Home/Blog/Cold email deliverability in 2026: what Google, Yahoo and Microsoft now require

Cold email deliverability in 2026: what Google, Yahoo and Microsoft now require

Laptop showing an email inbox representing cold email deliverability

There is a version of cold email that no longer works, and plenty of teams are still running it. Buy a list, spin up a few inboxes, send a few thousand emails a day, and treat the spam folder as the worst case. In 2026 the worst case is not the spam folder. It is rejection, where the mail never arrives anywhere and you have no idea it happened.

The reason is a shift that has been building for two years and is now fully in force. Google, Yahoo and Microsoft moved their sender requirements from recommended to enforced. Mail that fails their checks does not get filtered to spam. It gets refused at the door. If your outbound program is not set up correctly, you are not sending cold email. You are sending nothing.

This is a technical topic, but it is not only a job for whoever runs your infrastructure. It shapes what your sales team can and cannot do, how fast you can scale outbound, and whether your domain stays healthy enough to keep sending at all. Here is what changed and what to actually do about it.

The three checks that now decide whether you can send

The foundation of modern deliverability is authentication, and there are three records that matter. They are not new, but they are now mandatory rather than optional for anyone sending at volume, and the safe assumption is that the strict rules apply to cold email regardless of your volume.

The first is SPF, which tells receiving servers which mail servers are allowed to send on behalf of your domain. Without it, or with a broken record, your mail looks unauthorised.

The second is DKIM, which adds a cryptographic signature to each message so the receiver can confirm it really came from you and was not tampered with in transit.

The third is DMARC, which ties the first two together and tells receivers what to do when a message fails. DMARC also has to be aligned, meaning the domain a recipient sees needs to match the domains used in your authentication. Passing is not enough on its own. Alignment is the part many teams miss.

Get these three right and aligned and you clear the first gate. Get any of them wrong and it does not matter how good your copy is, because a growing share of your mail simply will not be delivered.

One-click unsubscribe is no longer a nicety

Alongside authentication, the major providers now require a working one-click unsubscribe for marketing mail, built to the RFC 8058 standard. This is the header-based unsubscribe that lets a recipient opt out in a single tap without leaving their inbox.

Cold email sits in an awkward spot here. Many operators assume unsubscribe requirements apply only to newsletters and bulk marketing. The trend in enforcement is toward universal application, and cold email sits closest to the behaviour these systems police. Treat one-click unsubscribe as required for your outbound, not optional, and make sure it genuinely works. A broken or missing unsubscribe is both a compliance problem and a fast way to attract complaints.

There is a practical upside here. An easy unsubscribe is better for your sender reputation than forcing people to hit the spam button to make you stop. Every spam complaint you avoid protects your ability to reach the next prospect.

The numbers that can shut you down

The providers now hold senders to specific complaint and bounce thresholds, and crossing them has real consequences. Google, Yahoo and Microsoft enforce bulk sender rules that require spam complaints to stay under 0.3 percent and bounces under 2 percent.

Google is more specific still. Its guidelines say senders should keep their reported spam rate below 0.1 percent and must never, under any circumstances, exceed 0.3 percent. That 0.1 percent figure is the level to design around. It means roughly one complaint per thousand delivered emails. It does not take many angry recipients to blow past it, which is why list quality and targeting matter more than raw volume.

Bounces matter for a similar reason. A high bounce rate signals that you are sending to bad or scraped addresses, which is exactly the behaviour these filters are built to catch. Verify addresses before you send, remove role accounts and obvious traps, and keep your bounce rate well under the 2 percent line.

The uncomfortable truth is that these thresholds punish the old high-volume, low-relevance playbook directly. If you spray a large untargeted list, you will collect complaints and bounces, your rates will climb, and your delivery will collapse. The system is designed to make that approach fail.

What this means for how you run outbound

Put the rules together and a clear strategy falls out. The winning approach in 2026 is lower volume, higher relevance, and clean infrastructure. That is not a moral position, it is the only setup the receiving servers reward.

Start with your domain strategy. Sending cold email from your primary domain risks your main business reputation, so most teams send from separate sending domains that are still properly authenticated and aligned. Warm new domains and inboxes gradually rather than blasting from day one. A brand new domain sending thousands of messages looks exactly like a spammer to a filter.

Then tighten your list. Every contact you email should be a reasonable fit, and every address should be verified. The days of loading a giant scraped list and hoping are over, because the complaint and bounce math will end your program before it produces results.

