emailrules.today
In forceAuthIn force 5 May 2025

Outlook rejects unauthenticated mail from high-volume senders

What are Outlook's requirements for bulk senders?

Global · Microsoft

In one sentence

Microsoft will bounce mail that is not authenticated — often with error 550 5.7.515.

Plain English

If you send about 5,000+ messages a day to Outlook.com, Hotmail or Live combined, Microsoft wants and , a record on your domain (even p=none counts for the requirement), and . Unlike Gmail’s quieter spam sorting, Microsoft often rejects bad auth with a bounce you can see in logs.

Why it matters. Bounces are visible. If your record is missing on the root domain, this is often the first provider that hurts loudly.

Dotted words open definitions. Full glossary.

What to do

Your move — not a lecture

Part platform, part you

The platform covers the mechanical bit. The judgement is still yours.

Your sets up and when you configure a branded sending domain, and that covers most of it.

Your part: The record. It lives in your own domain's and no can publish it for you, which is exactly why this is the requirement people fail.

What to do first

Run `dig +short TXT _.yourdomain.com` in a terminal. If it returns nothing and you clear 5,000 a day to Microsoft, your mail is bouncing right now.

You can skip this if: You send under 5,000 messages a day to Microsoft consumer addresses.

Who this applies to

Any domain sending 5,000 or more messages a day to Microsoft consumer addresses. Outlook.com, Hotmail and Live count together, which catches people who assume their Microsoft volume is small.

Checklist

  • 01Publish a record if you have none. Even p=none satisfies the requirement.
  • 02Confirm , not just presence: or has to match your , not your 's.
  • 03Watch for 550 5.7.515 in your bounce logs. Unlike Gmail, Microsoft tells you when it rejects you.
  • 04Count Outlook.com, Hotmail and Live as one volume, because Microsoft does.

That’s enough to act. Sources and exact wording are below for counsel, bosses, or AI tools that need a citation. Not legal advice.

Proof

Exact position, enforcement, sources

For records and people who will check you. Skip if Monday’s move is already clear.

The exact position

Microsoft requires domains sending 5,000 or more messages a day to Outlook.com, Hotmail and Live to pass both and , publish a record at minimum p=none, and align at least one of SPF or DKIM with the domain in the . Microsoft first announced routing non-compliant mail to Junk from 5 May 2025, then moved to outright rejection with SMTP error 550 5.7.515.

What happens if you do not

Enforced by hard rejection rather than silent filtering, which is unusually helpful: the bounce names the reason. Worth noting that Microsoft's own support page for the error carries no publication date, so the timeline comes from its announcement blog rather than the documentation.

Sources

  • Microsoft, Fix NDR error 550 5.7.515 in Outlook.com
    No publisher dateRead primary source
  • Microsoft, Strengthening Email Ecosystem: Outlook's New Requirements for High-Volume Senders
    No publisher dateRead primary source

History of this page

  • Re-verified against primary sources (bulk/auth/consent core).
  • Added. Microsoft's requirement had been missing while Gmail and Yahoo were covered, which was a real gap.

FAQ

Awkward questions

Who is this actually for?

People who ship email and are too busy to re-read every PDF: week-one marketers, lifecycle/CRM, deliverability, multi-country ops, DTC brands, agencies — on Klaviyo, Mailchimp, Braze, HubSpot, SFMC, or something else. Pick your tool and geos so product-specific pages only appear when they match. EU and UK are first-class filters. Not for people who sell tools about email and need a fake score to demo.

Why only ~40 rules? Isn’t that… thin?

On purpose. A wall of 400 undated “best practices” is how you look busy and still get burned. Every page needs a primary source we actually read. Thin and checkable beats fat and folklore. Europe, bulk inbox rules, measurement honesty, and protocol topics like BIMI/DMARC policy are on the shelf when we can cite them — not every Member State and not every vendor myth. Coverage map lists what we still refuse to invent.

Is this legal advice?

No. If it were, you’d have a billable hour and a longer PDF. This is a dated operator reference written by an email geek. Confirm anything high-stakes with counsel who knows your facts. Same for “will this make me compliant?” — no tool does that. Lawyers and judges do. We say what the sources say and what to do first on Monday.

Why no trust score out of 100?

Because we refuse to invent a number you can’t audit. Fake scores sell seed tests and panic. You get findings, dates, and links. If that feels less exciting than a red dial, good — you’re not the red-dial customer.

Why should I trust you more than my ESP’s blog?

ESPs sell seats. Seed-score vendors sell fear. AI invents citations when nobody watches. We sell nothing today — no pixels, no placement scores, no affiliate — so we can say when a tool is the problem. A human verifies, dates, and corrects in public. Tools may help draft; they do not ship unsourced claims. Check the primary links. Fail that test and leave.

Do I need an account?

No. Filters live in this browser and the URL. Share the link. That’s it. Accounts come later only if they earn it — not so we can nurture you about email.

I’m an agency. Where’s multi-client mode?

We tried a client-name CRM on the setup card. It made the product feel like work before it felt useful. Role filters + copy link + one-page brief (optional PDF title) is enough for now. Complexity comes back when the free shelf is habit, not before.

Is the quiet changelog a bug?

No. Quiet means nothing material moved. We don’t invent urgency so the homepage looks “alive.” Sticky risks still show what usually needs a person when the market is still.