Microsoft joined the mandate, Gmail moved to hard rejection, and DMARCbis reached the finish line. What 2025 changed for senders and what it sets up for 2026.
When Google and Yahoo announced their bulk sender requirements in late 2023, the open question was whether the rest of the ecosystem would follow or let the moment pass. 2025 answered it. This December the landscape looks categorically different from two years ago: every major consumer mailbox provider now requires authenticated mail from bulk senders, the biggest one rejects violations outright, and the protocol underneath finally became a real standard. A review of the year, and what it means for the one ahead.
Microsoft completed the triumvirate
The year's first structural event was Microsoft's April announcement and May 5 enforcement of sender requirements for Outlook consumer domains: SPF, DKIM, and aligned DMARC at p=none minimum for senders above 5,000 daily messages, with junk-foldering as the opening penalty and rejection promised later. Our July compliance guide covered the details; the December observation is how quietly it went. The senders who had done the 2024 work for Gmail and Yahoo mostly noticed nothing, which is exactly what convergence on a single standard is supposed to feel like.
The strategic meaning is larger than the technical one. With Microsoft in, there is no major consumer inbox left where unauthenticated bulk mail is merely penalized rather than policed. The authentication conversation inside companies changed accordingly: what was a deliverability optimization in 2023 is a market-access requirement in 2025, with a compliance owner and an audit trail.
Gmail stopped being polite
The second structural event arrived in November: Gmail moved from its long soft-enforcement phase, temporary failures, spam foldering, warning codes, to permanent 5xx rejection of bulk mail that fails the 2024 requirements. The escalation had been signposted for two years, and still it caught a population of senders who had treated tempfails as weather rather than warnings. Rejection is louder than foldering in the best possible way: it shows up in bounce logs, breaks dashboards, and forces the fix that the quiet phase only suggested.
The standards caught up
Underneath the enforcement news, the protocol layer had its own milestone year. DMARCbis completed its passage through the IETF, ending DMARC's decade as an Informational document and delivering the changes our September article detailed: the DNS tree walk replacing the Public Suffix List, pct retired, np added for non-existent subdomains. The reporting specifications followed as companion documents through the autumn. None of it required a single sender to touch DNS, and all of it matters for how the next five years of compliance frameworks, government guidance, and audit checklists will cite email authentication.
Regulation reinforced the same direction. NIS2 national implementations kept arriving across EU member states through 2025, and the security questionnaire industry duly converted state of the art into line items that read like this publication's checklists: DMARC at enforcement, transport security with MTA-STS or DANE, incident procedures with 24-hour clocks. Authentication stopped being something security teams asked marketing about, and became something auditors ask boards about.
What the mandates did not fix
The year's quieter lesson is what universal authentication does not buy. Authenticated identity makes reputation attribution precise, and precise attribution sharpens the judgment on everything else: list quality, complaint rates, engagement decay. The senders who struggled in 2025 were rarely failing SPF; they were mailing tired lists with AI-accelerated volume into inboxes that measure wantedness per recipient, exactly the dynamics our engagement and AI content articles described. Spammers, meanwhile, authenticate too, and the abuse frontier moved with them: DKIM replay, cousin domains with perfect DMARC, and compromised legitimate accounts defined 2025's threat reports far more than forged From headers.
That is the shape of the next era. Identity is solved plumbing; trust is not. The filtering models keep shifting weight toward behavioural evidence that a recipient wants the mail, and no DNS record generates that.
Positioning for 2026
The year-end audit
- Authentication passing and aligned at all three mandate providers, verified in aggregate reports, not assumed
- DMARC policy at quarantine or reject; p=none in 2026 is a monitoring phase, not a destination
- Records DMARCbis-clean: no pct, subdomain and np coverage planned
- Complaint rates holding under 0.1% with the monitoring stack watching all providers
- Engagement-based sunsetting live, with Q4's disengaged cohort suppressed in January
- Transport security (MTA-STS enforce, TLS-RPT) deployed while it is still a differentiator
Two years ago this publication argued that the authentication mandates would be remembered as the moment email's identity layer finally hardened. That happened, on schedule, and mostly without drama for anyone who did the work. The 2026 question is the harder one that was always underneath: now that every message provably says who sent it, is what you send worth wanting? The senders who can answer yes with engagement data have nothing to fear from whatever the providers announce next spring.
Frequently Asked Questions
We are under 5,000 messages a day everywhere. Did 2025 change anything for us?
When does Microsoft start rejecting instead of junk-foldering?
Did BIMI matter in 2025?
What should we watch for in 2026?
Key Takeaways
- Microsoft's May enforcement made authenticated mail mandatory at every major consumer provider
- Gmail escalated to permanent 5xx rejections for non-compliant bulk mail in November, completing the soft-to-hard arc
- DMARCbis finished at the IETF, giving the compliance world a real standard to cite
- Universal authentication moved the competitive frontier to list quality and per-recipient engagement
- The 2026 posture: enforcement-level DMARC, sub-0.1% complaints, live sunsetting, and transport security done early
Related articles
Building a Deliverability Monitoring Stack
Postmaster Tools, SNDS, FBLs, DMARC reports, TLS-RPT, bounce logs, engagement data: the full observability stack, what each layer catches, and the alerts worth paging on.
Q4 Peak Sending: Ramping Volume Without Triggering Filters
Between Black Friday and year end, send volumes triple while filters tighten. How to ramp into peak season so November's volume looks like growth, not an incident.
DMARCbis: What Changes When DMARC Gets a New RFC
DMARCbis is finishing its journey through the IETF, replacing RFC 7489 with a Standards Track spec. The tree walk, retired tags, and what senders should do now.