Skip to content
Not the Junk Folder

What does Outlook require from senders?

Scott Anderson · Last reviewed

Short answer

From 5 May 2025, domains sending more than 5,000 messages a day to Outlook.com, Hotmail.com or Live.com must pass SPF, DKIM and DMARC, with DMARC at p=none as the minimum and alignment on at least one of SPF or DKIM. Non-compliant mail was routed to Junk first, then rejected outright with a 550 5.7.515 error.

Key facts

Fifteen months after Gmail and Yahoo moved, Microsoft followed. The requirements are near-identical, which is the point: the two companies that between them run most of the world's consumer inboxes now agree on the minimum, and that minimum is authentication.

One difference is worth dwelling on. Google's enforcement mostly shows up as filtering. Microsoft's escalated to outright rejection, which produces a hard bounce with a specific error string — the rare case where a deliverability failure is actually visible to the sender.

The bounce message to look for

If you've seen this in a bounce, the cause isn't ambiguous and the fix isn't guesswork.

Rejection

550 5.7.515 Access denied, sending domain [yourdomain] does not meet the required authentication level

The receiving server never evaluated your message. It refused the sending domain.

What Microsoft requires

SPF
A valid record listing every server permitted to send for your domain, published once, resolving cleanly.
DKIM
A valid signature on outgoing mail, with the public key published under your selector.
DMARC at p=none or stronger
Published at _dmarc.yourdomain, with the visible From: domain aligned to SPF or DKIM — ideally both.
Functional unsubscribe and list hygiene
Microsoft's guidance also emphasises clear unsubscribe handling, valid recipient addresses and accurate sender identity. Those aren't hard technical gates but they shape whether you keep getting through.

Gmail and Outlook side by side

Gmail / YahooOutlook consumer
Enforcement began1 February 20245 May 2025
Bulk threshold5,000 messages/day5,000 messages/day
Required of bulk sendersSPF + DKIM + DMARC, alignedSPF + DKIM + DMARC, aligned
Required of everyoneSPF or DKIM, PTR, TLS, complaints under 0.3%Authentication expected; volume senders enforced first
Failure looks likeFiltered to spam, quietlyJunk, then a hard 550 5.7.515 bounce

If you're under 5,000 a day

The formal enforcement targets high-volume senders, so a business sending a few dozen messages a day isn't in scope of the hard rejection. That is not the same as being safe.

Microsoft framed this as raising the floor for the whole ecosystem, and filtering for smaller senders has moved in the same direction. A small unauthenticated domain doesn't get rejected — it gets quietly junked, which is harder to detect and just as expensive.

What to do about it

  1. 01

    Check whether you're already failing

    Read your published SPF, DKIM and DMARC records. If DMARC is absent, you don't meet Microsoft's requirement, full stop.

  2. 02

    Search your bounces for 5.7.515

    If it's there, you have a dated, documented delivery failure and a precise cause — genuinely useful when you need to justify the fix to someone holding the budget.

  3. 03

    Authenticate every sender, then publish DMARC

    Same order as always: inventory, SPF, DKIM, then DMARC at p=none with reporting turned on.

  4. 04

    Tighten once the reports are clean

    Move to quarantine and then reject when your DMARC reports show only senders you recognise.

Frequently asked

Does this affect Microsoft 365 business mailboxes too?

The announced enforcement covers Microsoft's consumer domains — Outlook.com, Hotmail.com, Live.com. Microsoft 365 business tenants run their own filtering with similar expectations, so authenticating properly is the right move either way. It also matters in the other direction: plenty of your customers use a personal Outlook address.

We got the 550 5.7.515 bounce. How fast can it be fixed?

The DNS changes themselves take an afternoon and propagate within hours. If DKIM has to be enabled on several platforms, allow a few days for the slowest vendor. The bounce stops as soon as the records satisfy the check.

Is p=none really enough for Microsoft?

It satisfies the stated minimum. It also does nothing to stop anyone spoofing your domain, which is the reason to keep going to quarantine and then reject once your reports are clean. Meeting a requirement and being protected are two different achievements.

Find out where your domain actually stands.

The checker reads your real records in a few seconds. The review works out whether they cover everything you send.