Gmail security, authentication and spam protection
- Document
- 3 October 2023
- Event
- 3 October 2023
- Retrieved
- 16 September 2026
The revenue mechanism
On 3 October 2023, Google published a post announcing new Gmail requirements that would take effect the following February, and the post carries a supporting quotation from a Yahoo executive rather than a separate Yahoo announcement of its own. Yahoo's own sender requirements page confirms it adopted the same February 2024 start date and, critically, the same underlying technical demand: a published DMARC policy. DMARC, short for Domain-based Message Authentication, Reporting and Conformance, is a technical standard that tells a receiving mail server what to do with a message that fails the two older checks, SPF and DKIM, and it requires the sending domain to publish that instruction so any receiver can read it.
What the documents show
The standards body behind the protocol, DMARC.org, describes DMARC as building on SPF and DKIM by adding three elements: a link to the domain shown in a message's From: field, a published policy telling receivers how to treat a failure, and a reporting channel back to the domain owner. Yahoo's own page states the policy must be set to at least p=none, the least restrictive setting, meaning a sender is not required to instruct Yahoo to block or quarantine failing mail, only to publish a record that authentication can be checked against. Google's guidelines make the identical minimum requirement. Neither company's page requires the stricter p=quarantine or p=reject settings that would actually cause failing mail to be blocked.
The assumptions exposed
A record set to p=none satisfies both companies' stated minimum, but it does no enforcement work on its own; it only turns on reporting. A publisher who reads a bare DMARC requirement as proof that spoofing is prevented is over-reading a minimum threshold that both documents describe as a starting point, not an end state. The standard itself has continued to evolve after the 2023 announcement, and DMARC.org's own page notes updated core specifications published after the original 2015 document, a reminder that a sending domain's compliance is checked against whichever version of the standard a mailbox provider currently honours, not a fixed 2023 snapshot.
What to check before you rely on it
This is an editorial checklist, built from what the three cited documents state rather than a claim about deliverability outcomes. A publisher should confirm a DMARC TXT record actually resolves for the sending domain, understand that p=none alone does not stop spoofed mail from reaching recipients, and treat the reporting data DMARC generates as a tool to monitor abuse of the domain, not merely a box to tick once.
- Does the DMARC record exist at the exact subdomain used for sending, not just the root domain?
- Is the policy still set to p=none a year or more after setup, or has it been strengthened?
- Is anyone actually reading the aggregate reports DMARC generates?
The requirement both companies describe is a floor for authentication, not a ceiling on the phishing risk a domain still carries.
Sources & reading trail
Google's own dated announcement, including Yahoo's supporting statement, establishing the coordinated timing of the requirement.
Source published: 3 October 2023 · Retrieved: 16 September 2026
States Yahoo's own DMARC requirement (at least p=none) alongside its February 2024 enforcement date.
Source published: Not established · Retrieved: 16 September 2026
Defines DMARC as a technical standard built on SPF and DKIM, and names the IETF working group and RFCs governing it.
Source published: Not established · Retrieved: 16 September 2026
Programme terms, standards and reports establish the entry; the assumptions reading is Publisher Revenue Guide editorial analysis. This retrospective draft does not imply the site published on the event date.