Microsoft backed down six days before the deadline

by Francis Rozange | Sep 8, 2026 | Email Marketing

On 2 April 2025, Microsoft announced that domains sending more than five thousand messages a day to Outlook.com and Hotmail would have to authenticate their mail. SPF, DKIM, DMARC at p=none minimum, aligned on one of the two. Enforcement on 5 May.

On 29 April, six days before the deadline, Microsoft updated its post. Non-compliant messages would not be rejected: they would go to the junk folder.

That quiet correction says more about the real state of the installed base than all the documentation around it.

What was announced, and what was delivered

The initial threat was rejection at the door, with an explicit SMTP code still documented today:

550 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.

A message rejected with that code never enters. The sender receives a non-delivery report, which is unpleasant but perfectly clear.

What was delivered is something else: the junk folder. The message enters, it is stored, it is not read, and nobody is told. Not the recipient, who will not go looking, and not the sender, who counts that delivery as a success.

From the sender’s point of view, the second penalty is far worse than the first: it is invisible. A rejection teaches you something. Junk folder placement teaches you nothing, and lets you carry on.

Why that retreat was inevitable

Microsoft did not back down out of kindness. It backed down because mass rejection on 5 May would have broken legitimate flows in large numbers, and the responsibility for that breakage would have been its own.

Google took almost two years to take the same step: the rules published in October 2023 for February 2024 only produced systematic rejections from November 2025, when Google announced “temporary and permanent rejections”.

Two years between announcement and enforcement, at the best-equipped player in the market. That delay is the true measure of the installed base’s inertia.

What Microsoft does not publish

The contrast with the other two operators is sharp on two points.

No quantified complaint rate is published for bulk senders. Google and Yahoo both state 0.30 percent. Microsoft, nothing. So you do not know at what point you are at fault with the world’s third operator.

No technical unsubscribe standard is required. Where Google and Yahoo impose the one-click mechanism with a stated deadline, Microsoft recommends a working, easy-to-find unsubscribe link. That is a common-sense requirement, not a verifiable one.

Microsoft does, however, restate a rule many senders break without knowing: do not exceed ten DNS lookups in the SPF record. That is not an in-house recommendation, it is a requirement of the standard since 2014, and the most banal authentication failure in the trade.

Do not confuse two Microsoft mechanisms

One confusion comes up in every Outlook discussion, and it wastes time.

On one side, the requirements for volume senders to consumer Outlook.com and Hotmail mailboxes: that is what this article covers.

On the other, the Bulk Complaint Level, a score from 0 to 9 assigned by Exchange Online Protection to bulk mail arriving at Microsoft 365 business customers. The default threshold is 7, the standard preset policy drops to 6, the strict one to 5.

The first mechanism concerns you as a sender. The second concerns your customers’ settings, over which you have no control, and it explains why the same message lands in the inbox at one company and in junk at another, with nothing having changed on your side.

July 2026: a signal going dark

Microsoft operates a network data service, SNDS, which shows IP address owners what the filter sees: volumes, complaint rates, and until now hits on its spam traps.

As of 22 July 2026, trap hit counts no longer appear in the report. The stated reason is protecting the integrity of anti-abuse systems.

The reasoning holds: a trap counter is also a calibration tool for anyone trying to avoid them. But the honest sender loses the one signal that told them, unambiguously, that their collection was polluted. That leaves treating the problem where it starts, in list hygiene itself.

What to do tomorrow morning

Look at your sending logs and search for code 5.7.515. If it appears, some of your messages are being refused at Outlook’s door, and you may have known it without knowing it.

Then compare, on the same send, your reported delivery rate at Outlook and your measured engagement at Outlook. A marked gap between the two is the signature of junk folder placement, the penalty that does not announce itself.

And take the general lesson from this episode: between what an operator announces and what it enforces there is a delay, an implicit negotiation with the installed base, and sometimes a climbdown. Building your deliverability on announcements means building on a calendar that moves.

Sources


LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.

Cart