Deliverability

Why email authentication is now mandatory at large mail providers (2024)

Email authentication has been effectively mandatory since 2024: large mail providers require anyone who sends email to prove, with SPF, DKIM and DMARC, that a message really comes from their domain. If that's missing, the mail is rejected or labelled as spam. In plain language: without correct authentication, your mail increasingly struggles to arrive. Below you'll read what those requirements involve, why they exist and how to make sure your mail simply lands in the inbox.

By the Mailflux team Published on

What does "email authentication mandatory" mean?

There's no law forcing you to authenticate your email. But the large mail providers (the parties that together manage most of the world's inboxes) sharpened their admission rules considerably at the start of 2024. Anyone delivering messages to their users must demonstrate that they are a legitimate sender. In practice that amounts to an obligation: if you don't do it, your mail no longer reliably reaches the recipient.

The reason is simple. Phishing and spoofing (mail posing as someone else) were too easy for years. By enforcing authentication, the receiving servers make it a lot harder to mail in someone else's name.

Overview of sent messages with their delivery status

Why these requirements matter

For you as a sender it comes down to one thing: arriving. A message that isn't authenticated no longer gets the benefit of the doubt at large mail providers. It disappears into spam, or is rejected outright.

That affects more than just those who send newsletters. Ordinary business mail too (quotes, invoices, appointment confirmations) falls under the same filters. If you send in larger volumes, stricter rules apply, but the basic signals are checked for everyone. What that means for those who occasionally do a larger mailing is covered in newsletter or bulk mail ending up in spam.

What the requirements concretely involve

The tightened rules revolve around a handful of points. For ordinary senders it mainly comes down to the first two; those who send in larger volumes also deal with the rest.

  • Authenticate your mail with SPF and DKIM, and set a policy for your domain with DMARC.
  • Ensure valid reverse DNS (PTR) on the sending server, so the name and IP address belong together.
  • Keep your spam complaints low. Too many recipients marking your mail as spam counts heavily.
  • Make unsubscribing easy with newsletters or larger sends, preferably with one click.

The good news: you set up the first two points once, and the third and fourth take care of themselves if you only mail to people who expect your mail. If you don't send bulk mail yourself, you mainly need to have your authentication in order.

How it works: SPF, DKIM and DMARC

Authentication leans on three arrangements you set through your DNS. Together they form the proof the recipient wants to see.

  • SPF defines which servers are allowed to send on behalf of your domain. The recipient checks whether your message comes from such an authorised server.
  • DKIM puts a digital signature on your outgoing mail. With it the recipient can verify that the message wasn't altered in transit.
  • DMARC tells the receiving server what to do if SPF or DKIM don't check out, and if you wish, sends you reports about who is mailing on your behalf.

You need all three; they complement each other. How to set them up correctly in one go is described step by step in setting up SPF, DKIM and DMARC.

What to watch out for

  • Set up all three, not just one. SPF alone is no longer enough; DMARC belongs with it.
  • Start cautiously with DMARC. Begin with a policy that only monitors and reports, and tighten it only once you're sure all legitimate mail authenticates properly.
  • Don't forget your other sending channels. If an accounting package or newsletter service mails in your name, they must also fall under your SPF and DKIM.
  • Check regularly. DMARC reports show whether something goes wrong or whether someone is abusing your domain.

If your mail still gets stuck despite everything, then why does my email end up in spam helps you further with the remaining causes.

How Mailflux takes care of this for you

At Mailflux you don't have to dive into these rules. We manage SPF, DKIM and DMARC and guard the IP reputation of our sending servers, so your mail meets what the large mail providers expect. On top of that, every plan filters with machine learning against spam, phishing and malware.

You work on your own domain, hosted in Europe and GDPR-compliant, from €4.99 per mailbox per month (billed annually). That way you're in order with the authentication requirements without tinkering with DNS records yourself.

Ready to get started?

Professional email on your own domain, hosted in Europe and GDPR-compliant. Request your mailbox with no obligation.

Get started

FAQ

Frequently asked questions

Is email authentication really legally mandatory?

Not by law, but in practice it is. The large mail providers have required senders to authenticate with SPF, DKIM and DMARC since 2024. If you don't comply, your mail is rejected or treated as spam, so the effect is the same as an obligation.

Do I have to do this too if I only send little mail?

Yes. Stricter rules apply to large sends, but the basic signals are checked for everyone. Even a handful of business mails a day arrives better with correct SPF, DKIM and DMARC. It's a one-time setup and after that you have peace of mind.