Next, watch your engagement. Positive engagement, replies and opens from real people, supports your reputation. Repeated sends to people who never engage drags it down. Prune unresponsive contacts instead of hitting them again and again.

Finally, monitor the signals the providers give you. Google Postmaster Tools and similar dashboards show your spam rate and domain reputation. If your spam rate creeps toward 0.1 percent, slow down and fix the cause before you cross the hard limit.

Warming domains and inboxes the right way

The single most common cause of a new outbound program collapsing in its first month is a cold domain sending at full volume from day one. To a receiving server, a brand new domain that suddenly pushes thousands of messages looks exactly like a spam operation, because that is often what it is. The fix is to warm up gradually, building a sending history that tells the providers you are a legitimate sender.

Warming means starting with a small daily volume and increasing it slowly over several weeks. Early on, the mail should go to engaged, responsive recipients where possible, because positive engagement early in a domain's life builds reputation faster than anything else. Sudden spikes in volume are a red flag, so the increase should be steady rather than jumping from a handful of emails to hundreds overnight.

The same logic applies to individual inboxes. Each sending mailbox needs its own history of healthy activity. Spreading a modest volume across a few properly warmed inboxes is far safer than pushing everything through one inbox at high volume, which looks aggressive and concentrates risk.

Patience here pays off directly. Teams that rush the warmup phase often burn a domain in weeks and have to start again, losing more time than the warmup would have taken in the first place. Treat the first month as an investment in a sending reputation that will carry the program for the year.

What DMARC alignment really means

Of the three authentication records, DMARC alignment is the one teams most often get subtly wrong, so it is worth a plain explanation. Passing SPF or DKIM is not enough on its own. Alignment means the domain the recipient actually sees in the from address has to match the domains used in your authentication.

In practice, a message can technically pass an SPF check while the domain that passed is not the domain the recipient sees, because it was authenticated on behalf of some intermediary. To a person that looks fine. To DMARC it is a misalignment, and increasingly it means the message is treated as unauthenticated. This is why some teams set up authentication, see the checks passing in isolation, and still watch delivery suffer. The individual pieces pass, but they do not line up.

The way to avoid this is to test alignment specifically, not just whether each record exists. Send test messages to accounts across the major providers and read the authentication results in the message headers. You are looking for SPF and DKIM to pass and, crucially, to align with the visible sending domain. If they do not, the fix is usually in how your sending platform is configured to sign and send on your domain, and it is worth solving before you send a single real prospect email.

The copy itself affects delivery

Deliverability is not only about DNS records and volume. The content of the message plays a part too, because filters read the mail and react to patterns associated with spam.

Heavy use of aggressive sales language, too many links, large images with little text, and classic spam trigger words all push a message toward the filters. This does not mean you have to write blandly. It means the message should read like a normal note from one person to another, which is also what earns replies. The interests line up here. The copy that performs best with humans, short, specific and low on hype, is also the copy that performs best with filters.

Formatting matters as well. A wall of tracking links, hidden pixels and mismatched display URLs looks manipulative to a filter and often to a recipient. Keeping messages simple, with a clear reason for writing and a single low-friction ask, keeps you clear of the patterns that trigger scrutiny. Every element you add that looks like mass marketing nudges you closer to the behaviour the providers are trying to suppress.

The infrastructure work is only half the job

It is tempting to treat deliverability as a purely technical checklist. Set up SPF, DKIM, DMARC, add the unsubscribe header, and move on. That gets you through the gate, but it does not keep you healthy over time.

Reputation is behavioural. It reflects how recipients react to your mail over weeks and months. You can have flawless authentication and still ruin your reputation by sending irrelevant messages to people who did not want them. The technical setup earns you the right to send. The quality of your targeting and copy decides whether you keep it.

This is why deliverability and targeting are really the same problem. A tightly targeted program that reaches genuinely relevant people generates replies, avoids complaints, and keeps your rates comfortably inside the limits. A loose program does the opposite, no matter how clean the DNS records are.

For teams running outbound at any scale, keeping list quality, sending behaviour and reputation joined up is the hard part. A system that handles prospecting, verification and sending together makes this easier, because you are not moving a scraped list between disconnected tools and losing control of quality along the way. Empiraa Signal is built to keep prospecting, enrichment and personalised sending in one place, which helps keep the list clean and the sending behaviour disciplined.

Monitoring and recovering when reputation drops

Even a well-run program will have wobbles, so knowing how to read the warning signs and respond is part of the job. The providers give you data, and the teams that stay healthy are the ones who watch it and act early rather than waiting for delivery to collapse.

