GMX / WEB.DE (United Internet) — Postmaster Requirements
Sender requirements for GMX, WEB.DE and mail.com (United Internet): mandatory aligned DKIM, strict header/DNS rules, RFC 8058 unsubscribe, error-message format, and the CSA path.
Operational4 min read
Who it is for Senders, ESP operators
Applies to senders on any platform
ContentsOn this page — 9 sections
If your list has European recipients, some of them use GMX, WEB.DE or mail.com, which dominate the German consumer mailbox market. These providers are stricter than most on two points: DKIM is mandatory (SPF alone is not enough), and generic reverse DNS is rejected outright.
All three are operated by United Internet (1&1) and share one postmaster policy, published in parallel at postmaster.gmx.net, postmaster.web.de and postmaster.mail.com.
Infrastructure and DNS requirements
| Requirement | Detail |
|---|---|
| Static IP | The delivering server must have a static IP address. IP addresses from dial-up or dynamically assigned ranges are not accepted |
| Reverse DNS (PTR) | Must resolve to an FQDN that belongs to the sender's own domain. Generic provider defaults (for example 123-123-123-123-static.ihrprovider.tld) "usually result in rejection" |
| Forward DNS | The sending domain must have valid MX or A records |
| HELO or EHLO | Must be a valid FQDN |
| Blocklists | Neither the IP address nor the domain may be listed on known blocklists (they suggest checking with dnsbl.info) |
Message-format requirements (RFC 5321 and 5322)
- Headers must comply with RFC 5321 and RFC 5322.
- Required header fields:
Date,From,Message-ID(andSenderif applicable). - Each of
BCC,CC,Date,From,Sender,Subject,Tomay appear only once. - The
Date(date, time and time zone) must be correct, and must not differ significantly from the actual time of sending.
Authentication: DKIM mandatory, aligned
- DKIM is mandatory: "the use of a valid DKIM signature is mandatory."
- SPF is only recommended. In their words: "We require DKIM as a minimum requirement; SPF alone is not sufficient."
- DMARC is recommended to prevent spoofing and phishing.
- The DKIM
d=domain must align with theRFC5322.Fromdomain, at least in relaxed mode:
DKIM domain (d=) |
From domain | Mode |
|---|---|---|
| example.com | child.example.com | relaxed (accepted) |
| child.example.com | example.com | relaxed (accepted) |
| example.com | example.com | strict |
| child.example.com | child.example.com | strict |
This is the same concept of alignment that DMARC uses (see DMARC), but United Internet requires DKIM alignment as a condition of acceptance even when the domain has no DMARC policy.
Bulk-sender requirements
- Explicit consent only, ideally through double opt-in.
- Follow the M3AAWG and CSA guidelines. Taking part in the CSA is recommended (below).
- Unsubscribe: every email must contain an unsubscribe option that is easy to find and understand. The preferred method is RFC 8058 one-click List-Unsubscribe. If a message complies, GMX and WEB.DE show an unsubscribe button in their interface. If RFC 8058 is not met, a valid reply address must be provided instead.
- List hygiene: avoid invalid, inactive or outdated addresses, and regularly remove addresses that cannot be delivered. "If many messages are sent to unknown or deactivated addresses, this can lead to temporary suspension" of acceptance.
- Sender identity: the sender must be clearly and unambiguously identifiable, the content must be relevant, and the frequency appropriate.
- Warm-up caveat: for mass mailings, "our system may throttle delivery despite IP warm-up". Expect temporary failures on new IP addresses even with a proper ramp-up (see IP Warm-Up).
Error messages
United Internet documents the structure of its SMTP errors rather than a complete table of codes:
- 5xx codes are permanent errors, and 4xx codes are temporary errors.
- Every rejection contains an SMTP status code, a description of the problem, and a URL with diagnostic parameters. The URL points to the matching postmaster page (
https://postmaster.gmx.net/...,postmaster.web.deorpostmaster.mail.com), which gives explanations and solutions. Always follow that URL, because it identifies the exact reason for the block. - Example:
554 gmx.net (mxgmx104) Nemesis ESMTP Service not available / No SMTP service / IP address is block listed.The connecting IP address is on a blocklist, and the URL in the message explains how to fix it.
Filtering behavior, allowlisting, feedback loop
- No allowlist: "GMX does not offer this service". According to GMX, following the requirements makes allowlisting unnecessary.
- Behavior similar to greylisting: they delay or reject mail from servers that show "unmistakable characteristics that indicate a spamming server."
- Filtering is based on both IP addresses and content. If a message is wrongly classified, submit its extended headers through their contact form (
https://postmaster.gmx.net/en/contact). - No public FBL of their own. In practice, complaint feedback for GMX and WEB.DE is available through the CSA (certified senders receive complaint data as part of certification). The postmaster site itself points bulk senders to the CSA instead of offering a direct FBL signup.
Certified Senders Alliance (CSA) and trustedDialog
- CSA: a positive-list project of eco (Verband der deutschen Internetwirtschaft) together with the DDV. GMX and WEB.DE and several other European providers check certification, and United Internet recommends that senders of newsletters and advertising take part. Information: certified-senders.org.
- trustedDialog: a paid brand-protection standard from United Internet Media. It combines sender authentication with verification that the content is intact, and in return shows a seal and brand logo in the inbox, gives recipients more confidence that the sender is authentic, and (according to United Internet Media) improves open and click rates. It is mainly relevant for large consumer brands that mail German users.
GMX outbound servers (for receivers / verification)
Mail that genuinely comes from GMX arrives from these published hosts:
| Role | Hostname | IPs |
|---|---|---|
| Outbound | mout.gmx.net | 212.227.15.15, 212.227.15.18, 212.227.15.19, 212.227.17.20, 212.227.17.21, 212.227.17.22 |
| Bounce handling | mout-bounce.gmx.net | 212.227.15.44–46, 212.227.17.26, 212.227.17.28, 212.227.17.29 |
| Lower reputation (forwarded by customers) | mout-xforward.gmx.net | 82.165.159.12–14, 82.165.159.40–42 |
If GMX blocks you
- Read the bounce. It contains the exact reason and a postmaster URL.
- Fix the root cause against the requirements above (the delisting form will not help while problems with PTR, DKIM or consent remain).
- Contact the abuse team through the postmaster contact form, and provide your email address, contact address, name, the date of the attempted send, the recipient domain, and the exact error message or mailer-daemon text. Bounces caused by full inboxes or by a recipient's misconfiguration are not "blocklisting", and do not belong on that form.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- Gmail Email Sender Guidelines
- Gmail SMTP Errors and Troubleshooting
- Yahoo Sender Requirements & Best Practices
- Yahoo Complaint Feedback Loop (CFL)