For about twenty years, email authentication was a thing you could skip. SPF shipped as an RFC in 2006. DKIM followed in 2007. DMARC — the protocol that ties them to the address your recipient actually sees — has been a published RFC since 2015. All three were available, well documented, and almost entirely optional. You could run a mail server that authenticated nothing, and the internet would carry your mail anyway.
Then, in about fourteen months, the three largest consumer mailboxes made authentication the price of admission. And here’s the part worth sitting with: they did it without changing SMTP by a single byte.
Nobody could force this, so nobody did
The reason authentication stayed optional for two decades isn’t that the protocols were bad. It’s that email is federated, and federation has no bouncer. There is no central authority that can flip a switch and say “unauthenticated mail is no longer allowed.” SMTP was designed in an era when every mail server trusted every other mail server, and that trust was baked so deep into the architecture that you cannot legislate it out from any one point. Every attempt to fix email — SPF, DKIM, DMARC, SMTP-over-TLS, the whole alphabet — was an addition bolted onto a protocol that still, underneath, accepts mail from anyone claiming to be anyone.
So adoption was voluntary, and voluntary meant decorative. Domains published v=DMARC1; p=none to make an auditor’s checklist turn green, and p=none tells receiving servers to do exactly nothing. The record existed. The spoofing continued. For years the honest summary of DMARC deployment was “widely adopted, rarely enforced,” and there was no mechanism anywhere to change that.
Except there was. It had just been sitting unused.
The mailbox providers were always the authority
Here’s the thing the standards bodies couldn’t do and three companies could: refuse the mail at the door.
A mail sender has no leverage. A mail receiver has all of it. And the receivers that matter — the inboxes where your customers, your users, your password resets actually land — are not spread across ten thousand independent servers anymore. They’re concentrated in a handful of enormous consumer mailbox operators. If Gmail, Yahoo, and Outlook all decide your mail needs to be authenticated to reach their users, that is, functionally, a global mandate. Not because anyone passed a rule, but because those three control the destinations you can’t afford to miss.
That’s what happened. It wasn’t a standards upgrade. It was the receivers discovering they’d been holding a veto the whole time.
Google and Yahoo moved first, jointly, with requirements that took effect in February 2024. The line they drew was volume: if you send roughly 5,000 or more messages a day to their users, you’re a “bulk sender,” and bulk senders have to clear a specific bar. Both SPF and DKIM, set up and passing. A DMARC record, at minimum p=none. DMARC alignment, meaning the authenticated domain has to match the domain in the From header your recipient sees. One-click unsubscribe on marketing mail, implemented the real way — the List-Unsubscribe-Post header from RFC 8058, with opt-outs honored within two days. And a spam complaint rate held below 0.3%, with Google openly telling people to aim for under 0.1%.
Even the smallest sender didn’t get off free: everyone, at any volume, now needs at least one of SPF or DKIM, valid forward-and-reverse DNS on their sending IPs, and TLS on the wire. The 5,000-a-day line just marks where the full checklist kicks in.
And they enforced it like people who’d thought about blast radius. February 2024 started with temporary failures on a slice of non-compliant mail — bounce-and-retry, not permanent loss — and the rejection percentage ramped through the spring. By June 1, 2024, the one-click unsubscribe requirement carried teeth of its own. It was a dial, turned slowly, not a cliff.
Then in April 2025, Microsoft joined. The blog post has the bureaucratic title these things always get — “Strengthening Email Ecosystem: Outlook’s New Requirements for High-Volume Senders” — and the same shape as the Google/Yahoo rules: more than 5,000 messages a day to Outlook.com, Hotmail, and Live addresses, and you need SPF and DKIM passing and DMARC at p=none or stronger, aligned with at least one of them. Enforcement began May 5, 2025. Microsoft first said it would be gentler about the stick — non-compliant bulk mail routed to the Junk folder, rejection at some later date — and then, days before the deadline, changed its mind: from May 5, non-compliant high-volume mail is rejected outright, bouncing with a 550 5.7.515 that names authentication as the reason.
Three mailboxes, fourteen months, one de facto standard. No RFC required.
What they actually require isn’t what the headlines say
Everyone calls this “the DMARC requirement,” and that framing is a little bit of a lie.
A DMARC record at p=none satisfies the mandate. And p=none, as I never tire of pointing out, stops zero spoofing — it’s a policy of “observe and take no action.” So if the point were to protect you from being impersonated, requiring p=none would be theater. It wouldn’t move the needle on a single spoofed invoice.
The point isn’t to protect you. The point is to make you legible.
What these mandates really require is that your mail carry a cryptographic identity — SPF and DKIM passing, aligned to your visible From domain — so the receiver has something stable to attach a reputation to. The DMARC record is how you tell them where to send the reports and, eventually, how aggressively to act. The parts with real teeth are the ones nobody puts in the headline: alignment, which is the actual anti-spoofing mechanism and the thing that quietly breaks legitimate senders who route through platforms they never aligned; and the 0.3% complaint rate, which is a reputation threshold, not an authentication one. You can pass every cryptographic check and still get throttled for annoying people.
So the honest description is that the big providers didn’t mandate security. They mandated accountability. They made you sign your mail so that when it’s garbage, they know whose garbage it is. That’s a more modest claim than “email is now secure,” and it’s the true one.
A good outcome, achieved the uncomfortable way
I want to be fair about this, because the result is genuinely good. This is the most effective push for email authentication in twenty years, full stop. Domains that ignored every best-practice blog for a decade set up SPF, DKIM, and DMARC in a panicked week in early 2024 because their marketing mail suddenly started bouncing at Gmail. Nothing — no RFC, no awareness campaign, no compliance framework — ever moved adoption the way a rejection notice did.
And it worked precisely because it wasn’t a standard. Standards ask. Three companies controlling the inboxes that matter don’t have to ask. They raised the cost of being unauthenticated until authentication was cheaper, and the market did the rest in months.
That’s the tension I can’t quite resolve. The federated, anyone-can-run-a-mail-server internet couldn’t fix its own authentication problem in two decades of trying. An oligopoly of mailbox providers fixed most of it in just over a year, by flexing the leverage federation was never supposed to let anyone have. The outcome is better mail. The mechanism is three companies deciding what reaches your inbox — and discovering they can make the whole internet comply.