If your cold email isn't authenticated, Microsoft and Gmail will now treat it as spam. Since May 2025, Microsoft refuses unauthenticated mail over 5,000 messages a day. Gmail requires SPF, DKIM, and DMARC from bulk senders. And both want your spam complaint rate under 0.10%. That's not a marketing problem. It's a technical one, and it's now a competitive advantage.
The regulatory floor moved, and most SDR stacks are still standing on the old one
For years, deliverability was a volume game. Send enough, rotate enough domains, and enough mail landed. That worked because the inbox providers hadn't drawn a hard line.
They have now. Microsoft's 5,000-per-day threshold is the clearest signal yet: if you're sending at scale without authentication, you're not a sender they want. Gmail's requirements are stricter on paper. SPF, DKIM, and DMARC aren't optional for bulk senders. They're the price of entry.
Here's the part most founders miss. The 0.10% spam rate isn't a target you aim for. It's a ceiling you stay under. At 10,000 sends a month, that's 10 complaints. Total. One badly targeted list can blow that in a morning.
We've written before about how Google and Microsoft closed the volume loophole. The short version: p=none used to be a free pass. It isn't anymore. If your DMARC record is still sitting at p=none with no enforcement, you're telling the inbox providers you don't care whether your mail is spoofed. They believe you.
What's changed structurally is that enforcement now happens at the point of delivery, not after a reputation problem surfaces. Microsoft and Gmail are rejecting or throttling unauthenticated bulk mail before it reaches a spam folder, which means the old playbook of "send, measure, clean up" no longer has a measurement phase. You either pass the authentication check at the gateway or your mail never enters the funnel. That collapses the feedback loop most SDR stacks depend on.
It also shifts the burden upstream. Domain warm-up, subdomain separation, and alignment between your From address and your DKIM signing domain are no longer deliverability tactics — they're infrastructure requirements. A misaligned record doesn't degrade performance gradually. It fails outright.
Most teams haven't rebuilt for this. They're still optimizing subject lines and send times while the gate they're trying to walk through has already closed. The fix isn't a tool. It's re-architecting how your outreach authenticates before it ever leaves your stack.
What the regulatory setup actually looks like
Three records. One alignment check. No shortcuts.
- SPF — lists the servers allowed to send on your domain's behalf. Keep it under 10 DNS lookups or it breaks silently.
- DKIM — cryptographically signs each message. If your ESP rotates keys and you haven't updated the record, your signature fails and nobody tells you.
- DMARC — tells the receiver what to do when SPF or DKIM fails. Start at p=none to monitor, move to p=quarantine, then p=reject. Most senders never get past step one.
Alignment is the bit people skip. Your From: domain has to match the domain in your SPF and DKIM records. If you're sending through a third-party tool with a different return-path, you can pass SPF and still fail DMARC. The inbox providers don't care that it's technically valid. They care that it's aligned.
A customer running outbound to UK accountancy firms had SPF and DKIM configured correctly. Their DMARC was p=none. They were landing in spam on roughly 40% of sends to Microsoft 365 inboxes. The fix wasn't a new domain or a warmer inbox. It was moving DMARC to p=quarantine and fixing a misaligned return-path. Two hours of work. Deliverability went from 60% to 94% over the following week.
Spam rate is the metric that actually decides your fate
Authentication gets you through the door. Spam rate decides whether you stay in the room.
Google Postmaster Tools shows your spam rate if you've set it up. Most SDRs haven't. If you're sending more than a few hundred emails a week and you don't know your spam rate, you're flying blind. The 0.10% threshold is enforced. Cross it consistently and your mail starts going to spam regardless of how clean your authentication is.
What drives spam complaints? Three things, in order:
Wrong list. If you're emailing people who never opted into anything remotely related to your product, they'll mark you as spam. That's not a deliverability problem. It's a targeting problem.
Wrong message. A generic pitch to a specific persona reads like spam because it is spam. Personalisation isn't a nice-to-have. It's a spam-rate control.
Wrong frequency. Three follow-ups in a week to someone who didn't reply to the first one is a complaint waiting to happen. We've seen teams run seven-touch sequences in 10 days and wonder why their domain reputation tanked.
We've written about how state privacy laws affect cold email compliance. The regulatory layer is getting thicker, not thinner. Authentication is the part you can fix today without a lawyer.
Why this is a competitive advantage, not just a compliance cost
Most of your competitors haven't done this work. They're still sending from a domain with p=none, no alignment, and a spam rate they've never checked. Their emails are landing in spam and they don't know it.
If you fix your authentication and keep your spam rate under 0.10%, you're not just compliant. You're visible. Your emails land in the primary inbox while theirs sit in the promotions tab or worse. That's not a marginal gain. It's the difference between outbound that works and outbound that burns budget.
The reason this gap persists is structural, not accidental. Authentication is a one-time engineering task: publish SPF, deploy DKIM signing, align both under a DMARC policy, then move the policy from p=none to p=quarantine to p=reject. Once it's done, it's done. Spam-rate discipline is the opposite — it's an operational commitment that has to survive every campaign, every list import, every new hire who thinks "more volume" is the answer. Providers evaluate reputation continuously, not at signup, so a single bad send can undo months of careful work. That asymmetry is why so many teams stall at p=none: the first half is a project, the second half is a habit.
There's also a compounding effect most senders miss. Authentication and engagement aren't separate scores — they feed each other. A verified domain earns more trust from the filter, which improves placement, which drives opens and replies, which further strengthens your sender reputation. Compliant senders get pulled upward by a flywheel. Non-compliant senders get pushed down by the inverse, and the decline is gradual enough that they rarely notice until deliverability is already gone.
The technical setup takes an afternoon. The discipline to keep spam rates low takes ongoing attention. Most teams will do the first and ignore the second. That's your opening.
What we'd do next
Check your DMARC record. If it says p=none, move it to p=quarantine this week. Set up Google Postmaster Tools and Microsoft SNDS if you haven't. Then look at your last 1,000 sends and ask how many people would have marked you as spam if they'd bothered to click the button.
That last question matters more than the first two, because authentication is now the floor, not the differentiator. Google and Microsoft have effectively made SPF, DKIM, and DMARC alignment table stakes for anyone sending at volume to their users. Passing those checks gets your mail delivered to the inbox. It does not keep it there. What keeps it there is engagement — opens, replies, and the absence of complaints — and that is a behavioral signal no DNS record can fake.
So the sequence for the next thirty days looks like this:
- Fix the record first. Move DMARC from p=none to p=quarantine, then to p=reject once you've confirmed nothing legitimate is breaking. Monitor the aggregate reports during the transition; a misconfigured subdomain or a third-party tool sending on your behalf will surface there before it surfaces as a delivery failure.
- Instrument the receiving side. Google Postmaster Tools and Microsoft SNDS give you reputation and spam-rate data that your own sending platform cannot see. If you are not reading them weekly, you are flying blind on the only metrics the filters actually weight.
- Audit for intent, not just volume. Pull your last 1,000 sends and segment them by whether the recipient had a plausible reason to expect your message. Cold outreach that survives 2026 is not the kind that technically complies — it is the kind that a reasonable person would not report.
- Cut the dead weight. Suppress anyone who has not engaged across your last several campaigns. Low engagement drags your domain reputation down faster than a high complaint rate, and it is the failure mode most senders never diagnose because nothing bounces.
If you want to see how MiraReach handles authentication checks and spam-rate monitoring before you send, give MiraReach a try. We built it so you never send a message that fails the regulatory floor.
— Mira