# Yahoo Sender Requirements & Best Practices

> Yahoo Mail's requirements for all senders and bulk senders (authentication, one-click unsubscribe, 0.3% complaint threshold) plus recommendations on list hygiene, infrastructure, and reputation.

Source: emailmarketing.net — https://emailmarketing.net/learn/providers/yahoo-sender-requirements

If you send to Yahoo Mail addresses, your mail must meet Yahoo's published sender requirements to reach the inbox. Yahoo began enforcing them in **February 2024**, with a gradual rollout, and began enforcing the List-Unsubscribe policy in **June 2024**.

The requirements apply to **all domains and consumer brands hosted by Yahoo Mail**, including AOL and the other domains Yahoo hosts. **Yahoo Japan operates independently** and is not covered.

Mail that fails the requirements may be delivered to spam, or rejected outright with an error code (see [Yahoo SMTP Error Codes](https://emailmarketing.net/learn/providers/yahoo-smtp-error-codes)).

## Requirements for all senders

| Requirement | Detail |
|---|---|
| Authentication | Implement **SPF or DKIM at a minimum** |
| Complaint rate | Keep the spam complaint rate **below 0.3%** |
| DNS | Valid **forward and reverse (PTR) DNS records** for sending IP addresses |
| Standards | Comply with **RFC 5321** and **RFC 5322** |

## Additional requirements for bulk senders

Yahoo does not publish a volume threshold that defines a "bulk sender": a bulk sender is one that sends a significant volume of mail. For enforcement, a "sender" is evaluated at the level of the **authenticated domain or the From header domain**, and Yahoo uses all the information available (content, IP and so on) to review compliance.

| Requirement | Detail |
|---|---|
| SPF **and** DKIM | Both must be implemented, not just one |
| DMARC | Publish a valid DMARC policy of **at least `p=none`**, and **DMARC must pass**. A `rua` tag for aggregate reports is recommended. **Relaxed alignment is acceptable**: the From header domain must align with the SPF domain or the DKIM domain. |
| List-Unsubscribe header | A working **List-Unsubscribe header that supports one-click unsubscribe** on marketing and subscribed messages. **The POST method of RFC 8058 is highly recommended**; the `mailto:` method is acceptable. |
| Visible unsubscribe | An obvious, visible unsubscribe link in the message body that **does not require a login**. Body links may lead to preference pages, but they do not replace the header |
| Unsubscribe honoring | Honor unsubscribe requests **within 2 days**, with no grace period beyond that |
| Complaint rate | Spam rate below **0.3%**, calculated on mail delivered to the inbox |
| DNS and RFC | The same forward and reverse DNS, and compliance with RFC 5321 and RFC 5322, as for all senders |

### Scope of one-click unsubscribe

- It applies **only to promotional or marketing messages**, not to transactional messages (order confirmations, password resets).
- If a class of message that does not require it generates many complaints, Yahoo suggests adding unsubscribe options anyway.
- When the List-Unsubscribe header is set up correctly according to RFC 8058 **and** the sender has enough reputation and engagement, Yahoo webmail shows a blue "Unsubscribe" option next to the From address. Test it at https://mail.yahoo.com/.

### Spoofing counts against you

Spoofed mail that uses your domain **counts toward Yahoo's enforcement thresholds**. If your domain is being spoofed, move DMARC to an enforcement policy (`p=quarantine` or `p=reject`). See [DMARC](https://emailmarketing.net/learn/authentication/dmarc) for how to reach Enforcement safely.

## Authentication details

- **DKIM key length**: at least **1024 bits**, with **2048 bits recommended**.
- **Multiple DKIM signatures**: Yahoo evaluates all signatures for DMARC alignment, for reputation calculation and for the Complaint Feedback Loop. Several signatures that do not pass do not add up to a DMARC pass.
- **SPF**: publish the specific set of IP addresses authorized to send.
- **ARC** (Authenticated Received Chain): recommended for mail that is forwarded.
- Yahoo publishes `p=reject` for its own domains, so mail that spoofs From addresses such as @yahoo.com is rejected.

