大手プロバイダが求めるメール認証の要件と、満たさないと何が起きるのかを整理します。
最終更新: 2026年6月(各社の要件は変わることがあります。最新情報は各社の公式ガイドラインをご確認ください)
Google と Yahoo は2024年から、Microsoft も続いて、メールを送る側に対して認証の設定を実質的に義務化しました。狙いは、なりすましや迷惑メールを受信側で見分けやすくすることです。当初は未対応メールが迷惑メール扱いされる程度でしたが、その後は条件を満たさないメールを恒久的に拒否する方向へと厳格化が進んでいます。
各社で細部は異なりますが、共通して求められる中心的な要件は次のとおりです。
p=none の DMARC レコードが必要です。これらは特に、1日に大量(おおむね数千通以上)を送る「一括送信者」に強く適用されます。
Google と Yahoo が2024年に先行して一括送信者向けの要件を導入し、Microsoft も大手送信者向けに同様の要件を適用しました。さらに各社は、認証を満たさないメールを迷惑メール送りにとどめず、恒久的に拒否する段階へと進めています。つまり「届かない」ことが現実的なリスクになっています。なお、PCI DSS のような業界基準でもメール認証が要件化されており、決済まわりを扱う事業者には別途の動機もあります。
一括送信者向けの厳格な基準は大量送信者が対象ですが、少量の送信者にも基本的な認証(SPF・DKIM・DMARC)の整備は推奨されており、未対応だと迷惑メール扱いされやすくなります。また、送信量にかかわらず、認証が無いドメインはなりすましの標的になりやすいという別のリスクがあります。送信量の多寡を問わず、整備しておく価値があります。
p=none のまま放置されていないかこれらは、自社ドメインを入力すれば無料で確認できます。
What the major inbox providers require from senders — and what happens to your mail if you don't comply.
Last updated: June 2026 (requirements change; always check each provider's current official guidelines)
Starting in 2024, Google and Yahoo effectively mandated email authentication for senders, with Microsoft following suit. The goal: make spoofed and spam mail easier to detect at the receiving end. Initially, non-compliant mail was sent to spam. The trend since then has been toward permanent rejection — mail that doesn't meet requirements simply doesn't arrive.
Details vary by provider, but the shared baseline requirements are:
p=none record is required.These requirements apply most strictly to "bulk senders" — typically those sending thousands of messages per day.
Google and Yahoo led in 2024 with requirements for bulk senders; Microsoft has applied equivalent rules for large senders. All three are moving beyond spam-folder treatment toward permanent rejection for non-compliant mail. "Your mail won't arrive" is now a realistic risk. Additionally, industry standards like PCI DSS now require email authentication for payment-related senders.
The strictest rules target high-volume senders, but basic authentication (SPF, DKIM, DMARC) is recommended for all senders — unauthenticated domains are more likely to be treated as spam. More importantly, regardless of how much mail you send, a domain without authentication is a prime target for spoofing attacks. The risk exists independent of your sending volume.
p=noneYou can verify all of these instantly by entering your domain below.
Free instant report on your SPF, DMARC, DKIM, and MX configuration. No sign-up required.
Check for free