Let's grow your business. 2 new positions just opened Wednesday, 9 September. Book a free call today.
Uncategorised 13 min read

Outbound Email Deliverability at Scale (2026)

Outbound Email Deliverability at Scale: Email, SMS and voice outreach from an AI sales agent converging into a booked calendar appointment.
Email, SMS and voice outreach from an AI sales agent converging into a booked calendar appointment.

Outbound email deliverability at scale means passing SPF, DKIM and DMARC alignment, keeping spam complaints under Google’s 0.30% ceiling (0.10% is the recommended target), and honouring one-click unsubscribe under RFC 8058 within two days. Since 5 May 2025, Microsoft rejects non-compliant bulk mail outright instead of filing it to junk.

The short answer: at real volume, deliverability is an infrastructure and consent problem, not a copywriting problem. Fix authentication, domain separation and list quality in that order — a better subject line will not save a domain Microsoft is already rejecting at the SMTP handshake.

If reply rates are sliding and you cannot tell whether the fault is copy, list or infrastructure, start with infrastructure. It is the layer enterprise procurement now audits before letting a vendor near a shared inbox, and it is the layer most revenue teams have not touched since IT set the domain up. We book AI-driven sales appointments for scale-up and enterprise clients across Australia and the US — 50,769+ since 2017 — and the single biggest predictor of a client’s reply rate is whether their sending infrastructure was built for volume or inherited from a startup’s first cold-email tool.

What Google, Yahoo and Microsoft actually require

Three mailbox providers set the rules that matter for outbound at scale, and as of 2026 they broadly agree with each other.

Google’s bulk sender guidelines have applied since 1 February 2024 to anyone sending more than 5,000 messages a day to Gmail and Googlemail addresses. They require SPF and DKIM on the sending domain, a published DMARC record (minimum policy p=none, aligned to SPF or DKIM), a spam rate that stays below 0.30% in Google Postmaster Tools, and one-click unsubscribe on every marketing message via the List-Unsubscribe and List-Unsubscribe-Post headers. Google’s own guidance is blunt about the target: stay under 0.30%, but aim for under 0.10%.

Yahoo’s sender requirements mirror Google’s almost line for line — SPF and DKIM, a DMARC policy of at least p=none with alignment, a spam rate under 0.3%, and one-click unsubscribe. Yahoo is explicit on the mechanism and the clock: it recommends the RFC 8058 POST method and requires that unsubscribe requests be honoured within two days.

RFC 8058 is the actual specification both providers point to. It defines the List-Unsubscribe header (an HTTPS URI identifying the recipient and list) and List-Unsubscribe-Post (a fixed value telling the mail client it can fire a one-click POST, no login, no second click, no landing page with a hidden re-subscribe checkbox). If your unsubscribe still routes through a marketing-preferences page, you do not have one-click unsubscribe by this definition, regardless of what your ESP’s dashboard tells you.

Microsoft came later and hit harder. Microsoft’s own rollout announcement confirms that from 5 May 2025, Outlook, Hotmail and Live.com began requiring SPF, DKIM and a DMARC record with passing alignment from any domain sending 5,000 or more messages a day — and non-compliant mail is not filtered to junk, it is refused at the SMTP level with a 550 5.7.515 “access denied” response. That distinction matters operationally: a message in spam is a deliverability problem you can measure and fix; a message Microsoft never accepted never shows up in any report you own.

How it works

How an AI sales agent books your appointments

01

Six channels feed in

Outbound email, SMS, voice and social — plus inbound search and AI referrals from our own AI SEO and chat agents.

02

Your list or CRM

Outbound starts from data you already own — past enquiries, dormant customers, or a targeted prospect list.

03

Qualified against your rules

Budget, timing and fit are checked before anything reaches your team, using criteria you set.

04

Booked into your calendar

Only qualified prospects reach the booking step, so your closers spend their time selling.

Six channels feed one agent. It handles contact, follow-up and qualification, and a human only joins once a qualified call is on the calendar.

MAKE MORE SALES.

Pay-Per-Result pricing — We scale sales HARD aligned to your interests, better than anyone else.

What changed in 2026: rejection, not foldering

Microsoft’s May 2025 shift to outright rejection is well documented, down to the exact error code senders see. What is less settled is where Google and Yahoo are heading next, and we want to be precise about the difference between what these platforms have announced and what the deliverability industry is reporting about them.

