DeliverabilityChecklist

Gmail Bulk Sender Requirements: A Practical Campaign Checklist

A practical guide to Gmail sender requirements covering SPF, DKIM, DMARC, one-click unsubscribe, spam rates, consent, and gradual sending volume.

Updated August 8, 20266 min readReviewed against linked primary sources
Direct answer

Authenticate the visible sending domain, align SPF or DKIM with the From domain through DMARC, provide easy unsubscribe mechanisms, send only to expected recipients, suppress negative signals promptly, and increase volume gradually while monitoring current Google guidance.

What you will be able to do
  • Treat Google's baseline sender rules as an operating minimum, not a threshold to work around.
  • Verify SPF, DKIM, DMARC, alignment, DNS, and message headers before launch.
  • Provide both a clear in-message opt-out and one-click unsubscribe where required.
  • Monitor recipient expectations, complaints, bounces, and volume changes after the send.

Deliverability begins before the subject line. Mailbox providers evaluate whether the sending domain is authenticated, whether recipients expect the message, how they respond, and whether leaving the list is easy.

Google's requirements are a useful operating baseline even when a campaign is below the bulk-sender threshold. This checklist translates the technical requirements into decisions a campaign owner can verify before scheduling.

Know which requirements apply

Google requires all senders to Gmail accounts to use SPF or DKIM authentication, valid DNS, TLS, valid message formatting, and a spam rate below 0.3 percent. Google recommends remaining below 0.1 percent and avoiding 0.3 percent or higher.

A sender delivering more than roughly 5,000 messages to personal Gmail accounts in a day must meet additional requirements, including SPF and DKIM, DMARC, From-domain alignment, and one-click unsubscribe for marketing and subscribed messages. Treat the threshold as a classification, not a target to work around.

Authenticate the visible sending domain

SPF identifies servers allowed to send for a MAIL FROM domain. DKIM adds a cryptographic signature associated with a domain. DMARC checks whether the domain visible in the From address aligns with the domain authenticated by SPF or DKIM and defines a policy for failures.

Mailbox providers recommend authenticating email for reliable delivery. In a managed sending workflow, the customer should verify a domain and choose a sender address from that domain rather than borrowing a platform-owned identity.

  • Publish the required DKIM DNS records.
  • Configure a custom MAIL FROM domain when appropriate.
  • Publish a DMARC record and monitor reports.
  • Use a From address that aligns with authenticated domains.
  • Test the received message headers before a live campaign.

Make unsubscribing easier than reporting spam

Marketing messages should include a clear unsubscribe link in the email body. Bulk senders to Gmail must also support one-click unsubscribe through the List-Unsubscribe and List-Unsubscribe-Post headers.

The visible link and one-click header serve related but different purposes. Include both where required. Process the request promptly and suppress the address from future eligible campaigns.

One-click unsubscribe headers
List-Unsubscribe: <https://example.com/unsubscribe/token>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

Protect reputation with audience discipline

Authentication proves who sent the email; it does not prove that the recipient wanted it. Send to people who expect the message, confirm addresses when they subscribe, remove invalid recipients, and respect prior opt-outs.

Monitor hard bounces, complaints, and Gmail Postmaster Tools. Suppression should happen before the next campaign, not after another delivery attempt. Mailbox providers expose different complaint signals, so direct reputation monitoring remains important.

Increase volume gradually

A newly verified domain does not immediately have a stable sending reputation. Google advises increasing sending volume slowly, sending at a consistent rate, and avoiding sudden spikes. The larger the intended volume, the more gradual the ramp should be.

Campaign software should enforce warm-up and account-level limits. A marketer should see a clear scheduling blocker rather than learning about a reputation problem after the campaign launches.

Pre-send deliverability checklist

This article is operational guidance, not legal advice. Requirements can change, and organizations should review the current mailbox-provider rules and laws that apply to their recipients.

  1. Verify the sending domain and approved From address.
  2. Confirm SPF, DKIM, DMARC, alignment, DNS, and TLS readiness.
  3. Confirm audience permission and campaign relevance.
  4. Remove invalid, unsubscribed, bounced, and complained addresses.
  5. Include visible and one-click unsubscribe where required.
  6. Review the subject, From name, body, links, and postal information.
  7. Check planned volume against warm-up and account limits.
  8. Monitor delivery, bounce, complaint, and Postmaster signals after launch.

Frequently asked questions

Is SPF alone enough for a Gmail bulk sender?

No. Google's additional requirements for bulk senders include both SPF and DKIM, DMARC, alignment of the visible From domain with an authenticated domain, and one-click unsubscribe for applicable messages. Check the current official guidance before launch.

Does email authentication guarantee inbox placement?

No. Authentication establishes sending identity. Recipient permission, engagement, complaints, list quality, content, volume patterns, and mailbox-provider decisions still affect deliverability.

Put the guide into practice

Prepare a campaign behind a verified sender

AttuneMail checks audience readiness, approval state, sending identity, suppression, and campaign capacity before launch.

21 days, no credit card