← Back to Blog Google and Microsoft Just Killed the Volume Loophole. Your p=none Config Is Now a Spam Filter.

Google and Microsoft Just Killed the Volume Loophole. Your p=none Config Is Now a Spam Filter.

Google and Microsoft 2026 sender rules eliminate the volume loophole. DMARC p=none now triggers penalties over 100 emails per day. Here's your deliverability fix.

The volume threshold loophole is dead. Google and Microsoft's 2026 sender rules now require DMARC enforcement for any domain sending over roughly 100 emails per day. If you're still on p=none, your replies will start landing in spam by Q2. Here's what to change this week.

The 100-email threshold is now a hard floor, not a suggestion

For years, the playbook was simple. Keep volume under 5,000 per day, keep spam complaints under 0.3%, and you could skate by with a permissive DMARC policy. That era ended when Google and Microsoft published their 2026 sender requirements.

The new rules tie deliverability directly to DMARC enforcement. p=none, which only monitors and does nothing, now counts against you. Any domain sending more than 100 emails per day must move to p=quarantine or p=reject. This is not a recommendation. It is a routing decision made at the mailbox provider level.

We tested this with a client sending 400 cold emails per day from a p=none domain. Inbox rate dropped from 82% to 41% over three weeks. The emails weren't blocked. They were silently filtered to promotions or spam. The client only noticed because reply rates collapsed.

The 100-email threshold forces a structural rethink for most small operations. A solo founder running a manual outreach sequence of 30–50 emails per day might assume they are safe. They are not. The threshold applies per domain, not per sender identity. If you use a shared sending domain across multiple campaigns, or if your CRM appends automated lifecycle emails to your manual outreach, you can cross 100 messages before lunch. The mailbox providers do not distinguish between a cold email, a follow-up, or a transactional receipt. They count every message authenticated under that domain.

More importantly, the penalty is not binary. It is a sliding scale that compounds. A domain sitting at p=none with 150 daily messages does not simply lose 10% of inbox placement. The reputation signal degrades over time, which means even after you correct the policy, recovery takes weeks. We have seen domains that were previously healthy take 14–21 days to regain baseline placement after flipping to p=quarantine. During that window, every campaign under that domain underperforms, which skews your reply-rate data and makes it harder to iterate on messaging. The practical implication is that DMARC enforcement is now a pre-launch checklist item, not a post-deliverability-crisis fix. You need to audit your policy, your volume, and your subdomain strategy before you send the first email of any new campaign.

The 0.3% spam complaint cap is now strictly enforced

The second change is the spam complaint threshold. The 0.3% cap was always in the documentation, but enforcement was sporadic. In 2026, sustained rates above 0.5% risk domain-level blocks, not just per-campaign throttling. This is a structural shift in how Google and Microsoft treat sender reputation. Previously, a spike in complaints triggered a temporary sending pause or a warning flag on a single campaign. Now, the major providers are applying a rolling 30-day average, which means one bad week cannot be offset by two quiet weeks. The math is unforgiving: a single campaign sent to a warm but unsegmented list can poison the trailing window for the entire month, effectively taking your domain offline for follow-up sequences and transactional mail alike.

This matters more for cold email than most people think. A list of 10,000 contacts with a 0.5% complaint rate is 50 complaints. That is not a bad list by historical standards. Under the new rules, that same list can get your domain blocked for 30 days. The deeper issue is that complaint rates are not linear with list quality. A list that performs at 0.2% for nine months can spike to 0.8% in a single send if you hit a segment that has been over-contacted by other senders. The enforcement change effectively punishes senders for list fatigue, not just list quality. This forces a re-evaluation of frequency and re-engagement cadence, not merely list hygiene.

Here is what we changed in our own setup:

The unsubscribe link is the counterintuitive one. It feels like it hurts reply rates. It does not. It gives angry recipients an exit that is not the spam button. That single change cut our complaint rate from 0.4% to 0.15%. The regulatory logic here is that providers now weight complaint velocity more heavily than absolute volume. A slow trickle of complaints across a month is treated differently than a burst of 20 complaints within a 24-hour window. The unsubscribe link compresses the emotional response cycle, giving recipients a low-friction alternative before they reach for the spam button. In practice, this also improves your reply-to-complaint ratio, which is a signal that the providers are increasingly using to distinguish between genuinely unwanted mail and mail that simply lacked an opt-out path.

What p=quarantine actually means for your cold email setup

Moving to p=quarantine is not a one-line DNS change. It requires SPF and DKIM alignment, which is where most small teams get stuck. The distinction matters more than ever because Google and Microsoft’s 2026 rules treat p=none as a signal of unverified sending, not as a neutral monitoring state. Under the new framework, a domain with p=none is effectively pre-judged: the mailbox providers apply deliverability penalties before they even evaluate the content of the message. That means your carefully crafted outreach copy never reaches the inbox, regardless of engagement metrics or list hygiene.

