggregate-report monitoring — fully enforced and watched. - Across all ~73 million apex domains, adoption is far thinner — about 13% at the end of 2024 (Red Sift), though 2.32 million domains added DMARC in the ten months after the February 2024 deadline alone.
- By sector: the Fortune 500 is at 95% adoption with over 80% at enforcement; the top 100 global banks are the strongest-enforcing sector studied; higher education is the weakest — under 8% of US
.edudomains reachp=reject(dmarcian's sector studies).
And the receiver-side proof that the requirements work: Google reported Gmail received 265 billion fewer unauthenticated messages in 2024 than in 2023 — a 65% drop from one year of enforcement.
What this means for your domain
If you send anywhere near 5,000 messages a day to Gmail or Outlook addresses, SPF, DKIM, and a DMARC record are table stakes — non-compliant mail is junked or bounced, and at Gmail the bulk-sender status is permanent once earned. If you're under the threshold, the any-volume rules (SPF or DKIM, PTR, spam-rate ceiling) still apply to you today, and the volume rules describe where the ecosystem is headed.
But notice what the requirements got everyone to do: publish p=none. That's the monitoring policy — it delivers every spoofed message while sending you reports about it. The requirements era moved half the internet to the starting line; the protection is in walking the ladder from p=none to quarantine to reject, which is an evidence problem — you enforce when your report data shows every legitimate sender aligned, and not before. That path is covered in What is DMARC? and Why monitor DMARC reports?
Checking where you stand takes ten seconds: paste your record into the DMARC record checker to have it parsed tag by tag, or scan your domain below for the full SPF, DKIM, DMARC and DNS picture at once. If you'd rather verify it yourself from a terminal:
dig +short txt _dmarc.yourdomain.com
No answer means no DMARC record — you don't meet the bulk-sender bar at any provider. An answer starting v=DMARC1; p=none means you meet today's requirements but block nothing.
Check SPF, DMARC, DKIM, MX, DNS and expiry in one free scan — with the exact record to paste in to fix each problem.