RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The guide archive · 100 retrospective records ↗
Publisher Revenue Guide

The guide archive / Newsletters

Newsletters / From the guide · 3 October 2023 event · prepared 16 September 2026

A DMARC record became the entry fee two mailbox giants required

Google's October 2023 announcement and Yahoo's own requirements both point back to a DMARC record most small senders had never configured.

blog.googleprimary record

Gmail security, authentication and spam protection

Document
3 October 2023
Event
3 October 2023
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The revenue mechanism

On 3 October 2023, Google published a post announcing new Gmail requirements that would take effect the following February, and the post carries a supporting quotation from a Yahoo executive rather than a separate Yahoo announcement of its own. Yahoo's own sender requirements page confirms it adopted the same February 2024 start date and, critically, the same underlying technical demand: a published DMARC policy. DMARC, short for Domain-based Message Authentication, Reporting and Conformance, is a technical standard that tells a receiving mail server what to do with a message that fails the two older checks, SPF and DKIM, and it requires the sending domain to publish that instruction so any receiver can read it.

What the documents show

The standards body behind the protocol, DMARC.org, describes DMARC as building on SPF and DKIM by adding three elements: a link to the domain shown in a message's From: field, a published policy telling receivers how to treat a failure, and a reporting channel back to the domain owner. Yahoo's own page states the policy must be set to at least p=none, the least restrictive setting, meaning a sender is not required to instruct Yahoo to block or quarantine failing mail, only to publish a record that authentication can be checked against. Google's guidelines make the identical minimum requirement. Neither company's page requires the stricter p=quarantine or p=reject settings that would actually cause failing mail to be blocked.

The assumptions exposed

A record set to p=none satisfies both companies' stated minimum, but it does no enforcement work on its own; it only turns on reporting. A publisher who reads a bare DMARC requirement as proof that spoofing is prevented is over-reading a minimum threshold that both documents describe as a starting point, not an end state. The standard itself has continued to evolve after the 2023 announcement, and DMARC.org's own page notes updated core specifications published after the original 2015 document, a reminder that a sending domain's compliance is checked against whichever version of the standard a mailbox provider currently honours, not a fixed 2023 snapshot.

What to check before you rely on it

This is an editorial checklist, built from what the three cited documents state rather than a claim about deliverability outcomes. A publisher should confirm a DMARC TXT record actually resolves for the sending domain, understand that p=none alone does not stop spoofed mail from reaching recipients, and treat the reporting data DMARC generates as a tool to monitor abuse of the domain, not merely a box to tick once.

  • Does the DMARC record exist at the exact subdomain used for sending, not just the root domain?
  • Is the policy still set to p=none a year or more after setup, or has it been strengthened?
  • Is anyone actually reading the aggregate reports DMARC generates?

The requirement both companies describe is a floor for authentication, not a ceiling on the phishing risk a domain still carries.

Sources & reading trail

Gmail security, authentication and spam protection ↗

Google's own dated announcement, including Yahoo's supporting statement, establishing the coordinated timing of the requirement.

Source published: 3 October 2023 · Retrieved: 16 September 2026

Sender Best Practices ↗

States Yahoo's own DMARC requirement (at least p=none) alongside its February 2024 enforcement date.

Source published: Not established · Retrieved: 16 September 2026

DMARC.org overview ↗

Defines DMARC as a technical standard built on SPF and DKIM, and names the IETF working group and RFCs governing it.

Source published: Not established · Retrieved: 16 September 2026

Programme terms, standards and reports establish the entry; the assumptions reading is Publisher Revenue Guide editorial analysis. This retrospective draft does not imply the site published on the event date.