## Recommendations beyond the requirements

### List acquisition and hygiene

- Send only to users who **specifically requested** the mail: no purchased lists, and no pre-checked opt-in boxes.
- Use **double opt-in** (a confirmation click) to improve list quality.
- Set expectations at signup (what mail to expect, how often, and what it looks like), and **keep to the frequency the list was set up for**, without raising it unexpectedly.
- Monitor hard and soft bounces and inactive recipients, and **remove invalid recipients promptly**.
- Periodically send a **reconfirmation email to inactive subscribers**.

### Infrastructure

- Publish **valid, meaningful, non-generic reverse DNS (PTR) records** that reflect your domain name, and avoid names that look like dynamically assigned IP addresses.
- **Separate mail streams**: do not send bulk or marketing mail from the IP addresses (or DKIM domains) you use for transactional mail, alerts or user mail. See [Advanced IP Segmentation](https://emailmarketing.net/learn/ip-management/advanced-ip-segmentation).
- Keep servers patched, and make sure they are not **open relays or open proxies** (Yahoo rejects mail from these).
- Add Border Gateway Protocol (BGP) routes for IP space you own.
- **Connection management**: limit the number of messages per SMTP connection, reconnect if the connection ends without an error code, and open concurrent connections with restraint. Yahoo publishes no specific limits per connection or on concurrency.

### Monitoring and reputation

- Enroll all DKIM domains in the [Complaint Feedback Loop](https://emailmarketing.net/learn/providers/yahoo-complaint-feedback-loop), and suppress complainers.
- Yahoo's reputation inputs include **IP reputation, URL reputation, domain reputation, sender reputation, autonomous system number (ASN) reputation, DKIM signatures, DMARC authentication**, and user spam votes.
- A good domain reputation alone does not guarantee the inbox. A combination of factors (high complaints, obfuscated URLs, missing rDNS, non-compliance with RFCs) can still send mail to spam. Rules set by individual users override the system's decisions.
- Control spikes in traffic, and warm up new IP addresses gradually. See [IP Warm-Up](https://emailmarketing.net/learn/ip-management/ip-warm-up).
- Yahoo evaluates complaint rates for enforcement **continuously**, and domains with high complaint rates may be deferred.

### Compliance

- Follow the **CAN-SPAM Act**: no false or misleading headers, and no deceptive subject lines.

## Operational FAQ points

| Topic | Yahoo's answer |
|---|---|
| Whitelisting | There is no formal allowlisting program. For large launches or legal notices, submit a Sender Support Request. Reputation may be adjusted, but inbox delivery is never guaranteed. |
| New IP addresses or domains blocked | Submit a Sender Support Request that includes the error and diagnostic codes from your logs. |
| Maximum message size | Approximately **25 MB** of attachments. It varies with several factors, and neither users nor the Postmaster team can configure it. |
| Reporting abuse by Yahoo users | Mark the message as spam in the product, or use Yahoo's Report Abuse form, with the full message text and headers. |
| BIMI logo not displaying | Requirements: a valid SVG record for Brand Indicators for Message Identification (BIMI), a DMARC policy of quarantine or reject, bulk mail being sent, and enough reputation and engagement. Allow time for DNS propagation, and verify at https://mail.yahoo.com/ with the cache cleared. |

## Related articles

- [Yahoo Complaint Feedback Loop](https://emailmarketing.net/learn/providers/yahoo-complaint-feedback-loop), to monitor the complaints that count toward the 0.3% threshold
- [Yahoo SMTP Error Codes](https://emailmarketing.net/learn/providers/yahoo-smtp-error-codes)
- [Yahoo Deliverability Performance Feeds](https://emailmarketing.net/learn/providers/yahoo-performance-feeds)
- [DMARC](https://emailmarketing.net/learn/authentication/dmarc)
- [Foundations of Email Deliverability](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability)
