Skip to content
All field notes

Microsoft 365 Sender Requirements Enforced

Microsoft now requires SPF, DKIM and an aligned DMARC record for bulk mail to Outlook.com. Who is affected and how it compares to Google and Yahoo's rules.

PlatOps Security TeamDeliverability4 min read
The short version
High-volume senders to Microsoft consumer mailboxes (Outlook.com, Hotmail, Live, MSN) now need SPF, DKIM, and an aligned DMARC record — same shape as the Google/Yahoo rules from 2024.
The threshold is ~5,000 messages a day to Microsoft consumer addresses, measured per sending domain.
Non-compliant bulk mail is routed to Junk first; Microsoft has signaled outright rejection for persistent offenders.
If you already passed the Google/Yahoo bar, you are most of the way there — but verify alignment, not just SPF/DKIM.

If you send marketing, billing, or notification email at any volume, the bar to reach an inbox just rose again. Microsoft now enforces authentication requirements for high-volume senders to its consumer mailboxes — Outlook.com, Hotmail, Live, and MSN — closing the gap with the rules Google and Yahoo put in place in 2024. Mail that does not meet them no longer lands; it goes to Junk, and eventually it will not be accepted at all.

The good news: if you did the work for Google and Yahoo, you are most of the way there. The catch is that "I have SPF and DKIM" is not the same as compliant. Here is exactly what Microsoft expects, who it applies to, and how to confirm you pass.

What Microsoft now requires

For high-volume senders to consumer mailboxes, three things are non-negotiable:

  • SPF — your sending IPs must be authorized in your domain's SPF record, and SPF must pass.
  • DKIM — messages must carry a valid DKIM signature that verifies against your domain.
  • DMARC — your domain must publish a DMARC record at a minimum of p=none, and it must align with the visible From: address.

Alongside authentication, Microsoft expects the basics of a legitimate sender: valid reverse DNS (PTR) on your sending IPs, accurate From and HELO values that do not impersonate, functional list-unsubscribe for bulk mail, and low spam-complaint rates. None of that is new as best practice — what changed is that it is now enforced for senders at scale.

Who this affects

The requirements target high-volume senders: roughly 5,000 or more messages per day to Microsoft consumer domains, measured per sending domain. If you are under that threshold, treat these as strong best practice — you still benefit from authentication, and crossing the line later is common. At or above it, they are the price of admission.

One clarification worth making: this is about mail you send to Outlook.com and Hotmail recipients. It is not a setting inside your own Microsoft 365 tenant — it is how Microsoft's consumer mail systems judge inbound mail from any sender, including you.

How it compares to the Google and Yahoo rules

If the requirements sound familiar, they should — they mirror what we covered in the Google and Yahoo sender requirements. The shape is the same across all three:

Requirement Google / Yahoo (2024) Microsoft (now)
SPF Required Required
DKIM Required Required
DMARC (min p=none, aligned) Required for bulk Required for bulk
One-click unsubscribe Required Expected
Spam-rate ceiling Under 0.3% Low complaint rate expected

The convergence is the real story: the major mailbox providers have settled on a shared baseline. Authenticate properly once, and you satisfy all of them. Miss it, and you lose deliverability everywhere at once.

The compliance checklist

Work through these in order:

  1. SPF passes for every system that sends as your domain — and you are under the 10-lookup limit.
  2. DKIM signs on your domain (not just your provider's shared domain), and the signature verifies.
  3. DMARC is published at _dmarc.yourdomain.com, minimum p=none, with a rua= address someone monitors.
  4. DMARC aligns — the SPF or DKIM domain matches your visible From:. This is the step most senders miss; passing SPF on a different domain does not count. Our explainer on DMARC alignment covers why.
  5. List-Unsubscribe with one-click is set on bulk mail.
  6. Reverse DNS (PTR) is valid for your sending IPs, and your complaint rate is low.

If you are new to any of this, start with what DMARC is and build up from there.

How to verify you pass

Do not assume — check. The fastest read is your own DMARC aggregate reports, which show whether your real sending sources authenticate and align as Microsoft and the others now demand. Send a test message to an Outlook.com address and inspect the headers for spf=pass, dkim=pass, and a DMARC result that is aligned, not just passing.

You can also check your domain's records in seconds to confirm SPF, DKIM discovery, and your DMARC policy are all in place before the next campaign goes out, instead of finding out from a drop in open rates.

The pattern is clear: every major mailbox provider now demands authenticated, aligned mail from anyone sending at volume. The work is the same one you have been putting off — publish SPF, sign DKIM on your domain, enforce DMARC, and watch your reports. Do it once and you are compliant everywhere. See where your domain stands before the requirements decide for you.

Questions we get asked

Any sender delivering roughly 5,000 or more messages a day to Microsoft consumer mailboxes — Outlook.com, Hotmail, Live, and MSN. Below that volume the rules are strong best practice; at or above it they are enforced. The threshold is measured per sending domain, and once you cross it the obligations apply.

Field notes, twice a month.

When a mailbox provider changes the rules, you hear it here with the record you need to change. No digest, no roundup, no product news.

DMARC field notes, twice a month, from PlatOps Security, LLC (Bethesda, MD). We use your address only to send it. Unsubscribe with one click in any issue. Privacy policy.