Microsoft now requires SPF, DKIM, and DMARC from high-volume senders to Outlook consumer domains. What the rules demand, how enforcement works, and how to comply.
Microsoft was the last major holdout. Google and Yahoo mandated authentication for bulk senders in February 2024; Outlook.com kept relying on filtering heuristics for over a year afterward. That ended this spring: Microsoft announced its own requirements for high-volume senders in April, and enforcement began on May 5, 2025. Two months in, the pattern of who gets junk-foldered is clear enough to write the practical guide.
What Microsoft requires
The requirements apply to domains sending more than 5,000 messages per day to Outlook consumer addresses (outlook.com, hotmail.com, live.com and related domains). The core is the familiar authentication triad: SPF must pass for the sending domain, DKIM must sign and validate, and a DMARC record must exist at p=none or stricter, aligned with SPF or DKIM, ideally both.
Around the triad sit hygiene obligations Microsoft lists in the same announcement: valid, non-deceptive From and Reply-To addresses that can receive replies, functional unsubscribe links in bulk mail, bounce management that removes invalid addresses, and consent-based list practices. These read as filtering inputs rather than hard gates, but Microsoft explicitly reserves the right to filter or block senders that ignore them.
How enforcement works right now
Since May 5, Outlook has been routing mail from non-compliant high-volume domains to the Junk folder rather than rejecting it. Microsoft has stated that outright rejection of non-compliant messages will follow at a date to be announced. This mirrors the Gmail playbook of 2024: a soft phase that hurts engagement metrics first, then hard SMTP failures for the senders who did not take the hint.
The junk-foldering phase is deceptively quiet. Delivery succeeds at the SMTP layer, bounce logs stay clean, and the only sender-visible symptoms are collapsing open and click rates on Microsoft domains. If your per-provider engagement segmentation exists, the affected senders stand out immediately; if you only track blended averages, you can lose the Microsoft audience for weeks before noticing. This is the scenario the per-provider dashboards from our monitoring articles were built for.
550 5.7.515 Access denied, sending domain [example.com] does not
meet the required authentication standards. Ensure SPF, DKIM and
DMARC are configured. See https://aka.ms/senderrequirementsIf you already comply with Gmail and Yahoo
Senders who did the February 2024 work properly are most of the way there. The authentication triad is identical, and the alignment requirement matches. The deltas worth checking: Microsoft's emphasis on a deliverable Reply-To, its explicit bounce management expectation, and the fact that its enforcement keys on Outlook consumer domains whose users may be a different slice of your list than Gmail's.
One Microsoft-specific nuance carries over from years of SNDS experience: Outlook weights IP reputation more heavily than Google does. Compliant authentication does not neutralize a cold or damaged IP. Meeting the new requirements is the entry ticket, not the placement guarantee.
The compliance checklist
Outlook requirements audit
- SPF record valid, passing, and within the 10-lookup limit for all sending services
- DKIM signing every stream with your own domain, keys 2048-bit, rotation documented
- DMARC record published at p=none minimum with rua reporting; alignment verified in aggregate reports
- From and Reply-To addresses valid and monitored for replies
- One-click unsubscribe honored within seconds on all bulk streams
- Bounce handling suppressing invalid addresses per our bounce classification guide
- SNDS and JMRP registered for your sending IPs
- Per-provider engagement dashboards separating Microsoft consumer domains
Reading the bigger picture
With Microsoft's move, every major consumer mailbox provider now mandates authenticated mail from bulk senders. DMARC at enforcement stops being a differentiator and becomes plumbing, and the senders still treating p=none as a destination rather than a monitoring phase are running out of providers that tolerate it. The compliance work doubles as preparation for wherever the next mandate lands, because the pattern is now established: announce in spring, junk-folder in the first phase, reject in the second.
Run the checklist this month, before the rejection phase gets a date. The soft-enforcement window is exactly the time to find and fix a broken DKIM selector or a bloated SPF record, while the cost of a mistake is a junk folder rather than a bounce.
Frequently Asked Questions
Does the 5,000 daily threshold count per message or per domain?
Is p=none really enough for Microsoft?
Do the requirements cover Microsoft 365 business tenants?
We got junk-foldered. How do we recover?
Key Takeaways
- Since May 5, 2025, Outlook junk-folders high-volume senders lacking SPF, DKIM, and aligned DMARC at p=none minimum
- Outright rejection is announced for a later date, mirroring Gmail's 2024 escalation path
- Hygiene requirements ride along: deliverable From and Reply-To, working unsubscribe, bounce management
- Gmail and Yahoo 2024 compliance covers most of the work; verify the Microsoft-specific details and IP reputation separately
- Junk-foldering is invisible in bounce logs, so per-provider engagement monitoring is how you detect non-compliance
Related articles
2025 in Email: The Year Authentication Became Mandatory Everywhere
Microsoft joined the mandate, Gmail moved to hard rejection, and DMARCbis reached the finish line. What 2025 changed for senders and what it sets up for 2026.
Building a Deliverability Monitoring Stack
Postmaster Tools, SNDS, FBLs, DMARC reports, TLS-RPT, bounce logs, engagement data: the full observability stack, what each layer catches, and the alerts worth paging on.
Q4 Peak Sending: Ramping Volume Without Triggering Filters
Between Black Friday and year end, send volumes triple while filters tighten. How to ramp into peak season so November's volume looks like growth, not an incident.