Outlook.com's requirements for high-volume senders
Microsoft now expects SPF, DKIM and DMARC from domains sending over 5,000 messages a day to Outlook.com, Hotmail and Live. What to check and fix.

On this page(8 sections)
- What Microsoft announced
- Recommended practices Microsoft listed
- How this compares with Gmail and Yahoo
- Checking your Microsoft-bound mail
- 1. Authenticate a test message
- 2. Check every stream
- 3. Watch Microsoft-specific signals
- What to do if your mail is landing in Junk
- Common gaps we see
- A Microsoft readiness checklist
- Bottom line
Gmail and Yahoo set the template in 2024; Microsoft followed for its consumer mailboxes in 2025. If you send meaningful volume to Outlook.com, Hotmail.com or Live.com addresses, you need SPF, DKIM and DMARC in place, and the reasons your mail might be junked or rejected there are now more predictable than they used to be.
What Microsoft announced
In April 2025, Microsoft published new requirements for high-volume senders to Outlook.com consumer mailboxes, effective May 5, 2025. The requirements apply to domains that send more than 5,000 messages per day to Microsoft's consumer services, which include addresses at outlook.com, hotmail.com and live.com.
The headline requirements for those senders:
| Requirement | Detail |
|---|---|
| SPF | Must pass for the sending domain |
| DKIM | Must pass |
| DMARC | Published with at least p=none, and must align with SPF or DKIM, preferably both |
Microsoft's announcement said that, after the enforcement date, non-compliant messages from high-volume domains would initially be routed to the Junk folder, with rejection planned for a later stage. Microsoft's guidance associates rejections of non-compliant mail with an SMTP response carrying the enhanced code 5.7.515, stating that the sending domain does not meet the required authentication level. Check Microsoft's current documentation for the latest enforcement status, since the plan was explicitly phased.
Recommended practices Microsoft listed
Beyond the hard requirements, the announcement grouped several practices as recommended for all senders, not only high-volume ones:
- A compliant From or Reply-To address that can receive replies, rather than an address that discards them.
- Functional unsubscribe links that are easy to find and work, for marketing and bulk mail.
- List hygiene, removing invalid addresses and recipients who do not engage, to keep bounce rates low.
- Transparent mailing practices: accurate subject lines, no deceptive content, and sending only to people who agreed to receive it.
Microsoft framed these as recommendations, but they map closely onto how its filtering already evaluates senders. Ignoring them hurts placement even when authentication passes.
How this compares with Gmail and Yahoo
If you already meet the Gmail and Yahoo bulk sender requirements, you meet Microsoft's authentication requirements too. The differences are mostly in emphasis:
| Topic | Gmail and Yahoo (bulk) | Microsoft Outlook.com (high volume) |
|---|---|---|
| Volume threshold | Around 5,000/day to personal accounts | More than 5,000/day to consumer mailboxes |
| SPF and DKIM | Both required | Both required |
| DMARC | At least p=none |
At least p=none |
| Alignment | SPF or DKIM aligned with From | Aligned with SPF or DKIM, ideally both |
| One-click unsubscribe | Required (RFC 8058) for marketing | Functional unsubscribe recommended |
| Spam rate threshold | Published (0.3%) | Not published as a number |
Note the last row. Microsoft does not publish a complaint-rate threshold the way Gmail and Yahoo do, but complaint data still drives reputation there, through user "Junk" clicks and its Junk Mail Reporting Program.
Checking your Microsoft-bound mail
1. Authenticate a test message
Send to an Outlook.com account you control and view the message source. Look for an Authentication-Results header showing results such as:
Authentication-Results: spf=pass (sender IP is 192.0.2.25) smtp.mailfrom=bounce.example.com;
dkim=pass (signature was verified) header.d=example.com;
dmarc=pass action=none header.from=example.com;
Confirm all three pass and that the SPF or DKIM domain shares your From domain's organizational domain.
2. Check every stream
The 5,000-per-day threshold is per domain, but authentication is per message. A small vendor sending a few hundred messages a day as your domain still needs to pass, because your domain as a whole is a high-volume sender. Review DMARC aggregate reports from Microsoft for unaligned sources.
3. Watch Microsoft-specific signals
- SNDS (Smart Network Data Services) shows how Outlook.com rates IPs you send from, if you operate dedicated IPs.
- JMRP (Junk Mail Reporting Program) sends you copies of messages that Outlook.com users mark as junk.
- Bounce logs for Microsoft destinations should be checked for
5.7.515or other 5.7.x codes mentioning authentication.
What to do if your mail is landing in Junk
Authentication is necessary but not sufficient. If messages pass SPF, DKIM and DMARC and still land in Junk at Outlook.com:
- Look at complaint feedback through JMRP. A spike usually traces back to a specific campaign or list segment.
- Check volume patterns. Sudden jumps from a new IP or domain look suspicious; ramp gradually.
- Review list sources. Old or purchased addresses produce bounces and spam trap hits that hurt reputation.
- Make replies possible. A From or Reply-To that bounces is explicitly listed among Microsoft's recommendations.
- Use SNDS data to see whether a specific IP has a problem.
If you believe your mail is being filtered incorrectly after fixing the basics, Microsoft provides a sender support process for Outlook.com deliverability issues; it expects you to show that authentication and list practices are in order.
Common gaps we see
- DMARC missing entirely on domains that send moderate volume, because "we are not a marketer." The requirement is volume-based, not purpose-based.
- Vendor mail without aligned DKIM, passing SPF and DKIM for the vendor's own domain.
- Noreply addresses that discard all replies, contrary to Microsoft's recommended practice.
- Subdomains forgotten in DMARC planning, with marketing on a subdomain sending unaligned mail.
A Microsoft readiness checklist
- SPF and DKIM pass for every stream sending as your domain.
- DMARC published, at least
p=none, with aggregate reports read regularly. - SPF or DKIM, ideally both, aligned with the From domain.
- Reply-capable From or Reply-To addresses.
- Working unsubscribe links in marketing mail, honored promptly.
- Bounce and inactive-address cleanup on a schedule.
- SNDS and JMRP enrollment if you send from dedicated IPs.
- Bounce monitoring for
5.7.515and other authentication-related codes.
Bottom line
Microsoft's requirements for domains sending more than 5,000 messages a day to Outlook.com, Hotmail and Live mailboxes, effective May 5, 2025, line up closely with Gmail and Yahoo: SPF, DKIM and DMARC with alignment. Meet those, follow Microsoft's recommended list and reply practices, and use SNDS and JMRP to watch how Outlook.com sees you.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


