Starting in February 2024, Gmail and Yahoo will begin enforcing stricter rules for anyone who sends email to their users. If your WooCommerce store sends order confirmations, newsletters or abandoned cart reminders, some of those messages could start landing in spam or being rejected outright. The good news: most of the fixes are one-time DNS and settings changes you can finish in an afternoon.
This guide explains what the two providers announced last October, which parts apply to a typical small store, and a checklist you can work through this month.
What Gmail and Yahoo announced
In October 2023, Google and Yahoo each published new requirements for email senders. The details differ slightly, but the core message is the same: senders have to prove who they are, make it easy to unsubscribe, and stop sending mail people mark as spam.
The rules fall into two groups.
For everyone who sends to Gmail or Yahoo addresses:
- Authenticate your mail with SPF or DKIM.
- Have valid forward and reverse DNS for the sending servers.
- Keep your spam complaint rate low.
For bulk senders (Google defines this as sending roughly 5,000 or more messages a day to Gmail addresses):
- Authenticate with both SPF and DKIM.
- Publish a DMARC record for your sending domain (a policy of
p=noneis enough to start). - Make sure the domain in your “From” address aligns with the domain authenticated by SPF or DKIM.
- Include one-click unsubscribe in marketing and promotional messages, and process unsubscribe requests within two days.
- Keep the spam rate reported in Google Postmaster Tools below 0.3%.
Google has said enforcement will roll out gradually rather than all at once, but it’s not worth waiting to see where the line falls.
“I’m a small store. Does this really apply to me?”
Probably more than you think. Many stores never hit 5,000 emails a day on a normal Tuesday. But a Black Friday campaign, a big newsletter blast or a store-wide announcement to your full list can easily cross that line. Google has also said that once you qualify as a bulk sender, you keep that status.
More important, the requirements for bulk senders are simply good practice. Mailbox providers already favor authenticated, aligned mail. Fixing this now protects the emails that matter most to your revenue:
- Transactional emails: order confirmations, shipping notices, password resets.
- Automated emails: abandoned cart reminders, welcome series, review requests.
- Campaigns: newsletters, sales announcements, product launches.
All three usually come from the same domain. If campaigns damage your domain’s reputation, your order confirmations suffer too.
Step 1: Find out who actually sends your email
Before touching DNS, map every service that sends mail as your domain. For a typical WooCommerce store, that list looks something like this:
| Email type | Usually sent by |
|---|---|
| Order and account emails | WordPress/WooCommerce through your web host, or through an SMTP plugin |
| Newsletters and campaigns | Your email marketing tool |
| Support replies | Your help desk or regular mailbox (Google Workspace, Microsoft 365, etc.) |
| Invoices, shipping labels | Accounting or shipping services |
Check WooCommerce → Settings → Emails to see which “From” name and address your store emails use. If WordPress sends mail directly through your host’s PHP mail function, that is often the weakest link. Most hosts don’t sign that mail with DKIM for your domain. Routing it through a proper SMTP service or transactional email provider with an SMTP plugin usually fixes authentication and improves deliverability at the same time.
Step 2: Set up SPF
SPF is a DNS TXT record that lists the servers allowed to send mail for your domain. You only get one SPF record per domain, so if you use several services, combine them:
v=spf1 include:_spf.google.com include:yourprovider.example ~all
Each service you use will document the exact include: value to add. Common mistakes to avoid:
- Publishing two separate SPF records (this breaks both).
- Forgetting a service, such as your help desk or invoicing tool.
- Exceeding the lookup limit of 10 DNS lookups by stacking too many includes.
Step 3: Turn on DKIM for every sender
DKIM adds a cryptographic signature to each message. Each service you send through (your email marketing platform, your SMTP provider, your mailbox provider) has a setting to enable DKIM for a custom domain. Usually it gives you one or more CNAME or TXT records to add to your DNS.
Do this for every service in your Step 1 list. It’s the single most important change, because DKIM is what lets a message pass DMARC even when it’s forwarded.
Step 4: Publish a DMARC record
DMARC tells mailbox providers what to do with mail that fails authentication, and where to send reports. Start with a monitoring-only policy:
_dmarc.yourstore.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
With p=none, nothing is blocked. You simply start receiving reports that show which services send as your domain and whether they pass. After a few weeks of clean reports, you can consider moving to p=quarantine and later p=reject for stronger protection against spoofing. There’s no need to rush that part.
A note on alignment: DMARC passes only if the domain in the visible “From” address matches the domain that passed SPF or DKIM. This is why sending your campaigns “from” [email protected] through a platform that signs with its own domain is no longer good enough. Set up a custom sending domain in that platform.
Step 5: Stop sending from free mailbox addresses
If your store emails go out “from” a @gmail.com or @yahoo.com address through your website or a marketing tool, change that now. Those domains publish strict DMARC policies, so mail claiming to come from them but sent through other servers will fail. Use an address on your own domain instead, such as [email protected].
Step 6: Add one-click unsubscribe to marketing emails
For promotional mail, the new rules require the List-Unsubscribe header with one-click support, not just a link in the footer. This is what powers the “Unsubscribe” button that Gmail shows next to the sender name.
In practice, you can’t add this header yourself. It has to come from your sending platform. Check that yours supports one-click unsubscribe, and that unsubscribes are processed right away rather than in a weekly batch. If you send marketing emails from a basic SMTP plugin or a homemade setup, this is a strong reason to move them to a dedicated email marketing tool.
Transactional emails like order confirmations don’t need an unsubscribe header, which is one more reason to keep them separate from promotional content. Resist the urge to turn every order email into a sales flyer.
Step 7: Bring your spam rate down
Authentication gets you through the door. Complaint rates decide whether you stay there. Every time a subscriber clicks “Report spam,” it counts against you. Ways to keep that number low:
- Only email people who opted in. Don’t import customer lists from marketplaces, trade shows or old spreadsheets and blast them.
- Set expectations at signup. Tell people what they’ll get and how often.
- Make unsubscribing easier than complaining. A visible unsubscribe link at the top of a promotional email is better than a complaint.
- Clean inactive subscribers. People who haven’t opened in many months are the most likely to complain. Send a re-engagement email, then stop mailing those who don’t respond.
- Segment instead of blasting. A message relevant to a customer’s past purchases gets fewer complaints than a generic one sent to everyone.
Register your domain in Google Postmaster Tools to see the spam rate Gmail measures for you. It only shows data once you send a meaningful volume to Gmail users, but it’s the most direct view you’ll get.
A walkthrough: a small store fixes its setup
Take a hypothetical store selling handmade candles. It has around 8,000 subscribers and sends a weekly newsletter plus a few thousand order emails a month. Here’s what its owner found and fixed in one afternoon:
- Audit: Order emails were going out through the host’s default mail function, “from” a Gmail address. Newsletters came from an email marketing tool using the tool’s shared domain.
- Transactional fix: She installed an SMTP plugin, connected a transactional email service, verified the store’s domain there and changed the “From” address in WooCommerce → Settings → Emails to
[email protected]. - Marketing fix: In her email tool, she added a custom sending domain and published the DKIM records it provided.
- SPF: She merged the two services into a single SPF record.
- DMARC: She published a
p=nonerecord with a reporting address. - List hygiene: She created a segment of subscribers who hadn’t opened anything in six months, sent them one “still want to hear from us?” email, and removed the ones who didn’t engage.
Nothing about this required a developer. It took DNS access, a little patience and a few test emails.
How to check your work
After making changes, send a test message to a Gmail address, open it, and use “Show original” from the message menu. You’ll see whether SPF, DKIM and DMARC say PASS. Do this for each sender: a WooCommerce order email, a newsletter, and a support reply.
It also helps to read our older guide on why WooCommerce emails go to spam, which covers other common causes like content and server reputation. And if you’re cleaning things up anyway, it’s a good time to customize your WooCommerce email templates so they look like they come from a real brand.
Your January checklist
- List every service that sends email as your domain.
- Move store emails off free mailbox addresses and off unauthenticated PHP mail.
- Publish one combined SPF record.
- Enable DKIM in every sending service.
- Publish a DMARC record, starting with
p=none. - Confirm your marketing tool supports one-click unsubscribe.
- Remove long-inactive subscribers and stop emailing anyone who didn’t opt in.
- Register with Google Postmaster Tools and test with “Show original.”
If you’re choosing an email platform as part of this cleanup, look for one built for WooCommerce that handles unsubscribes and segmentation automatically. iConvert Email Marketer is one option, but whatever you pick, get authentication sorted before the February deadline.
Flavius is an online marketing specialist with experience in the digital field. He is passionate about everything that means the online world, sports, but also crypto.
Comments are closed