Gmail Email Sender Guidelines
Google's requirements for delivering to personal Gmail accounts — authentication, spam-rate thresholds, one-click unsubscribe, bulk-sender rules, and the enforcement timeline.
Operational6 min read
Who it is for Senders, ESP operators
Applies to senders on any platform
ContentsOn this page — 8 sections
If you send mail to personal Gmail accounts, meaning addresses ending in @gmail.com or @googlemail.com, Google's Email Sender Guidelines set out what you must do for that mail to be accepted and delivered. The requirements have been enforced since February 1, 2024, and have become stricter over time (see Enforcement timeline).
Scope:
- The guidelines and Google's enforcement apply only to mail sent to personal Gmail accounts. Messages sent to Google Workspace accounts are not covered. However, all senders, including Google Workspace users, must meet the guidelines when they send to personal Gmail accounts.
- Google Workspace senders who send large volumes are also subject to the Gmail Spam and abuse policy.
Who counts as a bulk sender
"A bulk sender is any email sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period."
How this works:
- Volume is counted for each primary (organizational) domain, including its subdomains. Google's example: 2,500 messages a day from
solarmora.complus 2,500 a day frompromotions.solarmora.commake a bulk sender, because all 5,000 came from the primary domainsolarmora.com. - Bulk sender status is permanent: "Bulk sender status doesn't have an expiration date." Falling below 5,000 a day later does not remove the status.
- Note the words "close to 5,000". Do not treat 4,999 as safe.
Requirements for ALL senders (any volume)
| Area | Requirement |
|---|---|
| Authentication | Set up SPF or DKIM for your sending domains |
| DNS | Valid forward and reverse DNS (PTR) records for sending IP addresses. The sending IP address must match the IP address of the hostname in its PTR record, and the forward lookup (A or AAAA) of that hostname must resolve back to the same IP address |
| Transport | Use a TLS connection to transmit email (no specific TLS version is stated) |
| Spam rate | Keep the user-reported spam rate in Postmaster Tools below 0.10%, and never let it reach 0.30% or higher |
| Message format | Comply with RFC 5322 (Internet Message Format) |
| From header | Do not impersonate Gmail in From: headers. Gmail applies a DMARC quarantine enforcement policy on gmail.com, so spoofing it will hurt delivery. Use a single email address in the From: field |
| Message-ID | Every message needs a valid Message-ID: header |
| Headers | Headers that may appear only once (From, To, Subject, Date) must appear exactly once. No duplicate or malformed headers |
| Content | No content hidden with HTML or CSS. Web links must be visible and understandable. HTML must conform to standards. Do not mix different types of content (for example, a receipt with promotions) in one message |
| Forwarding | If you regularly forward mail or run a forwarding service (mailing lists, gateways), follow Google's Best practices for forwarding email to Gmail. Add ARC headers so that Gmail can see the original authentication results, and keep the original authentication intact where possible |
Additional requirements for bulk senders (≈5,000+/day)
Everything above, plus:
| Area | Requirement |
|---|---|
| Authentication | Both SPF and DKIM, not one or the other |
| DMARC | Publish a DMARC record for the From: domain. A minimum policy of p=none is acceptable |
| Alignment | For direct mail, the From: header domain must be aligned with the SPF domain or the DKIM domain (relaxed alignment on the organizational domain is enough) |
| DKIM key | A key of at least 1024-bit. 2048-bit is recommended |
| One-click unsubscribe | Marketing and subscribed (promotional or commercial) messages must support RFC 8058 one-click unsubscribe with both headers:List-Unsubscribe: <https://example.com/unsubscribe/…>List-Unsubscribe-Post: List-Unsubscribe=One-Click |
| Visible unsubscribe | A clearly visible unsubscribe link in the message body as well |
| Honor unsubscribes | Process unsubscribe requests within 48 hours |
Details of one-click unsubscribe, from Google's FAQ:
- It is required only for marketing and promotional messages. Transactional messages are excluded.
- A
mailto:List-Unsubscribeon its own does not meet the requirement, because RFC 8058 requires the HTTPS POST mechanism. - Other unsubscribe links in the message body do not have to be one-click.
- One-click unsubscribe may remove the recipient from that specific mailing list only, not necessarily from all mail from the sender.
