← Back to blog

Microsoft Bulk Sender Requirements

August 30, 2026

Outlook.com requires domains sending more than 5,000 emails per day to meet its high-volume authentication rules. Enforcement began May 5, 2025. This policy concerns consumer Outlook.com, Hotmail.com, and Live.com addresses; Microsoft 365 business tenants also apply their own filtering policies.

The concrete requirements and enforcement

As checked September 4, 2026, Microsoft requires SPF to pass, DKIM to pass, and a DMARC policy of at least p=none, with the visible From domain aligned to SPF or DKIM. Authentication failures can be rejected with 550 5.7.515.

The official announcement recommends a working, clearly visible unsubscribe link, consent, list hygiene, and bounce management. It does not state an RFC 8058 one-click mandate or a numerical complaint-rate cap. Do not present Gmail’s or Yahoo’s 0.3% figure as Microsoft policy. Implement one-click for marketing streams that also reach providers requiring it, and monitor Microsoft-specific complaints through its sender programs.

Map the sending environment

Document every platform that sends using your brand: Microsoft 365 mailboxes, newsletters, CRM automations, support desks, billing tools, form notifications, and agencies. Identify the visible From domain, the technical return-path if known, the DKIM selector, the owner, and the audience. This inventory lets you test each route individually and prevents a new marketing service from silently creating an authentication gap.

Build SPF deliberately

SPF is a DNS authorization policy for the envelope-from identity. Publish one SPF record rather than one record per vendor, and use only mechanisms documented by the provider that actually sends the mail. Review the expanded lookup count after every addition. A record that exceeds ten DNS lookups can fail even when it appears normal. See SPF record examples for structure and the lookup-limit guide for the common failure mode.

Enable and test DKIM

Each major sending platform should sign with DKIM when it supports it. Publish the selector record exactly as provided, then send a fresh message and inspect headers for a DKIM pass. DKIM is particularly useful when a third-party platform has its own return-path, because its aligned signature can support DMARC even where SPF alignment is different.

Use DMARC to connect the controls

DMARC evaluates whether SPF or DKIM passes in alignment with the address recipients see in From. Begin with monitoring while you discover legitimate sources. Use reports and real tests to correct misaligned senders, then move deliberately toward quarantine and reject. Read the DMARC checklist and the policy guide before enforcement.

Keep promotional and transactional mail separate

Account notices, receipts, and password resets should not be mixed into promotional list operations. Promotional streams need visible unsubscribe controls and one-click unsubscribe where applicable; transactional streams need reliable delivery without being suppressed by a marketing opt-out. Separating them gives clearer reputation data and safer recipient choices.

Run a responsible sending program

Send to people who expect the content, maintain suppression lists, avoid purchased lists, remove invalid addresses, and do not suddenly send high volume to inactive recipients. Track bounces, complaints, and engagement by platform. When placement declines, inspect message headers and recent configuration changes before editing DNS repeatedly.

Make testing routine

After a new vendor, new subdomain, mailbox migration, or DNS change, send a fresh test from every relevant system. Confirm authentication results, alignment, unsubscribe behavior, and the owner who can respond to an alert. Keep a dated change record with the prior DNS value and the test evidence.

Run Beacon’s free domain check to review the public authentication records recipients use to evaluate your domain.

Use ownership to prevent drift

Assign a person to review public records and another to own the sending-platform configuration. When responsibility is unclear, old vendors, untested selectors, and inaccurate unsubscribe settings remain in place too long. A short quarterly review of the sender inventory, current DNS values, and delivery signals is usually enough to catch drift before it affects a customer campaign or account notice.

For a broader operational reference, use the small-business deliverability checklist before launching high-volume mail.

Want a free deliverability check for your domain?
Run a free check →