This one is less about security and more about whether your fundraising
emails reach anyone, though it turns out the fix does both.
Google, Yahoo, and Microsoft all now require bulk senders to authenticate
their email. The threshold is 5,000 messages a day from your domain. If
you cross it without proper setup, your mail gets rejected, and the
enforcement got much harder recently. Google moved to permanent rejections
in November 2025, and Microsoft did the same after routing non-compliant
mail to junk starting that August. Yahoo has been enforcing since early
2024.
Here is why this matters even if you think you are too small. Most of us
send well under 5,000 a day on a normal Tuesday. Then a year-end appeal or
a giving day blast goes out to the full list, and you sail past it without
realizing. That is exactly the send you cannot afford to have bounce.
The three things required are:
– SPF, which lists the servers allowed to send email using your domain
name.
– DKIM, which adds a signature proving the message really came from you
and was not altered along the way.
– DMARC, which tells receiving mail servers what to do when the first two
fail, and sends you reports on who is trying to send mail as you.
There are two other requirements worth knowing. Your spam complaint rate
needs to stay under 0.3 percent, and marketing emails need a one-click
unsubscribe header, not just a link in the footer, with requests honored
within 48 hours.
The security payoff nobody mentions: DMARC is also what stops someone
sending email that appears to come from your executive director. If you
have worried about the fake payment request scam, this is a real part of
the defense, not just a deliverability chore.
What to do this week? Ask whoever manages your email or your domain
whether SPF, DKIM, and DMARC are configured. If you use a platform like
Mailchimp or Constant Contact for appeals, check their domain
authentication setup too, since sending through them does not
automatically cover your domain.
Give this a few weeks before your big sends. DMARC in particular is worth
rolling out gradually, in monitoring mode first, so you can see what
breaks before it starts rejecting your own legitimate mail.
Source: r/DFWNonprofitSecurity · by /u/glacistech