I have sat in a lot of outbound reviews where somebody pulls up a compliance checklist like a doctor's note. SPF, green. DKIM, green. DMARC published. One-click unsubscribe wired in. Spam rate under a tenth of a percent. Everything Google asked for, done, and reply rates still sliding.
The checklist is real. The work behind it is real. What nobody reads is the first line of the document it came from, which is the line that says who it applies to.
Google's email sender guidelines open by telling you the requirements are for sending to Gmail personal accounts, and then define that term: addresses ending in gmail.com or googlemail.com. That is the scope. Not every inbox Google operates. The consumer ones.
Your B2B list is not made of consumer mailboxes. It is made of work addresses at companies, which means Google Workspace tenants and Microsoft 365 tenants, two products that the sender guidelines do not govern in the way almost everyone assumes they do. So the team in that review had passed an exam for a school their buyers do not attend.
What the Gmail bulk sender requirements actually cover
Google's email sender guidelines set requirements for senders delivering mail to Gmail personal accounts, which the page defines as addresses ending in gmail.com or googlemail.com, with a stricter tier for anyone sending more than 5,000 messages a day to those accounts.
The tiering is worth separating out, because the two tiers get quoted interchangeably and they are not the same obligation.
| REQUIREMENT | WHO IT BINDS | WHAT THE GUIDELINES STATE |
|---|---|---|
| SPF or DKIM | All senders to personal Gmail | At least one must be configured and passing for the sending domain |
| SPF and DKIM and DMARC | More than 5,000 messages a day to personal Gmail | All three, with DMARC alignment on the From domain |
| One-click unsubscribe | Bulk marketing and subscribed mail above the threshold | List-Unsubscribe-Post and List-Unsubscribe headers, not a footer link |
| DKIM key length | Senders to personal Gmail | 1024 bits or longer, with 2048 bits recommended |
| Spam rate | All senders, measured in Postmaster Tools | Stay below 0.10%, and never reach 0.30% or higher |
| TLS for transmission | All senders, added December 2023 | Connections to Gmail must use TLS |
Every row of that table is a good idea. Several of them are table stakes for any sender who wants to be taken seriously by any filter anywhere. None of that is in dispute here.
What is in dispute is the inference. The basic requirements took effect on February 1, 2024, the industry read the announcement as a new universal standard for email, and a compliance economy grew on top of that reading. Audits, scores, badges, dashboards. All of it calibrated against a document whose own first paragraph scopes it to the mailboxes your buyers use for grocery receipts.
Microsoft drew its line in the same place
Microsoft's requirements for high-volume senders, announced in 2025 and enforced from May 5 of that year, apply to its consumer mail domains outlook.com, hotmail.com and live.com, and were not written to cover Microsoft 365 or Exchange Online business tenants.
The substance matches Google's closely enough that outbound teams treat the two as one standard. Above 5,000 messages a day to those consumer domains, Microsoft wants SPF passing, DKIM passing, and a DMARC record at p=none or stricter that aligns with at least one of them. Preferably both.
Enforcement started softer than the headlines suggested. From May 5, 2025, Microsoft said mail from non-compliant high-volume domains would be routed to the Junk folder, with outright rejection to follow on a date it did not announce. Microsoft's own post managed to be internally inconsistent about this, describing a rejection response in one paragraph and a Junk-first path in another, which is partly why the folklore around it is such a mess.
Two of the largest mail operators on earth published aggressive new rules, scoped both of them to their consumer products, and the B2B outbound industry adopted the rules as gospel for business mail. That is not a conspiracy. It is a scope line nobody read, repeated until it became a fact.
Who actually decides whether your B2B email lands
Delivery into a Google Workspace or Microsoft 365 tenant is decided by that organisation's own filtering configuration, set by its administrator in a console, with thresholds that are never published and outcomes that are never reported back to you.
This is the part that should reorganise how you think about outbound. Workspace administrators have a Gmail spam settings page, and the controls on it are blunt instruments with plain names.
| ADMIN CONTROL | WHAT IT DOES | WHAT IT MEANS FOR A COLD SENDER |
|---|---|---|
| Be more aggressive when filtering spam | Tightens filtering so more mail goes to the spam folder | A single checkbox can halve your placement across an entire company |
| Put spam in administrative quarantine | Holds suspected spam for admin review instead of delivering it | Your message is not in a spam folder a prospect might check, it is in a queue |
| Bypass spam filters for senders or domains in selected lists | Lets approved senders skip Gmail spam filtering | Being on an approved list is worth more than any score you can earn |
| Bypass spam filters and hide warnings for all senders | Turns filtering off for all inbound mail, and Google advises against it | Rare, and the reason a few accounts have inexplicably perfect placement |
| Custom spam filters on content and headers | Admin-defined rules on message attributes | Your template can be blocked by a rule written about a competitor |
Note what is absent from that console: any obligation to tell you anything. Google does not let an administrator switch off spam scanning entirely, and even approved senders stay subject to malware and attack filtering, so the tenant is not a lawless zone. But within those limits the administrator sets the bar, and you will never see where they set it.
