Google, Yahoo, and Microsoft all now require bulk senders to authenticate their email, and the enforcement recently got much less forgiving. This is worth ten minutes of your attention if email matters to your revenue.
What changed: Google moved to permanent rejections in November 2025. Microsoft started routing non-compliant mail to junk in August 2025, then began permanently rejecting it that November. Yahoo has been enforcing since early 2024. Before this, non-compliant mail was often just delayed or filtered. Now it bounces and stays bounced. The threshold is 5,000 messages a day from your domain.
What is required: – SPF, which declares which servers are allowed to send mail using your domain. – DKIM, which cryptographically signs your messages so receivers can confirm they came from you unaltered. – DMARC, which tells receiving servers what to do when the first two fail, and reports back on who is attempting to send mail as you. – A spam complaint rate under 0.3 percent. – One-click unsubscribe headers on marketing mail, honored within 48 hours. A footer link alone no longer satisfies this.
Why this catches companies off guard? Plenty of businesses sit well under 5,000 a day normally, then run a campaign, a billing cycle, or a customer notification blast and cross the line without noticing. That is usually the send you least want bouncing. Worse, bounced mail often does not surface cleanly to the person who sent it, so the first symptom is a customer saying they never got your invoice.
The security angle: DMARC is also the control that stops someone sending email that appears to come from your CEO or your controller. If you have ever worried about the fake wire transfer request, this is a real part of the defense, not just a deliverability task. Free check, no strings. These records are public DNS entries, so anyone can look them up.
Comment or message us your domain and we will tell you whether your SPF, DKIM, and DMARC are configured correctly and what is missing. No form, no call required. If you want to hand the findings to your current IT provider, that is a perfectly good outcome.
If you would rather see the whole picture, our free IT risk assessment covers this along with backups, endpoint security, and licensing: https://glacistech.com/it-risk-assessment/?utm_source=reddit&utm_medium=brand_page&utm_campaign=company_page&utm_content=email_auth
GlacisTech, managed IT and cybersecurity in Richardson, TX.
Source: r/u/glacistech · by /u/glacistech