Skip to content
DnsLister Forum

Where domain hunters compare notes

Before your giving season appeals go out, check that your email can actually be delivered

This one is less about security and more about whether your fundraising

emails reach anyone, though it turns out the fix does both.

Google, Yahoo, and Microsoft all now require bulk senders to authenticate

their email. The threshold is 5,000 messages a day from your domain. If

you cross it without proper setup, your mail gets rejected, and the

enforcement got much harder recently. Google moved to permanent rejections

in November 2025, and Microsoft did the same after routing non-compliant

mail to junk starting that August. Yahoo has been enforcing since early

2024.

Here is why this matters even if you think you are too small. Most of us

send well under 5,000 a day on a normal Tuesday. Then a year-end appeal or

a giving day blast goes out to the full list, and you sail past it without

realizing. That is exactly the send you cannot afford to have bounce.

The three things required are:

– SPF, which lists the servers allowed to send email using your domain

name.

– DKIM, which adds a signature proving the message really came from you

and was not altered along the way.

– DMARC, which tells receiving mail servers what to do when the first two

fail, and sends you reports on who is trying to send mail as you.

There are two other requirements worth knowing. Your spam complaint rate

needs to stay under 0.3 percent, and marketing emails need a one-click

unsubscribe header, not just a link in the footer, with requests honored

within 48 hours.

The security payoff nobody mentions: DMARC is also what stops someone

sending email that appears to come from your executive director. If you

have worried about the fake payment request scam, this is a real part of

the defense, not just a deliverability chore.

What to do this week? Ask whoever manages your email or your domain

whether SPF, DKIM, and DMARC are configured. If you use a platform like

Mailchimp or Constant Contact for appeals, check their domain

authentication setup too, since sending through them does not

automatically cover your domain.

Give this a few weeks before your big sends. DMARC in particular is worth

rolling out gradually, in monitoring mode first, so you can see what

breaks before it starts rejecting your own legitimate mail.

Source: r/DFWNonprofitSecurity · by /u/glacistech

Leave a Reply

Your email address will not be published. Required fields are marked *