As of this writing, Google’s own sender guidelines page still describes non-compliance as risking that a message “might not be delivered as expected, or might be marked as spam” — not a guaranteed hard rejection. A cluster of deliverability vendors (dmarcian, Redsift, PowerDMARC and others publishing 2026 compliance guides) report that Gmail moved from temporary 421 deferrals to permanent 550 rejections for repeat non-compliant senders starting around November 2025, and that a p=none DMARC policy is increasingly treated as a yellow flag rather than a pass at volume, even though it technically still satisfies the published minimum. We have not found a Google or Yahoo announcement that states this in those terms — it is vendor reporting on observed enforcement behaviour, not a platform policy change we can point you to. Treat it as directionally credible and operationally worth acting on, not as gospel to quote to your CISO as an official rule.

What is not in dispute: publishing DMARC at p=none and stopping there is a starting position, not an end state. Every major mailbox provider’s own documentation frames p=none as a monitoring phase before you move to p=quarantine or p=reject. At real outbound volume, a domain that has sat at p=none for years reads as unmanaged, and unmanaged is exactly the signal these systems are built to filter on.

Want this done for you? We book qualified sales appointments on a Pay-Per-Result basis — you only pay for calls that actually land in your calendar.

Domain and infrastructure architecture for senders at real volume

Most reply-rate problems at scale are not about what you are sending. They are about what else is sending from the same place.

Separate your domains by traffic type. Cold outbound, transactional mail (receipts, password resets, booking confirmations) and lifecycle/nurture mail behave completely differently from a mailbox provider’s point of view — different expected volumes, different engagement rates, different complaint tolerances. Send all three from one domain and a spike in cold-outbound complaints drags down the domain your customers rely on to receive their password reset. Most mature senders run at least three sending domains or subdomains: one for cold outbound, one for transactional, one for lifecycle marketing.

Use subdomains deliberately, not by accident. A subdomain (outbound.yourcompany.com versus notify.yourcompany.com) gets its own DKIM keys and can carry its own DMARC posture while still inheriting some of the parent domain’s trust. The mistake we see most often is a company that already has this structure but never told their outbound tool, which quietly reverts to sending from the root domain the moment someone reconfigures a CNAME.

Warm up new domains and IPs on a realistic curve. A brand-new sending domain or IP has no reputation, and mailbox providers treat sudden volume from an unfamiliar source as the single strongest spam signal there is. Deliverability practitioners and ESPs (Postmark and Mailgun both publish this guidance) converge on a similar shape: start at a few hundred sends a day to your most engaged contacts, increase gradually over four to six weeks rather than days, and watch spam-complaint and bounce rate at every step rather than following a fixed calendar regardless of what the metrics say. Skip the ramp and you can burn a domain’s reputation in the first week of a new campaign.

A shared IP pool is not a smaller dedicated IP — it behaves differently. On a shared pool, your deliverability partly rides on every other sender using that pool; a smaller sender can borrow reputation from well-behaved neighbours, but bad actors on the same pool drag everyone down. A dedicated IP puts you in full control — nobody else’s mistakes touch you, but you start from zero and build the reputation yourself. ESP guidance generally holds that a dedicated IP only earns its keep once you are sending consistent six-figure monthly volume; below that, a shared pool with a good reputation usually outperforms an under-warmed dedicated one.

Buying more inboxes is treating the symptom. Spinning up another twenty mailboxes to spread volume around does not fix a spam-complaint problem, a consent problem or a copy problem — it just gives the same underlying issue more surface area to fail on, and more domains to eventually burn. If your current infrastructure is already flagged, adding capacity accelerates the decline rather than reversing it.

SMS deliverability: the parallel compliance track

Email has mailbox providers gatekeeping delivery; SMS has carriers, and the registration requirements differ by country. In the US, unregistered A2P 10DLC brand and campaign registration is what the major carriers filter against — an unregistered 10-digit long code sending application-to-person traffic gets throttled or blocked regardless of message content, because the carrier has no vetted record of who is sending or why. In Australia, the relevant mechanism is SMS sender ID registration, which sits alongside the Communications Alliance’s Reducing Scam Calls and Scam SMS industry code (C661:2022), registered with the ACMA. These are not interchangeable: a US A2P registration does nothing for an Australian carrier, and an AU sender ID does nothing on a US 10-digit long code. We cover both registration processes in detail on the pages linked above — the short version for this page is that SMS deliverability at scale is a registration and carrier-trust problem before it is a content problem, exactly like email.