Microsoft 365 tenants work on the same principle through Exchange Online Protection, with anti-spam policies, bulk complaint thresholds and tenant allow and block lists, all set by the customer. Different console, same conclusion: the person deciding your fate is an IT administrator at the company you are prospecting, not a policy team in Mountain View.
Why the Gmail bulk sender requirements still matter to you
Authentication remains non-negotiable for B2B outbound, because tenant-side filters score SPF, DKIM and DMARC heavily as inputs, even though the published consumer thresholds do not formally bind mail sent to business tenants.
I want to be precise about the argument, because the lazy version of it is dangerous. The lazy version says the rules do not apply to you, so relax. That is wrong and it will cost you a domain. The right version says the rules are necessary and not sufficient, and that confusing the two is what produces a team with a perfect compliance report and a dead campaign.
Think of the consumer requirements as the floor of the building rather than the roof. Unauthenticated mail fails everywhere, consumer and business alike, because authentication is how any filter establishes that you are who the envelope says you are. Getting that right earns you the chance to be evaluated. It does not win the evaluation. The gap between those two things is where every honest conversation about outbound deliverability actually happens, and it is the gap we spend most of our time in on cold email lead generation engagements.
The same logic runs through the rest of the technical stack. We argued when DMARCbis landed that the policy record is infrastructure, not a score to chase, and the same holds for the warmup and domain rotation tactics teams reach for when placement slips. They are necessary hygiene. They are not a strategy, and they cannot compensate for a list and a message that a filter has good reason to distrust.
What to measure when the scoreboard is private
When the gatekeeper publishes no threshold and returns no score, measurement has to shift from compliance metrics you can read to behavioural metrics you can observe, which means replies, bounces and per-company placement rather than a spam rate.
Here is the uncomfortable implication. Most outbound dashboards report the numbers that are easy to collect, and the easy numbers are the consumer-scoped ones. The useful numbers require work and smaller samples.
| METRIC | WHAT IT TELLS YOU ABOUT B2B TENANTS | VERDICT |
|---|---|---|
| Postmaster Tools spam rate | Complaint behaviour of consumer Gmail recipients only | Keep it clean, stop treating it as your B2B health score |
| Inbox placement from a seed list | How a handful of test mailboxes treated you, not your prospects | Weak proxy, useful only for catching catastrophic breakage |
| Reply rate by recipient mail provider | Whether an entire class of tenant is filtering you silently | The strongest signal available, and almost nobody segments it |
| Hard bounce rate on verified data | Data quality, and whether a tenant is rejecting you at the gate | Leading indicator, and the cheapest one to fix |
| Open rate | Very little, given image proxying and privacy protections | Retire it as a deliverability metric |
| Placement variance across companies | Which tenants have aggressive filtering configured | The metric this whole problem actually calls for |
Reply rate segmented by recipient mail provider is the one I would build first if I could only build one. It turns a silent failure into a visible one. If replies from Microsoft 365 recipients collapse while Workspace recipients hold steady, you have learned something no compliance report would ever have told you, and you have learned it from data you already own.
Bounce behaviour is the other cheap signal, and it needs the same discipline about sample size we have argued for elsewhere. A 4% bounce rate on 50 sends is noise. The distinction between a hard bounce and a soft bounce tells you whether you are looking at bad data or a tenant decision, and complaint rates read off small samples have started more unnecessary infrastructure rebuilds than any other number in outbound.
What to do differently on Monday
The practical change is to split your outbound reporting by recipient mail provider, keep the consumer compliance work exactly as it is, and stop reading a passing compliance report as evidence that business inboxes are accepting you.
None of that is exotic. It is mostly the discipline of reporting on the thing you are trying to affect instead of the thing that is easy to query. Any serious cold email agency should be able to tell you what share of your list sits behind Workspace, what share sits behind Microsoft 365, and how differently those two groups reply, and if that question lands as a surprise, it is a reasonable place to start asking harder ones. The same split matters upstream of deliverability too, because sequence length changes complaint behaviour and the tolerance for a fifth follow-up is not the same in a 40-seat startup tenant as it is in an enterprise one.
The broader point outlives this particular scope line. Published platform rules are written for the platform's own reasons, scoped to the platform's own interests, and the scope is usually in the first paragraph. Reading it is free. Assuming it is what you wanted it to say has been expensive for a lot of outbound programs over the last two years.
See where you are cited today
A free snapshot audit of your rankings and AI citations before we ever talk.
Josh leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.