# Gmail Email Sender Guidelines

> Google's requirements for delivering to personal Gmail accounts — authentication, spam-rate thresholds, one-click unsubscribe, bulk-sender rules, and the enforcement timeline.

Source: emailmarketing.net — https://emailmarketing.net/learn/providers/gmail-sender-requirements

If you send mail to **personal Gmail accounts**, meaning addresses ending in `@gmail.com` or `@googlemail.com`, Google's Email Sender Guidelines set out what you must do for that mail to be accepted and delivered. The requirements have been enforced since **February 1, 2024**, and have become stricter over time (see [Enforcement timeline](#enforcement-timeline)).

Scope:

- The guidelines and Google's enforcement apply **only to mail sent to personal Gmail accounts**. Messages sent to Google Workspace accounts are not covered. However, all senders, including Google Workspace users, must meet the guidelines when they send to personal Gmail accounts.
- Google Workspace senders who send large volumes are also subject to the Gmail Spam and abuse policy.

## Who counts as a bulk sender

> "A bulk sender is any email sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period."

How this works:

- **Volume is counted for each primary (organizational) domain, including its subdomains.** Google's example: 2,500 messages a day from `solarmora.com` plus 2,500 a day from `promotions.solarmora.com` make a bulk sender, because all 5,000 came from the primary domain `solarmora.com`.
- **Bulk sender status is permanent**: "Bulk sender status doesn't have an expiration date." Falling below 5,000 a day later does not remove the status.
- Note the words "close to 5,000". Do not treat 4,999 as safe.

## Requirements for ALL senders (any volume)

| Area | Requirement |
|---|---|
| Authentication | Set up **SPF or DKIM** for your sending domains |
| DNS | Valid **forward and reverse DNS** (PTR) records for sending IP addresses. The sending IP address must match the IP address of the hostname in its PTR record, and the forward lookup (A or AAAA) of that hostname must resolve back to the same IP address |
| Transport | Use a **TLS connection** to transmit email (no specific TLS version is stated) |
| Spam rate | Keep the user-reported spam rate in Postmaster Tools **below 0.10%**, and **never let it reach 0.30% or higher** |
| Message format | Comply with **RFC 5322** (Internet Message Format) |
| From header | Do not impersonate Gmail in `From:` headers. Gmail applies a **DMARC quarantine** enforcement policy on `gmail.com`, so spoofing it will hurt delivery. Use a single email address in the `From:` field |
| Message-ID | Every message needs a valid `Message-ID:` header |
| Headers | Headers that may appear only once (`From`, `To`, `Subject`, `Date`) must appear exactly once. No duplicate or malformed headers |
| Content | No content hidden with HTML or CSS. Web links must be visible and understandable. HTML must conform to standards. Do not mix different types of content (for example, a receipt with promotions) in one message |
| Forwarding | If you regularly forward mail or run a forwarding service (mailing lists, gateways), follow Google's *Best practices for forwarding email to Gmail*. Add **ARC headers** so that Gmail can see the original authentication results, and keep the original authentication intact where possible |

## Additional requirements for bulk senders (≈5,000+/day)

Everything above, **plus**:

| Area | Requirement |
|---|---|
| Authentication | **Both SPF and DKIM**, not one or the other |
| DMARC | Publish a **DMARC record** for the `From:` domain. A minimum policy of `p=none` is acceptable |
| Alignment | For direct mail, the `From:` header domain must be **aligned** with the SPF domain or the DKIM domain (relaxed alignment on the organizational domain is enough) |
| DKIM key | A key of at least **1024-bit**. **2048-bit** is recommended |
| One-click unsubscribe | Marketing and subscribed (promotional or commercial) messages must support **RFC 8058 one-click unsubscribe** with both headers:<br>`List-Unsubscribe: <https://example.com/unsubscribe/…>`<br>`List-Unsubscribe-Post: List-Unsubscribe=One-Click` |
| Visible unsubscribe | A clearly visible unsubscribe link in the message body as well |
| Honor unsubscribes | Process unsubscribe requests within **48 hours** |

Details of one-click unsubscribe, from Google's FAQ:

- It is required only for **marketing and promotional** messages. Transactional messages are excluded.
- A `mailto:` `List-Unsubscribe` on its own does **not** meet the requirement, because RFC 8058 requires the HTTPS POST mechanism.
- Other unsubscribe links in the message body do not have to be one-click.
- One-click unsubscribe may remove the recipient from that specific mailing list only, not necessarily from all mail from the sender.

