DMARC
Gmail's Enforcement Wave Is Here — And the Federal Government Already Showed Us What Comes Next
September 17, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

For most of 2024 and 2025, non-compliant bulk mail to Gmail addresses landed in a spam folder somewhere and quietly hurt a sender's reputation. That grace period is over. Starting in November 2025, Google began issuing hard SMTP rejections to senders who fail its authentication and spam-rate requirements, and the Gmail Email sender guidelines FAQ now states plainly that non-compliant traffic will experience disruptions including temporary and permanent rejections. For MSPs managing client domains, this is the moment the theoretical became operational.
The pattern is not new. The federal government ran this exact experiment starting in 2017, when the Department of Homeland Security ordered every civilian agency to adopt DMARC on a fixed timeline. Eight years of public compliance data from that mandate shows that publishing a DNS record is the easy part, and that mandates without ongoing enforcement and monitoring produce years of partial, fragile compliance rather than clean results.
What Changed in Gmail's Enforcement in November 2025?
Google moved from filtering non-compliant bulk mail into spam to rejecting it outright at the SMTP level. Messages that fail authentication or exceed spam-rate thresholds now bounce with specific error codes rather than silently disappearing into a folder the sender can't see. This applies to anyone sending 5,000 or more messages a day to personal Gmail and Googlemail addresses, and the enforcement is described in Google's guidance as gradual and progressive rather than an instant cutover.
The mechanics matter for how an MSP diagnoses a client complaint. Google's own guidelines require bulk senders to keep reported spam rates below 0.10% and never let them reach 0.30%, a threshold so tight that three complaints per thousand delivered messages can tip a domain into rejection territory, according to reporting on the Gmail bulk sender rollout. Microsoft followed a nearly identical path months earlier. Its own Tech Community announcement confirmed that after May 5, 2025, Outlook began routing non-compliant high-volume senders to Junk, with outright rejection following for domains that stayed uncorrected.
How Did Google and Microsoft Get to Hard Rejections?
Neither company moved without warning. Google announced its bulk sender requirements in October 2023, gave the industry a February 2024 start date for soft enforcement, and only flipped to permanent rejections after roughly twenty months of warnings sat unheeded by a meaningful share of senders. Microsoft's own guidance frames its rollout the same way, noting that stricter standards including mandatory SPF, DKIM, and DMARC settings were phased in deliberately to give senders room to adjust before the Junk-folder routing and eventual blocking took effect.
The requirements themselves are not exotic. They rest on standards that have existed for over a decade: SPF, DKIM, and DMARC, the last of which ties the other two together by requiring alignment between the visible From header and the authenticated sending domain. What changed is the consequence for ignoring them. A comparison of where the three major mailbox ecosystems and one major compliance regime have landed shows how tightly the thresholds now cluster:
| Requirement source | Volume trigger | Spam rate ceiling | Enforcement action |
|---|---|---|---|
| Gmail (Google) | 5,000+ msgs/day | 0.30% (target 0.10%) | Permanent SMTP rejection since Nov 2025 |
| Outlook/Hotmail (Microsoft) | 5,000+ msgs/day | 0.30% | 550 5.7.515 rejection since May 2025 |
| PCI DSS v4.0 | Any card-data processor | Not spam-rate based | DMARC at quarantine/reject required since March 2025 |
| Federal civilian agencies (BOD 18-01) | All .gov domains | Not spam-rate based | DMARC at p=reject required within one year of the 2017 directive |
What Does the Federal Government's DMARC Record Predict for MSP Clients?
It predicts a slow, uneven climb to compliance even under a binding legal mandate, followed by persistent technical decay that resurfaces years later. DHS's Binding Operational Directive 18-01, issued in October 2017, gave agencies 90 days to publish a monitoring-only DMARC record and one year to reach a full reject policy, according to the CISA directive itself. That one-year deadline was not quietly met.