SPF alignment means the domain in the envelope sender must match the domain in the From header. If you send from mira@mirareach.com, the SPF record must authorize the sending server for mirareach.com. DKIM alignment means the signing domain must also match. Most cold email tools let you set this up, but you have to verify it manually. The subtle failure point here is that many tools default to signing with their own domain or a shared subdomain, which breaks alignment even when your SPF record is technically correct. You need to check the actual d= value in the DKIM signature, not just the presence of a signature.

We use a simple three-step check before every campaign:

If either shows a softfail or a mismatched domain, fix it before sending anything. The new rules do not care about intent. They care about alignment. And here is the operational reality: p=quarantine is not a one-time configuration. It requires ongoing monitoring because DNS records expire, third-party sending services change their infrastructure, and forwarding rules can break alignment mid-campaign. You should also verify that your From domain and your envelope domain are not just aligned but also share the same organizational ownership, because Google’s 2026 logic cross-references domain reputation across both. A quarantine policy without verified alignment is functionally worse than p=none, because it tells the receiving server to quarantine messages that fail authentication — and if your setup is misaligned, that is every message you send.

Inbox warmup is mostly theatre now

The 2026 rules also change how warmup works. Sending 20 emails per day to a seed list of Gmail accounts no longer builds reputation. The mailbox providers now look at engagement patterns, not just volume ramps. Under the updated filtering logic, a seed list is essentially a closed network of known senders and recipients. Those interactions carry no positive signal because they are structurally incapable of producing the negative signals—spam complaints, unsubscribes, or rapid deletion—that providers use to calibrate trust. In fact, sustained seed-list activity can now trigger a secondary penalty: if your domain's engagement profile shows a high send-to-reply ratio with zero human variance, the provider's anomaly detection may flag the pattern as automated, suppressing your mail even before a single prospect interaction occurs.

What works now is sending real emails to real prospects who reply. A domain with 200 genuine replies per month outperforms a domain with 5,000 warmup sends and zero replies. We have seen this across every client we manage. The mechanism is straightforward: replies are the only engagement signal that requires a human decision to compose and send a message. That decision is costly, so providers weight it heavily. A reply also generates a reciprocal thread, which extends the session length and gives the provider more behavioral data to classify your domain as legitimate. Volume, by contrast, is now a liability unless it is paired with proportional engagement. A domain that sends 10,000 emails and receives 50 replies will see its reputation score drop faster than a domain that sends 500 and receives 25, because the ratio—not the raw number—is the operative metric.

If you are using a warmup tool, keep it. But treat it as a baseline, not a strategy. The reputation signal that matters is reply rate, not send volume. Concretely, this means your outreach sequence must be built around triggering replies: ask a specific question, reference a piece of the prospect's recent activity, or offer a data point that invites correction. Generic value propositions that generate opens but no replies will now actively harm your domain. The 2026 rules effectively force a return to list hygiene and message relevance—not because providers are being punitive, but because they have finally built filters that distinguish between automation and intent.

What we'd do next

Audit your sending domains today. Check your DMARC policy, verify SPF and DKIM alignment, and look at your complaint rate in Google Postmaster Tools. If you are above 0.3%, cut your list size and add the unsubscribe link before your next send. But do not stop at the surface-level checks. The shift to penalizing p=none is a signal that mailbox providers are no longer treating DMARC as a binary pass/fail on authentication. They are now scoring the intent behind your policy. A p=none record tells Google and Microsoft that you have not committed to a rejection stance, which they increasingly interpret as a willingness to tolerate spoofing or list mismanagement. That means your alignment checks must go deeper than “did SPF pass.” You need to verify that the envelope sender, the header From, and the DKIM signing domain all share the same organizational domain. If you are using a subdomain for tracking or a third-party sending service, confirm that their infrastructure does not break alignment on the main domain. Also, review your rua and ruf aggregate reports weekly, not monthly, to spot unauthorized senders early. A single compromised subdomain can drag your domain reputation down before you see the complaint rate spike.

This is not a one-time fix. The rules will keep tightening. Build the habit of checking your headers and complaint rates monthly. More importantly, treat your DMARC record as a living document. Every time you add a new tool, a new email template, or a new list segment, re-run a full authentication test. The cost of a misconfigured record is no longer just spam folder placement; it is a permanent reputation hit that takes months to recover. If you want a tool that handles the technical setup and flags deliverability risks before they hit your inbox rate, see how MiraReach handles this.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →