Microsoft Bulk Sender Requirements 2026: Outlook Now Rejects Your Cold Email
Microsoft bulk sender requirements 2026, explained properly: what triggers a 550 5.7.515 rejection, and why compliant cold email still lands in Junk.
Here is the bounce that sent you looking:
550 5.7.515 Access denied, sending domain [yourdomain.com]
does not meet the required authentication levelThat is the Microsoft bulk sender requirements working as designed in 2026. Your mail was refused at the door. Not filtered, not delayed. Refused, permanently, before a human being had any chance to see it.
And here is the part almost nobody writes about. If your reply rates have quietly collapsed at Microsoft addresses but you are not seeing that bounce, you have a completely different problem, and every checklist on the first page of Google is going to fix the wrong thing.
So this is a guide to what the rules actually say, who they actually apply to, and why the majority of B2B cold email that dies at Microsoft dies for reasons the requirements never mention.
What the Microsoft Bulk Sender Requirements Actually Say
Microsoft's high-volume sender policy applies to any domain sending 5,000 or more messages per day to Microsoft consumer addresses: outlook.com, hotmail.com, and live.com. The count is measured against the domain in your 5322.From address, and it includes mail that a third-party platform sends on your behalf using your domain.
If you cross that line, three things must be true:
- SPF passes. Your DNS lists the servers authorized to send as you.
- DKIM passes. Your messages carry a valid cryptographic signature.
- DMARC exists and aligns. Minimum policy of
p=none, aligned to SPF or DKIM, ideally both.
Enforcement started on 5 May 2025. The original announcement said non-compliant mail would be routed to Junk. Microsoft revised that on 2 May, three days before go-live, to hard rejection instead, which is where the 550 5.7.515 comes from. dmarcian's breakdown tracks that shift well.
Alongside the hard requirements, Microsoft published a set of expectations it enforces at its own discretion: a working From and Reply-To that reflects your real sending domain, a visible unsubscribe on anything marketing-shaped, active list hygiene and bounce management, honest subject lines and headers, and documented consent. Microsoft reserves the right to apply additional filtering to senders who ignore these repeatedly.
That is the whole published policy. You can implement it in an afternoon. Which is exactly why it is not your problem.
There Are Two Microsofts, and You're Probably Fighting the Wrong One
This is the distinction that the entire first page of search results misses.
Microsoft runs two separate mail systems, and they behave nothing alike.
Outlook.com is the consumer service. Personal accounts on outlook.com, hotmail.com and live.com. This is where the bulk sender requirements above apply, and where the 5,000/day threshold is measured.
Microsoft 365 is the corporate service. Exchange Online Protection and Defender for Office 365, sitting in front of the mailbox of every prospect whose email address ends in their company's own domain. There is no published sender checklist for this system. None. It runs on scoring, and the scores are configured per tenant.
Now think about who you are actually emailing. A VP of Revenue Operations at a 400-person software company does not receive business mail at hotmail.com. She receives it inside her employer's Microsoft 365 tenant. Your entire addressable market on the Microsoft side sits behind the system with no checklist.
Here is how to tell which fight you are in:
| What you see | Which system | Actual cause | Can you fix it? |
|---|---|---|---|
550 5.7.515 hard bounce | Outlook.com consumer | Authentication failing at 5,000+/day on that domain | Yes, in a day. It is DNS. |
| Silent Junk placement at company domains | Microsoft 365 EOP | Bulk Complaint Level at or above the tenant's threshold | Partly. It is behavior, not DNS. |
| Nothing. No bounce, no reply, at some companies only | Defender Strict preset | Tenant quarantines at a lower threshold | Mostly no. |
Most B2B cold email problems are row two. Every article ranking for this keyword is about row one.
Gmail, Yahoo and Microsoft: What Is Now Universal
The three providers have converged, and it is worth seeing the requirements side by side because the differences matter more than the similarities.
| Gmail | Yahoo | Microsoft (Outlook.com) | |
|---|---|---|---|
| Bulk threshold | 5,000/day | 5,000/day | 5,000/day |
| SPF + DKIM | Required | Required | Required |
| DMARC | Required, p=none min | Required, p=none min | Required, p=none min |
| Alignment | Required | Required | Required |
| One-click unsubscribe | Required (RFC 8058) | Required (RFC 8058) | Expected on marketing mail |
| Spam complaint ceiling | 0.30%, target under 0.10% | 0.30% | 0.30% commonly cited |
| Failure mode | 550 permanent rejection | Spam folder, then blocking | 550 permanent rejection |
Two things on that table deserve more than a row.
Gmail's enforcement changed character in November 2025. When the requirements launched in February 2024, non-compliant mail got a 421 temporary deferral, which is a warning shot. Your sending platform retries, some of it gets through, and you have time to notice. As of November 2025 it is a 550 permanent rejection. Retries do not help. The message is gone.