## Enforcement timeline

| Date | What changed |
|---|---|
| **February 1, 2024** | The requirements take effect for senders to personal Gmail accounts. Bulk senders (5,000+/day) must authenticate with SPF, DKIM and DMARC, avoid unwanted mail, and make unsubscribing easy. Enforcement began as "gradual and progressive": first temporary errors on part of the non-compliant traffic, then rising rejection rates |
| **June 1, 2024** | Deadline for senders that already include an unsubscribe link to add **one-click unsubscribe** to all commercial and promotional messages |
| **June 2024** | Bulk senders with a user-reported spam rate **> 0.3%** become **ineligible for mitigation** (escalations to delivery support) |
| **November 2025** | Gmail is "ramping up its enforcement on non-compliant traffic". Non-compliant messages meet disruptions, including **temporary and permanent rejections** |

### Mitigation eligibility

Google's escalation (mitigation) form for bulk senders only helps senders who already comply:

- A sender is ineligible while its user-reported spam rate is **> 0.3%**.
- Eligibility returns once the spam rate stays **below 0.3% for 7 consecutive days**.
- Full authentication (SPF, DKIM, DMARC) and a working one-click unsubscribe are prerequisites.
- The spam rate and other Postmaster Tools data are calculated and updated **daily**.

## Non-compliance error codes

Gmail reports failures to meet the guidelines with 4.7.x temporary errors (rate limiting), which escalate to 5.7.x permanent rejections. All Gmail SMTP errors carry the identifier `gsmtp` (and `gcdp` when a Workspace administrator's custom rule caused them).

| Requirement failed | Temporary (rate-limited) | Permanent (blocked) |
|---|---|---|
| PTR or reverse DNS | 451-4.7.23 (also 421-4.7.0 "no PTR record") | 550-5.7.25 |
| SPF or DKIM (unauthenticated) | 421-4.7.26 | 550-5.7.26 |
| SPF failed | 421-4.7.27 | 550-5.7.27 |
| DKIM failed | 421-4.7.30 | 550-5.7.30 |
| No DMARC record | 421-4.7.40 | 550-5.7.40 |
| From: not aligned with SPF or DKIM | 421-4.7.32 | 5.7.32 |
| No TLS | 421-4.7.29 | 550-5.7.29 |
| Unusual or unsolicited volume | 421-4.7.28 | 550-5.7.28 |
| Suspicious SPF record entries | 451-4.7.24 | 550-5.7.24 |
| IPv6 sending guidelines (PTR or authentication) | None | 550-5.7.1 "does not meet IPv6 sending guidelines" |

The full list of errors, including format and reputation errors, is in [Gmail troubleshooting](https://emailmarketing.net/learn/providers/gmail-troubleshooting).

To recover from rate limiting (SMTP 4.7.28 quota errors): wait at least **10 minutes**, then resume with a **single connection**. If that works, add connections **one at a time**. If the single connection still fails, wait another 10 minutes.

## Sending-practice recommendations (non-binding but weighted)

- Send from **consistent IP addresses**. Use different IP addresses for different types of message (for example, notifications and promotions), and consistent `From:` addresses for each category. See [Advanced IP segmentation](https://emailmarketing.net/learn/ip-management/advanced-ip-segmentation).
- Increase volume **gradually**, at steady rates, and avoid bursts. See [IP warm-up](https://emailmarketing.net/learn/ip-management/ip-warm-up).
- On **shared IP addresses**, every sender's activity affects the shared reputation. Monitor the IP address against blocklists and in Postmaster Tools.
- Do not buy email lists, send unsolicited mail, or use opt-in forms with pre-checked boxes (regional law may prohibit them).
- Monitor **affiliates** and drop any that send spam: "If your brand is associated with marketing spam, other messages sent by you might be marked as spam."

### Display name rules

A sender's display name must identify only that sender, and reflect a consistent, clear and accurate identity. The display name must not contain subject-line text or message content ("URGENT REQUEST", "TIME IS RUNNING OUT"), deceptive emoji, the recipient's own name, or anything that imitates a threaded conversation (deception in the style of "Re:").

## Compliance verification

Use [Google Postmaster Tools](https://emailmarketing.net/learn/postmaster-tools/google-postmaster-tools), in particular the **Compliance status dashboard**, to check each requirement, and the Spam Rate dashboard to track the thresholds of 0.10% and 0.30%. After a fix, changes in compliance status can take up to 7 days to appear.

## Related articles

- [DMARC](https://emailmarketing.net/learn/authentication/dmarc), on SPF, DKIM, DMARC and alignment
- [Yahoo sender requirements](https://emailmarketing.net/learn/providers/yahoo-sender-requirements)
- [Microsoft sender requirements](https://emailmarketing.net/learn/providers/microsoft-sender-requirements)
- [Google Postmaster Tools](https://emailmarketing.net/learn/postmaster-tools/google-postmaster-tools)
