On May 5, 2025, Microsoft began rejecting — not junking, rejecting with a 550 code — email from high-volume senders that fails authentication. Gmail and Yahoo had led the way in February 2024. By July 2026 these rules are fully enforced. I wanted to know where Québec brands stand: not 'are they protected', a question I have already asked here, but 'would they pass the checks the big providers actually run today'. The answer is yes, nearly all of them. And that is precisely what is worrying.
p=none, which observes without blocking anything. They are compliant. They are spoofable.p=none already collect reportsThree dates sum up the last three years.
February 2024 — Gmail and Yahoo impose requirements on bulk senders, defined by Google as those sending more than 5,000 messages per day to Gmail accounts. Those senders need SPF and DKIM, and a published DMARC record. For everyone else the rule is softer but universal: have SPF or DKIM.
May 5, 2025 — Microsoft enforces its own requirements on consumer Outlook.com mailboxes. Failing messages are refused with 550 5.7.515 Access denied, sending domain does not meet the required authentication level. That is not the junk folder: the email lands nowhere.
Today — these rules are in force. And the most important one deserves a careful read, because it explains everything else: the DMARC required of bulk senders may be set to p=none. Google says so explicitly. Publishing DMARC is enough; making it enforce anything is not required.
I reused exactly the same list of 26 brands as the lookalike-domain study published here on July 27 — finance, insurance, public sector, telecom, media, retail, delivery, industry — and queried public DNS on July 31, 2026 for each: is SPF published? Is DKIM detectable? Is DMARC published, and with which policy?
Then I applied the two bars described above. That is all. No site visited, no email sent, no private data: only DNS records anyone can look up.
p=reject — the fake email is refused13 brandsp=quarantine — it goes to junk4 brandsp=none — it lands in the inbox8 brandsPut the two results side by side. 24 of 26 brands would meet the bulk-sender requirements. Only 17 are actually protected. Seven brands sit in that gap, plus an eighth with no detectable DMARC.
Those eight did the visible work. SPF is published. DKIM signing is in place. The DMARC record exists. A compliance table would show them all green. But their DMARC says p=none, which translates literally to: "if a message fails the check, let it through anyway".
In other words, a fraudster emailing your customers while posing as one of these brands will have that message delivered to the inbox. Not to junk. To the inbox. The protection is published; it is simply not switched on.
The tempting conclusion is negligence. The data says otherwise. I checked whether those eight domains ask to receive DMARC reports — the rua tag, which delivers a daily statement of everything sent in your name.
Six of the eight have one. Several point at commercial DMARC platforms, meaning paid tools. These organisations do not shrug: they started the process, bought the tool, and collect the data. They simply never took the next step.
And that step is the only frightening one, because it is the only one that can break something. Moving to quarantine or reject means accepting that any legitimate sender you forgot — the newsletter tool, the invoicing software, the agency writing on your behalf — stops being delivered. Nobody wants to be the person who cut off payroll email. So you stay in observation mode. One year. Two years.
It is an inventory problem, not a technical one. DMARC reports exist precisely for this: they list who sends in your name, so you can tighten the screws knowing what you are about to break.
Let us be honest: if you are a ten-person business, you are not a "bulk sender" in Google's sense. The strictest requirements do not apply to you, and nobody is going to start rejecting your email tomorrow on that basis.
Three things still concern you.
The universal bar does apply. Gmail asks every sender to have at least SPF or DKIM. All 26 brands measured here clear it; it is the bare minimum, and a small business without SPF sits below it.
The threshold is crossed without noticing. Five thousand messages a day is one newsletter to a decent-sized list, or a single campaign. The day it happens, the rules apply all at once.
And above all, spoofing asks nobody's permission. That is the real subject. No Gmail or Outlook rule protects you from someone emailing your customers in your name: only DMARC at quarantine or reject does. A small business is in fact an easier target than a major brand, because its customers expect nothing sophisticated.
Compliance and protection are two different things, and 2026 has just demonstrated it across a sample. A domain can tick every box the big providers set and remain, to a fraudster, exactly as open as before.
So the useful question is not "do I have DMARC". It is "what does my DMARC do when somebody lies". If the answer is none, the answer is: nothing.
Checking takes fifteen seconds and requires no signup — the report reads your public records and tells you which category you fall into, with the exact value to set in order to leave it.
Enter your domain: in 15 seconds we test your SPF, DKIM, DMARC and website — free, no signup, public data only.
Run the free check →Method and limits: the same 26 Québec brands as the lookalike-domain study of July 27, 2026 (finance, insurance, public sector, telecom, media, retail, delivery, industry), queried over public DNS (cloudflare-dns.com) on July 31, 2026. For each: presence of an SPF record at the domain root, presence of DMARC on _dmarc.