If we can’t make you money, we don’t deserve yours.

Pay-Per-Result pricing — performance-based alignment.

50,769+
AI-booked appointments
Average sales lift
Pay-Per-Result
Performance-based alignment

The uncomfortable point: deliverability is downstream of consent

Here is the part of this page that is easy to skip past. You can get SPF, DKIM and DMARC perfectly aligned, run a textbook six-week warm-up, split your domains cleanly by traffic type, and still land in the spam folder — because the platforms are not measuring your infrastructure in isolation, they are measuring what recipients do when your mail arrives. A list you cannot evidence consent for will generate complaints no amount of authentication fixes will offset, because Gmail, Yahoo and Outlook do not know or care whether the recipient technically opted in somewhere three years ago. They measure the click on “report spam,” not your intent when you bought or scraped the list.

This is also where the legal and technical layers meet without being the same thing. Consent, disclosure and opt-out rules under frameworks like the US TCPA or Australia’s Spam Act are a separate legal question from whether Gmail accepts your mail — we cover that layer, and the enterprise procurement questions that come with it, in our AI outbound compliance checklist for enterprise. The two layers reinforce each other: a list built without evidenced consent is both a legal exposure and a deliverability liability, and fixing one without the other leaves you still exposed.

It is also why we run outbound on a permission-and-relevance-first basis for corporate sales teams rather than maximising raw list size. A smaller list of contacts who match a real buying signal produces a lower complaint rate than a large, loosely-sourced one, and complaint rate is the metric every mailbox provider on this page is actually watching.

Diagnostic table: matching the symptom to the cause

Symptom Most likely cause What to check first
Sudden bounce spike across all providers List decay, a bad import, or a broken DNS record (SPF/DKIM record edited or expired) DNS record validity for the sending domain; date and source of the list segment you just sent to
Gradual reply-rate decay over weeks Domain or IP reputation eroding from rising complaint rate, not a copy problem Spam-complaint trend in Google Postmaster Tools and your ESP’s complaint dashboard over the same period
Deliverability fine everywhere except one provider That provider’s specific alignment or DMARC policy requirement not met, or IP-specific reputation issue DMARC aggregate reports filtered to that provider; whether that provider requires stricter alignment than the others
Fine everywhere except Microsoft (Outlook/Hotmail/Live) Missing or misaligned DMARC record, since Microsoft rejects outright rather than foldering Whether DMARC passes and is aligned, specifically for Outlook.com/Hotmail/Live.com recipients; look for 550 5.7.515 in bounce logs
High open rate, near-zero replies Not a deliverability problem at all — message is landing, targeting or offer is the issue Segment-level reply rate by list source and by offer, before touching infrastructure

Frequently asked questions

What counts as a “bulk sender” under Google and Yahoo’s rules?

Both providers apply their requirements to anyone sending more than 5,000 messages a day to their domains, counted in aggregate across your sending infrastructure, not per campaign. Google states this threshold directly in its sender guidelines. Below that line the requirements are still best practice, but enforcement is looser.

What spam complaint rate is actually safe?

Under 0.30% is the hard ceiling both Google and Yahoo publish; Google’s own guidance recommends staying under 0.10% and treating 0.30% as a line you should never approach, not a target to hover near.

Does my DMARC policy need to be set to p=reject?

Not to meet the published minimum — p=none with passing alignment satisfies Google and Yahoo’s stated requirements. In practice, deliverability vendors report that mailbox providers increasingly treat a long-parked p=none policy as a negative signal at volume, though this is industry reporting rather than a stated platform rule. Moving toward p=quarantine once your aligned mail is confirmed clean is the safer long-term position.

How long do I have to action an unsubscribe request?

Yahoo’s sender requirements specify two days from request to actioned. RFC 8058 defines the one-click mechanism itself — a compliant List-Unsubscribe-Post header lets the mail client fire the request with no further clicks from the recipient.

Should cold outbound and transactional email share a sending domain?

No. A complaint spike on a cold-outbound campaign will drag down the reputation of any transactional mail sharing that domain, including receipts and booking confirmations your existing customers rely on. Separate domains or well-managed subdomains contain the damage to the traffic type that caused it.

