1. Establish a permission ledger
Start with the question a recipient could answer: when and why did I ask for this? Record the signup source, date, disclosed purpose and status. Keep unsubscribes, hard bounces and complaints suppressed. A platform change, acquisition or dormant database does not renew consent. Purchased and scraped addresses fail the expectation test even when a vendor calls them verified.
Separate legal basis from operational evidence. US CAN-SPAM applies requirements to commercial messages, including accurate headers, a postal address and an effective opt-out. UK and European electronic marketing frequently requires consent or a defined exception, with rules that depend on audience and relationship. Consult qualified counsel for the jurisdictions you target. This checklist cannot decide whether a specific list is lawful.
2. Authenticate the identity readers see
Map the visible From domain, envelope sender, return path, DKIM signing domain, link-tracking domain and reply address. Then follow the sending provider's current DNS instructions. Google requires SPF or DKIM for all senders to personal Gmail accounts. Above 5,000 messages per day to those accounts, it requires SPF, DKIM and DMARC, and the visible From domain must align with SPF or DKIM for DMARC.
Do not publish a second SPF record or copy an example record without understanding every sender already authorized. Use a sufficiently long DKIM key where supported, verify DNS after propagation, and inspect the authentication results in received message headers. A green badge inside an email platform is helpful, but a real received message is stronger evidence that signing and alignment work end to end.
DMARC policy is a security decision, not a decoration. Begin at a policy appropriate to the domain, review aggregate reports, identify legitimate services, and tighten deliberately. Get specialist help when several business systems send as the same domain.
3. Make unsubscribe both visible and machine-readable
A body link and one-click unsubscribe solve different problems. The visible link gives a person an understandable route inside the message. One-click unsubscribe uses message headers so a supporting mailbox can present a native control. Google requires both for marketing and subscribed messages sent above its bulk threshold. Yahoo asks bulk senders to support a visible unsubscribe and standards-based one-click unsubscribe, and to honor requests within two days.
Test the whole chain: click the body link, use the mailbox control when available, confirm the address becomes suppressed, and ensure future scheduled automations also respect that state. Do not force a login, collect more personal data than necessary or make the reader navigate a preference maze before honoring a full opt-out. Preferences can be offered as an additional choice, never as a barrier.
4. Keep identity, cadence and content coherent
Use a stable From name that readers recognize, an accurate subject and a reply path someone monitors. Avoid mixing promotional content into receipts or security notices; Google advises separating message types. Keep marketing, transactional and operational streams identifiable so a complaint against one does not confuse the purpose of another.
Cadence should match the signup promise. If a weekly publication has been silent for a year, do not resume at daily volume to the full historical list. Reconfirm stale permission where required, begin with recently engaged readers and increase volume gradually. Google recommends a consistent sending rate rather than sudden bursts. A warm-up plan is not permission to send unwanted mail, and no schedule can repair a list that did not ask to hear from you.
Review the rendered message on mobile, in dark mode and with images blocked. Confirm the sender identity, postal address, unsubscribe, link destinations and plain-text alternative. Accessibility and clarity support trust even though they are not a magic filtering trick.
5. Monitor signals without inventing certainty
Track accepted, deferred and rejected mail by receiver; hard and soft bounces; complaints; unsubscribes; and authentication failures. For sufficient Gmail volume, Postmaster Tools can show compliance, reputation and user-reported spam data, but its dashboards may omit low-volume days and do not describe every filtered message. Google says it does not track opens and cannot verify third-party open-rate accuracy.
Google recommends keeping its reported spam rate below 0.10% and preventing it from reaching 0.30% or higher. Treat 0.30% as an upper danger threshold, not a target. Segment-level trends and server responses are more actionable than a single blended delivery percentage. Pause expansion when complaints, blocks or unexplained deferrals change materially; diagnose acquisition source, message type and receiver separately.
Write response owners before launch. DNS problems belong to one person, consent questions to another, content and links to an editor, and platform incidents to an operator. A dashboard without authority to stop a send is observation, not control.
6. Run the 24-hour pre-send sequence
- Freeze late audience imports and reconcile active, suppressed and excluded counts.
- Verify SPF, DKIM and DMARC on a newly received message from the production stream.
- Test visible and one-click unsubscribe, preference changes and automation suppression.
- Proof subject, From name, reply address, postal identity, links, rendering and plain text.
- Send to an internal seed set across representative mailbox providers; inspect headers and links.
- Confirm the monitoring window, owners and the conditions that pause or roll back the send.
After launch, watch real receiver responses rather than declaring victory from a platform's initial “delivered” count. In email reporting, delivered often means accepted by the receiving server; it does not prove placement in the primary inbox or that a human wanted the message.
Facts you can verify
Operational and commercial details were reviewed on 16 July 2026. Requirements, pricing and product behavior can change; follow the primary source before acting.
- 01Google email sender guidelines
SPF, DKIM, DMARC, alignment, spam-rate and unsubscribe requirements.
support.google.com - 02Google sender-guidelines FAQ
Threshold, enforcement and one-click unsubscribe details.
support.google.com - 03Google Postmaster Tools dashboards
What compliance and spam dashboards measure and omit.
support.google.com - 04Yahoo sender best practices
Yahoo requirements for bulk senders and unsubscribe handling.
senders.yahooinc.com - 05FTC CAN-SPAM compliance guide
US commercial-email rules and opt-out duties.
www.ftc.gov - 06ICO guidance on direct marketing using electronic mail
Current UK direct-marketing and consent guidance.
ico.org.uk
Frequently asked questions
Does SPF, DKIM and DMARC guarantee inbox placement?
No. Authentication proves aspects of sending identity and is required by major receivers, but filtering also considers permission, reputation, content, volume and recipient feedback. No checklist or vendor can guarantee the inbox.
Does every sender to Gmail need DMARC?
No. Google's current baseline for all senders to personal Gmail is SPF or DKIM. Senders above 5,000 messages per day need SPF, DKIM and DMARC, plus additional alignment and unsubscribe controls.
Is a footer unsubscribe link the same as one-click unsubscribe?
No. A visible footer link is used inside the message; one-click unsubscribe is implemented through standards-based headers used by supporting mailboxes. Bulk marketing mail should provide both where receiver rules require them.
Is a 0.30% Gmail spam rate acceptable?
Treat 0.30% as a boundary to avoid, not a goal. Google recommends staying below 0.10% and preventing the reported rate from ever reaching 0.30% or higher.
Is this checklist legal advice?
No. It summarizes operational controls and links to regulator guidance. Consent, exemptions, record retention and message classification depend on jurisdiction and facts; obtain qualified advice for your program.