Outlook Sender Requirements for Bulk Mail: What Microsoft Checks
The outlook sender requirements make SPF, DKIM and DMARC mandatory for any domain sending more than 5,000 emails per day to hotmail.com, live.com and outlook.com addresses. Fail those checks and the mail is rejected. Microsoft spelled it out in its announcement for high-volume senders, in effect since May 5, 2025, and an April 29, 2025 update swapped Junk routing for outright rejection. So if your January 2026 review of holiday campaigns shows Hotmail and Outlook.com bounces well above the Gmail ones, look here first. Below: who is covered, what each check has to do, how to read the error code and what to fix first.
Who counts as a high-volume sender for Outlook?
Any domain whose daily mail to Outlook.com consumer addresses goes over Microsoft’s threshold. That means personal mailboxes at hotmail.com, live.com and outlook.com, not every business inbox Microsoft happens to host.
The limit is counted per day, not as a monthly average. A store whose regular newsletters sit comfortably under the line can cross it during a seasonal promotion, and from that moment the stricter treatment applies to its domain.
What SPF, DKIM and DMARC must do under the Outlook.com bulk sender rules
You need all three protocols in place, and DMARC has to align with the From domain through SPF or DKIM. Alignment, in plain terms: the domain your subscribers see in the From line matches the one that passed authentication.
- SPF passes for the sending domain, so the DNS record lists every server allowed to send on its behalf.
- DKIM signature validates, which proves nobody altered the message in transit.
- DMARC record is published and aligned - this is the microsoft dmarc requirement that most often trips up shops sending through a shared domain.
A message can pass SPF and DKIM separately and still fail, and that is the usual reason why DMARC alignment fails. In MailCraft, the SPF/DKIM/DMARC setup wizard walks you through the records, and a custom sending domain is available on Pro and higher plans. Forwarding and mailing lists can break alignment too, so Microsoft recommends ARC.
What does 550 5.7.515 Access denied mean?
Outlook rejected the message because the sending domain did not meet the required authentication level. Under Microsoft’s updated policy, non-compliant mail gets this response instead of landing in Junk.
Which is why the problem shows up in campaign reports as bounces, not as low engagement. A message filtered to spam still counts as delivered, a rejected one gets logged as a failure - and there’s your gap against Gmail in the holiday results. Seeing a temporary 4xx instead? Different issue, and we cover it in our explanation of why large sends get deferred.
Recommended practices beyond authentication for Hotmail deliverability
Microsoft also recommends valid sender addresses, a working unsubscribe and clean lists, and it reserves the right to act against senders who ignore them. None of this sits inside the hard rejection rule. But it shapes hotmail deliverability once authentication is sorted:
- Valid From and Reply-To addresses that can actually receive replies.
- An easy, clearly visible unsubscribe link in marketing and bulk mail.
- List hygiene, with invalid addresses removed regularly.
In my view hygiene deserves a proper look right after a peak season. That’s when old segments tend to get reactivated, and when you find out how spam traps reach lists that looked safe. MailCraft takes care of the routine part with hard bounce auto-cleanup, ISP feedback loops and the List-Unsubscribe one-click header.
How Outlook differs from the Gmail and Yahoo rules
Same authentication base across all three providers. Where they part ways is what else is mandatory and what happens when you fail. At Outlook, only authentication is mandatory, and failure ends in rejection with 5.7.515.
Gmail asks for more on the mandatory side: bulk senders must also use TLS, add one-click unsubscribe headers and keep user-reported spam in check. According to the Gmail sender guidelines FAQ, non-compliant messages might be rejected or delivered to spam, and Gmail started ramping up enforcement on such traffic in November 2025. One compliant setup covers all three, so fix the domain once.
A post-holiday check against the Outlook sender requirements
Start the January review with authentication. It is the only part that triggers outright rejection, so work in this order:
- Pull bounces for hotmail.com, live.com and outlook.com.
- Look for the 5.7.515 code among them.
- Verify SPF, DKIM and DMARC alignment on the From domain.
- Test the unsubscribe link and header from a real message.
- Clean out hard bounces before the next send.
Tweaking subject lines or pruning segments first? Wasted time when the domain itself is being refused. Once the outlook sender requirements are met at the DNS level, the remaining steps protect your reputation instead of rescuing it.
FAQ
Do the Outlook rules apply if I send below the high-volume threshold?
The mandatory rejection applies to domains above Microsoft’s daily limit for consumer mailboxes. Smaller senders are not exempt from filtering, though, and a seasonal peak can push a shop over the line. Set up all three protocols now and that risk is gone.
Does error 550 5.7.515 mean my domain is blocklisted?
No. The code says the message failed the authentication requirements, not that your domain or IP sits on a blocklist. You fix it in DNS and in the sending setup - a delisting request won’t help.
Why does forwarded mail fail DMARC at Outlook?
Forwarding can break DMARC alignment, because the message arrives from a server your records do not list, or with altered content. ARC preserves the original authentication checks, so legitimate forwarded mail is not wrongly flagged.