Is a dedicated sending IP always better than a shared pool?

Not below real volume. A dedicated IP gives you full control of your own reputation but starts from zero and needs its own warm-up; a well-managed shared pool can outperform an under-warmed dedicated IP for a sender who is not yet sending consistent six-figure monthly volume.

Is SMS deliverability governed by the same rules as email?

No — SMS runs on carrier registration rather than mailbox-provider authentication. In the US that is A2P 10DLC brand and campaign registration; in Australia it is sender ID registration under the ACMA-registered scam-SMS industry code. The two are not transferable across markets.

Pay-Per-Result appointments

See if we’re a fit

We book qualified sales appointments for you and you pay on results, not retainers. Our booking page asks a few quick questions so you find out in two minutes whether that model suits your business.

  • 50,769+ appointments booked without cold calling.
  • Pay-Per-Result pricing — you pay for booked, qualified calls.
  • Pick your own time on our live calendar, no phone tag.

View all articles

Pay-Per-Result · No retainers

Turn this into booked sales calls.

Our AI agents — trained on 50,769+ booked appointments — fill your calendar with pre-qualified buyers. You only pay when calls land.

Keep reading

Related on Leads Now AI

The thesis behind everything we do

Why Pay-Per-Result is the only marketing pricing model that aligns the agency with you

Leads Now AI is a 100% Pay-Per-Result marketing agency. You only pay when a qualified booked appointment lands on your calendar — priced one of two ways — pay-per-result, at roughly 1–5% of your closed-deal value per appointment, or a revenue share of 10–20% of the sales we help you generate. Both bill on outcomes. Not on clicks. Not on lead-form fills. Not on retainer months. Not on “strategy hours.” If the calendar stays empty, you owe zero. See full pricing →

1. Incentives align

The agency only succeeds when you succeed. We eat the cost of bad ad creative, bad lists, ICP mismatches and no-shows. You never pay for our learning curve.

2. Self-selecting shortlist

Only an agency confident in its delivery can operate this model. The pool of Pay-Per-Result agencies is tiny precisely because most agencies can’t survive on it. Pick from the agencies who can.

3. Cost cannot detach from revenue

Sized to 1–5% of closed-deal value, your acquisition cost stays sustainable across LTV bands. A $500-membership business and a $50,000-engagement business can both run the model profitably.

4. No retainer trap

The standard engagement carries no monthly retainer — nothing arrives on your invoice regardless of outcome. No 6 or 12-month lock-in, no clawback on appointments already delivered, cancel any time with 7 days notice. Early-stage businesses that need the sales systems built first are quoted scoped groundwork up front, never a standing fee.

5. De-risks the pilot

Test before commitment. A small scope-based setup fee covers hard build costs; everything after that is purely outcome-linked. There’s no “we’ll see how it performs after $30k of spend.”

6. Forces agency discipline

If our AI agents qualify poorly, if our reminders fail, if our no-show recovery doesn’t fire — we eat the cost. That’s why the show-rate benchmark sits at 60–75%+.

The volume argument

A fully-ramped human SDR produces on the order of $200,000 a year. They work one conversation at a time, sleep, take leave, and cap out at a territory. Our agents work every lead in the list in parallel — responding in seconds, following up indefinitely without getting bored, and adding capacity without adding headcount.

At 100 qualified booked appointments a month against a $5,000 average deal value, that is $500,000 of booked pipeline every month — roughly what one SDR produces in two and a half years.

Read that precisely: booked pipeline means appointments multiplied by your average deal value. It is not closed revenue — closing is your side of the table, and your close rate decides what lands. The inputs above are a worked example; we size them to your actual deal economics before quoting. What we can evidence on our own numbers: 1,425 qualified appointments in 9 months from our own outbound (3.9% list-to-appointment), 50,769+ appointments delivered since 2017, database reactivation converting 4.4–8.9% on dormant CRM lists, and a 60–75%+ show rate.

The proof: 50,769+ AI-booked sales appointments delivered since 2017 across coaches, consultants, RTOs, course creators, finance brokers and B2B service firms in Australia, USA, UK, Canada, NZ and Europe. Named clients include Sam Tajvidi (121 Brokers), Marcus Wilkinson (Iron Body), Foundr, SheSells.online and Lambda Academy. Wikidata Q139846230. See full Pay-Per-Result pricing →