Google Postmaster Tools is the main window into how Gmail sees you. It shows your spam complaint rate and your domain reputation over time. The moment your spam rate starts drifting up toward the 0.1 percent target, that is your cue to slow down and find the cause, well before you approach the 0.3 percent hard ceiling where delivery falls apart. Reputation is much easier to protect than to rebuild, so treat any upward drift as a signal to act, not a number to note and ignore.

If reputation has already dropped, the recovery is mostly about behaviour. Cut your volume back sharply and send only to your most engaged, most relevant contacts for a while. This rebuilds a pattern of positive engagement that slowly repairs how the providers see you. Continuing to send at the same volume to the same broad list will only deepen the hole, because the behaviour that damaged your reputation is still happening.

At the same time, hunt for the cause. A reputation drop usually traces back to something specific: a batch of poorly targeted sends, a spike in volume, a list with a lot of bad addresses, or a broken unsubscribe generating complaints. Find and fix the source rather than just riding out the symptom, or the problem will return the moment you scale back up.

If a sending domain is badly burned, sometimes the pragmatic move is to retire it and warm a fresh one, while fixing whatever caused the damage so the new domain does not go the same way. That is a real cost, which is exactly why prevention, tight targeting and steady sending, is so much cheaper than recovery.

A practical setup checklist

If you want a concrete order of operations, work through these steps before you scale any outbound program.

  1. Confirm SPF, DKIM and DMARC are published, passing and aligned for every sending domain. Do not assume this is done. Test it and read the results.
  2. Publish a DMARC policy and monitor the reports so you can see what is failing and fix it.
  3. Add RFC 8058 one-click unsubscribe to your outbound and confirm it actually removes people.
  4. Verify every address before sending and keep bounce rates under 2 percent.
  5. Warm new domains and inboxes gradually, and keep cold sending off your primary business domain.
  6. Connect a postmaster dashboard and watch your spam rate against the 0.1 percent target and the 0.3 percent hard ceiling.
  7. Prune unengaged contacts regularly rather than emailing them repeatedly.

Work through that list and you clear the technical bar. Keep your targeting tight on top of it and you stay clear over time.

The takeaway

Cold email is not dead, but the version that relied on volume and luck is finished. The providers have made the cost of low-relevance sending immediate and severe. Fail the checks and your mail is rejected. Cross the complaint thresholds and your reputation collapses.

The teams that will keep winning with outbound in 2026 are the ones that treat deliverability as a first-class concern, not an afterthought. Get the authentication right, keep the unsubscribe working, verify your lists, watch your rates, and send fewer, more relevant messages. Do that and cold email still works. Ignore it and you will be talking to an empty room without realising the door was locked.

Frequently asked questions
What are the Google and Yahoo sender requirements for 2026?

At volume, senders must authenticate with SPF, DKIM and DMARC that are passing and aligned, offer a working one-click unsubscribe built to RFC 8058, keep spam complaint rates low, and keep bounces under 2 percent. These moved from recommended to enforced, so failing them can mean outright rejection rather than the spam folder.

What spam complaint rate is safe for cold email?

Google says to keep your reported spam rate below 0.1 percent and never exceed 0.3 percent. Design your program around the 0.1 percent target, which is roughly one complaint per thousand delivered emails. Tight targeting and clean lists are the main ways to stay under it.

Do one-click unsubscribe rules apply to cold email?

Enforcement is heading toward universal, and cold email sits closest to the behaviour these systems police. The safe assumption is yes. Add a working RFC 8058 one-click unsubscribe to your outbound and make sure it genuinely removes people, because a broken unsubscribe invites complaints.

Should I send cold email from my main domain?

Most teams avoid it, because complaints or bounces on cold outreach can damage the reputation of your primary business domain. Use separate sending domains that are still properly authenticated and aligned, and warm them gradually before scaling.

Why is my cold email not being delivered even though it is not in spam?

If your authentication fails or your reputation is poor, providers can reject mail outright rather than filing it in spam, so it never arrives anywhere. Check that SPF, DKIM and DMARC are passing and aligned, review your spam and bounce rates in a postmaster dashboard, and tighten your list quality.

Ash Brown

Ash Brown

Founder & CEO of Empiraa

Published 23 July 2026

Ready to fix the part of your business that feels messy?

Whether you're trying to execute strategy, grow pipeline, or connect the way your team works, Empiraa gives you a clearer system to run from.

GPS for strategy execution. Signal for sales growth.