Gmail · Yahoo · Microsoft bulk sender rules, 2026

Your Campaign Isn’t Being Deferred Any More. It’s Being Rejected.

Gmail moved from soft 4xx deferrals to permanent 5xx rejections in November 2025. Microsoft has been rejecting non-compliant bulk mail since 5 May 2025, and a recipient adding you to their Safe Sender list does not override it. The rules are all published; what nobody has is a straight answer to “is our sending domain actually ready?” This is that answer, per domain, in writing, before you press send.

Buy Now — $19

One-time payment · works offline · nothing leaves your browser

14 checks
authentication · one-click unsubscribe
list hygiene · transport & monitoring
Per domain
own score, own evidence, own hand-off
marketing, transactional and bounce hosts
$19
once, for the auditor and every re-audit
no seats, no subscription, no account

The dashboard that used to warn you is gone

On 30 September 2025 Google retired the High / Medium / Low / Bad reputation grades that marketing teams had watched for years. They were replaced by a pass/fail Compliance Status view in Postmaster Tools v2 — and a Compliance Status change can take up to seven days to appear. The gentle early-warning signal is not there any more, and the thing that replaced it reports after the fact.

  • Gmail, November 2025 — enforcement moved from soft 4xx deferrals to permanent 5xx rejections. A refused message is not retried and queued; it is refused.
  • Microsoft Outlook, 5 May 2025 — rejection of non-compliant bulk mail began, and it cannot be overridden by a Safe Sender entry at the recipient’s end.
  • 5,000 a day to personal inboxes — the threshold at which the full bulk sender requirements apply, crossable on a single large send.
Permanent rejection, not a retry

Requirements and enforcement dates change. This is a checklist and recordkeeping aid, not deliverability advice — verify current requirements with each mailbox provider’s own documentation before a launch.

It audits your domains. It does not touch your DNS.

Nothing connects to anything. You record what you verified, where the evidence lives, and who has to fix what — and you get a readiness record a marketing team can hold, defend and hand to IT without a meeting.

1

Fourteen checks that reflect the actual rules

SPF under ten DNS lookups. DKIM alignment with the visible From: domain, not just a passing signature. The literal List-Unsubscribe-Post: List-Unsubscribe=One-Click header. HTTPS POST, not GET or a redirect. Both unsubscribe headers inside the DKIM signature. The specifics that decide it, not a generic “set up SPF” line.

2

A blocker is a blocker, whatever the percentage says

Any failure in authentication or one-click unsubscribe raises a CAMPAIGN BLOCKED banner naming the items, no matter how healthy the score looks. Those are the failures that produce permanent 5xx rejection — averaging one away behind twelve passes is exactly how a send gets refused.

3

“Unknown” is counted, not quietly forgiven

Unverified items count as not passing and get their own counter with a one-click filter, so the gap between what you have confirmed and what you are assuming stays visible. N/A is the only status excluded from the denominator, and you have to choose it deliberately.

4

The IT hand-off writes itself

Every failing and unverified item, with its evidence note, grouped by owner — Marketing, IT, ESP — so the IT block is one contiguous list to paste into a ticket. Copy it as plain text, print the full record, or export every domain as JSON.

What it looks like

One sending domain mid-audit. The score says 71%, but that is not the headline — the two hard failures are.

mail.northstar.com — bulk sender readiness
14 checks · audited 12 days ago
71%
Do not launch
10
Passing
2
Failing
2
Unverified
CAMPAIGN BLOCKED — 2 hard failures A failure in section A or B blocks the send regardless of percentage. These trigger permanent 5xx rejection.
CheckOwnerEvidenceStatus
List-Unsubscribe-Post headerLiteral List-Unsubscribe=One-Click ESP Header absent in raw source, 4 Sep Fail
SPF alignment with From:Passes on the ESP bounce domain only IT DMARC report, week of 1 Sep Fail
Postmaster Tools v2 verificationVerified on the click-tracking host IT Needs re-check on the DKIM d= domain Unknown
Complaint rate under 0.1%0.06% across the last 30 days Marketing Postmaster daily view, screenshot filed Pass
Unsubscribes honoured in 2 daysSuppression syncs nightly Marketing Tested 28 Aug, opt-out stopped in 4h Pass
The Postmaster row is the instructive one. The domain is verified — on the click-tracking host, which is not the DKIM signing domain or the SPF return-path domain. The dashboard looks populated and covers the wrong thing, so it sits at Unknown until someone checks which domain is actually verified.

Your options today are a deliverability platform priced per-seat for a team that already has a deliverability manager, or a spreadsheet that does not know an aligned DKIM signature from a passing one. This is the thing in between: a purpose-built auditor for one set of dated, enforced rules — for $19, once, before the next campaign goes out.

One file. One payment.

Buy it, open it, audit your first sending domain this afternoon. No account, no subscription, no seat count.

Bulk Sender Compliance Auditor
$19
One-time purchase
Yours to keep. No renewal, no per-seat pricing.
  • 14 checks across authentication, one-click unsubscribe, list hygiene and monitoring
  • Unlimited sending domains, each with its own score and evidence record
  • Hard-blocker banner for any authentication or unsubscribe failure
  • Automatic bulk-sender badge at 5,000 a day to personal inboxes
  • Transactional-only mode that marks the unsubscribe section exempt
  • Owner-grouped remediation list, copyable as plain text for a ticket
  • Printable per-domain summary, JSON export and import
  • Re-audit staleness flag at 90 days
  • Installable PWA — works fully offline
  • Light and dark themes, mobile-ready
Buy Now — $19
Instant access after checkout. Runs entirely in your browser — no domain names, evidence notes or volumes are ever uploaded.

Before you buy

Does it check my DNS or my headers automatically?

No. It makes no network calls at all — that is deliberate, because it means your domain list, volumes and internal notes never leave the machine. You check SPF, DKIM and the headers with the tools you already use, and this is where the answers, the evidence and the ownership live afterwards.

We send under 5,000 a day. Is this for us?

Enter your volume and it says so plainly, with a note that authentication is still expected of every sender. The threshold is also crossed on a single large send, so the useful posture is to audit as though the full requirements apply rather than discover mid-launch that they did.

We only send transactional mail. Does the unsubscribe section apply?

Tick transactional-only and section B is set to N/A and excluded from the score, with the exemption stated inline: transactional mail is exempt from the one-click unsubscribe requirement. Authentication is not exempt, so section A stays in force in full.

Why does a 92% score still say “do not launch”?

It will not say 92% and pass if a check in authentication or one-click unsubscribe is failing. Those two sections are hard blockers — they are what produces a permanent 5xx rejection rather than a retryable deferral — so a failure there raises the blocker banner regardless of how many other items pass.

Where does the data go?

Nowhere. It is a single HTML file storing everything in your own browser. You will be typing in sending domains, platform names, volumes and internal notes, so that matters. Export a JSON backup whenever you want a copy, or import one to move it to another machine.