# What does Outlook require from senders?

_Not the Junk Folder — Scott Anderson. Last reviewed 4 August 2026._

## Short answer

From 5 May 2025, domains sending more than 5,000 messages a day to Outlook.com, Hotmail.com or Live.com must pass SPF, DKIM and DMARC, with DMARC at p=none as the minimum and alignment on at least one of SPF or DKIM. Non-compliant mail was routed to Junk first, then rejected outright with a 550 5.7.515 error.

## Key facts

- Enforcement began on 5 May 2025 for senders of more than 5,000 messages per day to Microsoft consumer domains. [Microsoft's announcement](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730)
- SPF, DKIM and DMARC are all required. DMARC must be at least p=none, aligned to SPF or DKIM. [Microsoft's announcement](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730)
- Non-compliant mail is rejected with: 550 5.7.515 Access denied, sending domain does not meet the required authentication level. [Microsoft's announcement](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730)

Fifteen months after Gmail and Yahoo moved, Microsoft followed. The requirements are near-identical, which is the point: the two companies that between them run most of the world's consumer inboxes now agree on the minimum, and that minimum is authentication.

One difference is worth dwelling on. Google's enforcement mostly shows up as filtering. Microsoft's escalated to outright rejection, which produces a hard bounce with a specific error string — the rare case where a deliverability failure is actually visible to the sender.

## The bounce message to look for

If you've seen this in a bounce, the cause isn't ambiguous and the fix isn't guesswork.

**Rejection**

```
550 5.7.515 Access denied, sending domain [yourdomain] does not meet the required authentication level
```

The receiving server never evaluated your message. It refused the sending domain.

## What Microsoft requires

- **SPF** — A valid record listing every server permitted to send for your domain, published once, resolving cleanly.
- **DKIM** — A valid signature on outgoing mail, with the public key published under your selector.
- **DMARC at p=none or stronger** — Published at _dmarc.yourdomain, with the visible From: domain aligned to SPF or DKIM — ideally both.
- **Functional unsubscribe and list hygiene** — Microsoft's guidance also emphasises clear unsubscribe handling, valid recipient addresses and accurate sender identity. Those aren't hard technical gates but they shape whether you keep getting through.

## Gmail and Outlook side by side

|  | Gmail / Yahoo | Outlook consumer |
| --- | --- | --- |
| Enforcement began | 1 February 2024 | 5 May 2025 |
| Bulk threshold | 5,000 messages/day | 5,000 messages/day |
| Required of bulk senders | SPF + DKIM + DMARC, aligned | SPF + DKIM + DMARC, aligned |
| Required of everyone | SPF or DKIM, PTR, TLS, complaints under 0.3% | Authentication expected; volume senders enforced first |
| Failure looks like | Filtered to spam, quietly | Junk, then a hard 550 5.7.515 bounce |

## If you're under 5,000 a day

The formal enforcement targets high-volume senders, so a business sending a few dozen messages a day isn't in scope of the hard rejection. That is not the same as being safe.

Microsoft framed this as raising the floor for the whole ecosystem, and filtering for smaller senders has moved in the same direction. A small unauthenticated domain doesn't get rejected — it gets quietly junked, which is harder to detect and just as expensive.

> Volume is counted per day, not per month. One newsletter to a list you've been building for five years can put you over the threshold on a single Tuesday — the day, of course, when you most wanted the mail to arrive.

## What to do about it

1. **Check whether you're already failing** — Read your published SPF, DKIM and DMARC records. If DMARC is absent, you don't meet Microsoft's requirement, full stop.
2. **Search your bounces for 5.7.515** — If it's there, you have a dated, documented delivery failure and a precise cause — genuinely useful when you need to justify the fix to someone holding the budget.
3. **Authenticate every sender, then publish DMARC** — Same order as always: inventory, SPF, DKIM, then DMARC at p=none with reporting turned on.
4. **Tighten once the reports are clean** — Move to quarantine and then reject when your DMARC reports show only senders you recognise.

## Frequently asked

### Does this affect Microsoft 365 business mailboxes too?

The announced enforcement covers Microsoft's consumer domains — Outlook.com, Hotmail.com, Live.com. Microsoft 365 business tenants run their own filtering with similar expectations, so authenticating properly is the right move either way. It also matters in the other direction: plenty of your customers use a personal Outlook address.

### We got the 550 5.7.515 bounce. How fast can it be fixed?

The DNS changes themselves take an afternoon and propagate within hours. If DKIM has to be enabled on several platforms, allow a few days for the slowest vendor. The bounce stops as soon as the records satisfy the check.

### Is p=none really enough for Microsoft?

It satisfies the stated minimum. It also does nothing to stop anyone spoofing your domain, which is the reason to keep going to quarantine and then reject once your reports are clean. Meeting a requirement and being protected are two different achievements.

## Related

- https://notthejunkfolder.com/guides/gmail-sender-requirements
- https://notthejunkfolder.com/guides/microsoft-365-email-setup
- https://notthejunkfolder.com/guides/dmarc-p-none

---

Not the Junk Folder reviews small business email configuration — SPF, DKIM, DMARC and MX — and fixes what's broken. Free domain checker at https://notthejunkfolder.com/#check. Contact: hello@notthejunkfolder.com.