At the 90-day checkpoint, independent analysis found that only 47.1% of covered domains had a DMARC record published at all, with nearly half of agencies not yet started, according to a contemporaneous review from Proofpoint's research team. By the one-year deadline, a Valimail study found that just 50% of covered .gov domains were fully compliant with a reject policy, and a quarter of federal domains still had no DMARC record in any form. Even among domains counted as compliant, a large share were "defensive" domains configured never to send mail, which the researchers noted is a far easier bar to clear than locking down an active, high-volume sending domain, as detailed in the Valimail federal compliance report.
The story does not end at the one-year mark. CISA later issued BOD 25-01 to extend DMARC baseline requirements specifically into Microsoft 365 and Google Workspace configurations, an acknowledgment that agencies had moved their mail into cloud platforms faster than their DNS hygiene had kept pace. A September 2025 survey of 713 U.S. government email domains by dmarcian, the DMARC management vendor, found that sixty percent of the domains involve SPF errors such as missing records, invalid syntax, or too many DNS lookups, according to dmarcian's own analysis, eight years after the original mandate. A legally binding directive with a hard deadline still left the majority of mandated domains with broken or fragile SPF records years later.
That is the pattern MSPs should expect to see repeat in the commercial world now that Gmail and Microsoft have their own version of a binding deadline. A record can exist and still be wrong. A policy can be set to enforcement and still leak legitimate mail if SPF and DKIM alignment were never fully mapped. Compliance is not a single project with a finish line, it is a maintenance obligation that decays without monitoring.
Where the Real Risk Sits for MSP Clients
Most SMB clients sending under 5,000 messages a day to Gmail addresses will tell themselves the bulk sender rules do not apply to them. That reading misses two things. Google's baseline authentication guidance, requiring at least SPF or DKIM and discouraging domain impersonation, applies to every sender regardless of volume, and marketing platforms, invoicing tools, and helpdesk software sending on a client's behalf can quietly push a domain over the 5,000-message threshold without anyone noticing.
The domains most exposed are the ones nobody is actively watching: legacy subdomains, decommissioned marketing tools still authorized in an old SPF record, and DMARC policies left at p=none since the day they were first configured. These are precisely the failure modes the federal survey data surfaced at scale, and they are invisible without regular scanning.
A practical response for an MSP looks like this:
- Inventory every client domain's current SPF, DKIM, and DMARC state, not just whether a record exists but whether it resolves cleanly and stays under SPF's 10-lookup limit.
- Move clients still sitting at
p=nonetowardp=quarantineand eventuallyp=reject, using aggregate report data to catch legitimate senders before locking the policy down. - Recheck authentication status on a recurring schedule rather than once at onboarding, since third-party sending tools change constantly and silently break alignment.
Where Should MSPs Start This Week?
The starting point is visibility, not a rewrite of every client's DNS in one sitting. A domain scan that surfaces SPF, DKIM, and DMARC status alongside policy strength turns an abstract compliance deadline into a prioritized punch list, which is the difference between reacting to a client's rejected invoice emails and getting ahead of the next enforcement wave. ActiScan's getting-started guide walks through running that first inventory across a client base in a single pass.
Once the gaps are visible, the fix work itself is standard DMARC hygiene: correcting SPF includes, adding missing DKIM selectors, and stepping policies up in controlled stages. What changes the economics for an MSP is doing this at scale across dozens or hundreds of client domains without manually checking each one by hand, which is where ongoing scanning earns its keep against a one-time audit. Firms evaluating that shift can compare plan tiers on the pricing page against the labor cost of doing this work manually per client.
Gmail's November enforcement wave will not be the last of its kind. Microsoft already followed Google's lead once, PCI DSS v4.0 folded DMARC into its own requirements in March 2025, and the federal government's eight-year experience says clearly that any mandate without continuous monitoring will drift back toward non-compliance. MSPs that treat this as a one-time cleanup will be back here again. Those that build recurring scanning into their standard offering, starting with a free signup to see where client domains stand today, will be the ones with an answer ready the next time a major mailbox provider flips the switch from warning to rejection.