Business Email7 min read

SPF, DKIM, DMARC: passing the 5,000-email threshold

Since May 2025, Gmail and Outlook no longer filter suspicious emails into the spam folder — they reject them with an SMTP 550 error, before the recipient ever sees them. The rule applies from 5,000 messages per day to Gmail, and covers any sender without DMARC alignment.

Why the rules changed in 2024-2025

Google published its Sender Guidelines in October 2023 and tightened them in April 2024: any sender dispatching more than 5,000 messages per day to Gmail accounts must have SPF, DKIM and a DMARC record in place. Microsoft aligned Outlook with the same requirements in May 2025. An email rejected with a 550 never reaches the recipient's inbox. The sender receives a bounce; the message is lost.

What these three records give you in practice

  • Guaranteed deliverability — Gmail and Outlook servers accept the message instead of rejecting it with a 550.
  • Protection against spoofing — SPF and DKIM prevent a third party from sending emails in your name from an unauthorized server.
  • DMARC reports — the rua record sends you daily reports on which servers sent email under your domain.
  • Sender reputation preserved — DMARC alignment at p=quarantine then p=reject protects your domain against phishing campaigns.
  • Compliance with major platform requirements — mandatory for Mailchimp, Brevo, SendGrid and most ESPs since 2024.

The three DNS records: prerequisites

SPF, DKIM and DMARC are three separate DNS records published in the sending domain's zone. SPF (TXT on your-domain.com) lists authorized servers. DKIM (TXT on mail._domainkey.your-domain.com) adds a cryptographic signature. DMARC (TXT on _dmarc.your-domain.com) tells receiving servers what to do with emails that fail both checks. DMARC alignment — required since 2025 — means the domain in From must match the domain verified by SPF or DKIM.

Configure SPF, DKIM and DMARC step by step

01

Publish the SPF record

Create a TXT record at the root of your domain listing authorized sources, for example v=spf1 include:_spf.your-provider.com ~all. Only one SPF record per domain.

02

Enable and publish the DKIM key

Your mail server or ESP generates a key pair. Publish the public key in a TXT record under the chosen selector, for example mail._domainkey.your-domain.com.

03

Add the DMARC record with reports

Create a TXT record on _dmarc.your-domain.com. Starting value: v=DMARC1; p=none; rua=mailto:[email protected]. In p=none mode no email is rejected.

04

Verify sender domain alignment

Send a test email and check received headers for Authentication-Results mentioning spf=pass, dkim=pass and dmarc=pass. Tools like MXToolbox or mail-tester.com allow this check.

05

Tighten DMARC after two to four weeks of reports

When all legitimate sources pass SPF and DKIM, move to p=quarantine, then to p=reject. With p=reject any failing email is refused with SMTP 550.

Security: moving to p=reject and monitoring reports

The p=reject mode is the final goal: it protects your domain against phishing and meets strict Gmail and Outlook requirements. Verify all sending sources sign with DKIM. Enable the ruf tag for forensic reports.

After configuration: monitor and maintain

SPF, DKIM and DMARC are not one-time settings. A new email provider added without updating SPF immediately triggers alignment failures. Plan a quarterly review to check all active sources.

Host your website and emails with full DNS access

With ServOrbit web hosting, you manage your DNS zone, SPF, DKIM and DMARC records, and SMTP configuration from a single space.

Need help?

Browse our help center and FAQ, or write to our team — support in French, English and Arabic.