Microsoft rejects rather than filters. Gmail and Yahoo will often bury non-compliant mail in spam, where a determined recipient could still dig it out. Microsoft's consumer rejection means the message never existed as far as your prospect is concerned. There is no folder to check.
The practical read: the authentication stack is no longer a deliverability optimization. It is the ante. We cover the full three-provider picture in our cold email deliverability guide for 2026, and the DNS mechanics in how to set up cold email infrastructure.
The Compliance Checklist
Do these, confirm them, and stop thinking about them:
- SPF record published, listing every service that sends as your domain. One record, under ten DNS lookups.
- DKIM signing enabled on every sending platform. 1024-bit minimum key, 2048-bit if you are setting it up fresh.
- DMARC record published at
p=noneas the floor. Move top=quarantineonce your reports are clean, because the providers increasingly treat long-termp=noneas a sender who is monitoring but not committing. - Alignment verified, not assumed. A passing SPF check on a bounce domain that does not match your From domain does not align, and it will fail DMARC.
- One-click unsubscribe headers (
List-UnsubscribeplusList-Unsubscribe-Post: List-Unsubscribe=One-Click) on anything remotely marketing-shaped. - TLS on transmission.
- Hard bounce rate under 2%. Above 2-3% sustained, every major provider throttles you.
- Complaint rate under 0.10%. The published cliff is 0.30%. Do not operate anywhere near it.
That is table stakes, universally enforced, and genuinely not the interesting part.
Why Compliant Cold Email Still Lands in Junk at Microsoft 365
You did all of the above. SPF, DKIM, DMARC, aligned, verified. Your bounces went to zero. And your meetings booked did not move.
Welcome to Exchange Online Protection.
When mail arrives at a Microsoft 365 tenant, EOP assigns it a Bulk Complaint Level, a score from 0 to 9 that estimates how bulk-like and complaint-attracting the sender's behavior is. It gets stamped into the message headers alongside the Spam Confidence Level. Microsoft documents BCL publicly, which is more than can be said for how it is calculated.
The defaults matter:
- Default anti-spam policy, new policies, and the Standard preset: threshold 7. Mail at BCL 7 or above goes to the recipient's Junk Email folder.
- Strict preset: recommended threshold 5. Mail at BCL 5 or above gets quarantined, which means the recipient does not even have a Junk folder to find it in.
Read those two lines again, because the implication is the awkward one. The threshold is set by the receiving company, not by Microsoft and definitely not by you. The identical campaign, sent from the identical authenticated domain at the identical moment, can inbox at one prospect's employer and quarantine at the next. Nothing about your setup changed. Their security admin picked a different preset.
There is no DNS record that lowers your BCL. There is no header you can add. BCL is downstream of how your sending looks over time: volume patterns, list quality, how many people mark you as junk, how templated the content reads, whether your domain has history.
This is the same structural shift happening on every outbound channel. We wrote about carriers doing exactly this to cold calls earlier this year. The gatekeeper stopped checking credentials and started scoring behavior.
The 5,000-a-Day Trap in Outlook's Bulk Sender Rules
Here is where a lot of outbound teams get a false sense of safety.
Run the arithmetic on a standard cold email estate. Twenty sending domains, three mailboxes each, thirty sends per mailbox per day. That is 1,800 emails a day in total, and ninety per domain.
Ninety. Against a threshold of five thousand.
By Microsoft's published definition you are not a bulk sender. The high-volume requirements do not apply to you. You could skip the whole checklist and never see a 550 5.7.515 in your life.
You would also still be in trouble, for three reasons.
First, the infrastructure is the signal. Twenty freshly registered domains with no history, all sending low volume to the same industry, all with similar content, is a pattern that filtering systems were built specifically to recognize. Spreading volume thinly across domains does not hide the behavior. It just changes its shape.
Second, thresholds are floors, not exemptions. Nothing in Microsoft's policy says senders below 5,000/day are exempt from filtering. It says they are exempt from that specific authentication gate. BCL scoring applies to everybody.
Third, you are optimizing for the wrong system anyway. All 1,800 of those emails are going to corporate Microsoft 365 tenants, where the 5,000/day threshold is not the operative rule. It was never measuring the thing you were worried about.
One piece of related advice worth correcting while we are here, because it is still repeated constantly: the per-mailbox External Recipient Rate limit of 2,000 external recipients per 24 hours, announced for Exchange Online in 2024, was cancelled in January 2026 and never took effect. Microsoft replaced it with a tenant-level limit scaled to licence count. If you send from Microsoft 365 mailboxes and built your sending caps around the per-mailbox number, the constraint you planned around does not exist.