Enforcement timeline
| Date | What changed |
|---|---|
| February 1, 2024 | The requirements take effect for senders to personal Gmail accounts. Bulk senders (5,000+/day) must authenticate with SPF, DKIM and DMARC, avoid unwanted mail, and make unsubscribing easy. Enforcement began as "gradual and progressive": first temporary errors on part of the non-compliant traffic, then rising rejection rates |
| June 1, 2024 | Deadline for senders that already include an unsubscribe link to add one-click unsubscribe to all commercial and promotional messages |
| June 2024 | Bulk senders with a user-reported spam rate > 0.3% become ineligible for mitigation (escalations to delivery support) |
| November 2025 | Gmail is "ramping up its enforcement on non-compliant traffic". Non-compliant messages meet disruptions, including temporary and permanent rejections |
Mitigation eligibility
Google's escalation (mitigation) form for bulk senders only helps senders who already comply:
- A sender is ineligible while its user-reported spam rate is > 0.3%.
- Eligibility returns once the spam rate stays below 0.3% for 7 consecutive days.
- Full authentication (SPF, DKIM, DMARC) and a working one-click unsubscribe are prerequisites.
- The spam rate and other Postmaster Tools data are calculated and updated daily.
Non-compliance error codes
Gmail reports failures to meet the guidelines with 4.7.x temporary errors (rate limiting), which escalate to 5.7.x permanent rejections. All Gmail SMTP errors carry the identifier gsmtp (and gcdp when a Workspace administrator's custom rule caused them).
| Requirement failed | Temporary (rate-limited) | Permanent (blocked) |
|---|---|---|
| PTR or reverse DNS | 451-4.7.23 (also 421-4.7.0 "no PTR record") | 550-5.7.25 |
| SPF or DKIM (unauthenticated) | 421-4.7.26 | 550-5.7.26 |
| SPF failed | 421-4.7.27 | 550-5.7.27 |
| DKIM failed | 421-4.7.30 | 550-5.7.30 |
| No DMARC record | 421-4.7.40 | 550-5.7.40 |
| From: not aligned with SPF or DKIM | 421-4.7.32 | 5.7.32 |
| No TLS | 421-4.7.29 | 550-5.7.29 |
| Unusual or unsolicited volume | 421-4.7.28 | 550-5.7.28 |
| Suspicious SPF record entries | 451-4.7.24 | 550-5.7.24 |
| IPv6 sending guidelines (PTR or authentication) | None | 550-5.7.1 "does not meet IPv6 sending guidelines" |
The full list of errors, including format and reputation errors, is in Gmail troubleshooting.
To recover from rate limiting (SMTP 4.7.28 quota errors): wait at least 10 minutes, then resume with a single connection. If that works, add connections one at a time. If the single connection still fails, wait another 10 minutes.
Sending-practice recommendations (non-binding but weighted)
- Send from consistent IP addresses. Use different IP addresses for different types of message (for example, notifications and promotions), and consistent
From:addresses for each category. See Advanced IP segmentation. - Increase volume gradually, at steady rates, and avoid bursts. See IP warm-up.
- On shared IP addresses, every sender's activity affects the shared reputation. Monitor the IP address against blocklists and in Postmaster Tools.
- Do not buy email lists, send unsolicited mail, or use opt-in forms with pre-checked boxes (regional law may prohibit them).
- Monitor affiliates and drop any that send spam: "If your brand is associated with marketing spam, other messages sent by you might be marked as spam."
Display name rules
A sender's display name must identify only that sender, and reflect a consistent, clear and accurate identity. The display name must not contain subject-line text or message content ("URGENT REQUEST", "TIME IS RUNNING OUT"), deceptive emoji, the recipient's own name, or anything that imitates a threaded conversation (deception in the style of "Re:").
Compliance verification
Use Google Postmaster Tools, in particular the Compliance status dashboard, to check each requirement, and the Spam Rate dashboard to track the thresholds of 0.10% and 0.30%. After a fix, changes in compliance status can take up to 7 days to appear.
Related articles
- DMARC, on SPF, DKIM, DMARC and alignment
- Yahoo sender requirements
- Microsoft sender requirements
- Google Postmaster Tools
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- Gmail SMTP Errors and Troubleshooting
- Yahoo Sender Requirements & Best Practices
- Yahoo Complaint Feedback Loop (CFL)
- Yahoo SMTP Error Codes