Flying Blind: Microsoft Gives You Less Data in 2026 Than It Did in 2025
Google gives senders Postmaster Tools: domain reputation, spam rate, authentication success, all at the domain level, all free.
Microsoft gives you SNDS, the Smart Network Data Services portal, paired with the Junk Mail Reporting Program for complaint feedback. It is the closest equivalent, and it has a design problem for cold emailers: SNDS reports on IP addresses, not domains.
If you send through a shared ESP pool, the IP reputation you can see is not yours. It is the aggregate of everyone on that pool. Your twenty carefully warmed domains are invisible to the only monitoring surface Microsoft offers.
And in 2026 the surface got smaller. As of 22 July 2026, trap-hit counts are no longer included in the SNDS Data Report. Microsoft cited protecting the integrity of its anti-abuse systems, which is a reasonable thing for Microsoft to want and a genuine loss for anyone sending in good faith. Trap hits were the single clearest signal that a purchased or scraped list had gone stale. That number is gone. Separately, automated access on the old sendersupport.olc.protection.outlook.com/snds/ path is being deprecated, so any monitoring script you built against it needs repointing.
Which leaves you instrumenting your own side:
- Hard bounce rate by domain and by list source. Your best remaining proxy for list rot.
- Reply rate by recipient mail provider. Segment your reporting by MX. If Google replies hold steady and Microsoft replies fall off a cliff, that is a filtering verdict, not a copy problem.
- Bounce codes, read individually.
550 5.7.515is authentication. A550 5.7.1or a silent accept-then-junk is reputation. Do not average them into one "bounce rate" number that hides which problem you have. - Seed accounts inside real Microsoft 365 tenants, not consumer Outlook.com addresses. The consumer inbox does not tell you what a corporate tenant did.
The Only Input You Still Control
Look at what all three providers actually measure now. Gmail's spam rate. Yahoo's complaint ceiling. Microsoft's Bulk Complaint Level. Different names, different scales, one underlying question: did the people receiving this want it?
You cannot authenticate your way past that question. SPF, DKIM and DMARC establish that you are who you claim to be. They are an identity check, and identity checks earn you the right to be evaluated. They do not influence the evaluation.
The evaluation is decided by complaint rate, and complaint rate is decided by one thing: whether the message had a reason to exist for the person who received it. A well-authenticated, perfectly aligned, TLS-encrypted email to someone with no reason to care is still a complaint waiting to happen. And every complaint compounds, because it moves the score that decides the next thousand sends.
That is the honest case for signal-based outreach, and it has nothing to do with deliverability tooling. If your list is built from a job-title filter, most recipients had no reason to hear from you, and your complaint rate reflects that arithmetic no matter how clean your DNS is. If your list is built from people whose recent public activity says they are dealing with the problem you solve right now, the same volume produces a fraction of the complaints.
Cleed reads public LinkedIn activity across eleven signal types and scores which prospects have a live reason to hear from you this week. It is not a deliverability product and will not fix your DMARC record. It changes the input that deliverability systems are actually measuring. If Microsoft filtering has you rethinking channel mix entirely, our comparison of cold email versus LinkedIn outbound covers the trade.
The Takeaway
The Microsoft bulk sender requirements in 2026 are real, enforced, and less relevant to your B2B outreach than the first page of search results suggests.
What to hold onto:
- The published rules apply at 5,000+/day per domain to consumer Outlook.com addresses only. SPF, DKIM, DMARC with alignment,
p=noneminimum, enforced since 5 May 2025 with a550 5.7.515rejection. - Your B2B prospects are not on the consumer system. They are behind Microsoft 365 and Exchange Online Protection, which has no published sender checklist.
- BCL is the corporate gate. Default threshold 7 routes to Junk, Strict preset at 5 quarantines, and the receiving company picks. The same campaign inboxes at one account and vanishes at another.
- Being under 5,000/day exempts you from one authentication gate, not from filtering. Twenty low-volume domains is a pattern, not a hiding place.
- Gmail went from
421deferrals to550rejections in November 2025. There is no longer a warning shot. - Microsoft's monitoring got worse in 2026. SNDS is IP-level, and trap-hit counts left the Data Report on 22 July 2026. Instrument reply rate by recipient provider yourself.
- Complaint rate is the metric under all of them, and it is a relevance problem wearing a deliverability costume.
Fix the authentication this week. It is deterministic, it is cheap, and nothing else works without it. Then accept that you have bought a ticket to be evaluated, and spend your remaining effort on the thing being evaluated. For what to expect once your mail is landing, our 2026 cold email benchmarks set the bar.
Start your free Cleed trial and see which prospects have a live reason to hear from you this week. Seven days free, no credit card required.