Google and Yahoo have hired a digital bouncer, but we’re here to help you get on the list!

What were previously considered recommended best practices will now be mandatory for senders to enhance their credibility amidst the epic battle against unsolicited salty processed canned pork emails, aka SPAM.

Starting in February 2024, Google and Yahoo will require senders to implement email authentication alongside other significant policy changes surrounding consent and engagement. Senders who fail to meet these requirements will see their emails delayed, blocked, or directed to spam. While this may seem sudden, these changes have always been touted as the standard best practices of email deliverability.

With the uptick of spam and abuse, mailbox providers are finding the balance between unauthorized and legitimate mail by fortifying their systems to further protect their users. You may be left wondering ‘What does this mean for me?” But don’t stress! We prepared the following guide to outline what you need to do to meet the new requirements with HubSpot today.

There are three primary requirements all HubSpot Marketing and Connected Email users should be aware of: authenticate your emails with SPF, DKIM, and DMARC, enable easy unsubscription, and only send wanted emails by maintaining low spam rates.

1. Email Authentication: Authentication is a methodology that empowers senders to legitimize their sending further. There are three primary methodologies that Gmail and Yahoo will now require - SPF, DKIM, and DMARC. Unauthenticated emails may be bounced with a 5.7.26 error or marked as spam.

Simply configuring your Email Sending Domain doesn’t cover all the bases. Verifying that your ‘from addresses’ are actively using your connected domain and ensuring it’s authenticated with DKIM is crucial. HubSpot already has you covered with SPF if you’re sending from our shared swimlanes, and if you’re using a dedicated IP for sending our team will be in touch with additional instructions on how to get this properly set-up for your account. When crafting marketing emails, remember the ‘Suggestion’ prompt that alerts you if you’re about to save or send an email without utilizing a connected domain. We also recommend going through your active campaigns to check for this suggestion and update your ‘from address’ accordingly. Here are all the resources you need to ensure you meet the authentication requirements if you are using HubSpot Marketing Email:

1. Set up DKIM by connecting an email sending domain

2. Add HubSpot to your SPF record if you are using a dedicated IP. If you are using our shared swimlanes for sending, HubSpot already has you covered and no changes are needed.

3. Use a DMARC policy with HubSpot

If you are using another product to send emails and have questions about DNS authentication, please contact your Network Administrator or IT team for additional assistance, as these settings are not managed within your HubSpot account. For more information about the importance of email authentication and its impact on your overall deliverability, please check out the following blog post.

2. Enable Easy Unsubscription: Senders will now need to make unsubscribing from emails as easy as possible. If people don’t want your emails anymore, they shouldn’t have to hunt down the unsubscribe button or send carrier pigeons.

HubSpot is planning an update to the marketing email headers (aka ‘list-unsubscribe’ headers) to meet this new standard. When this is released you may see a spike in unsubscribe rates.

Sends from connected email accounts do not automatically include unsubscribe links. To ensure you meet the upcoming requirements, follow this guide to add unsubscribe links to your 1:1 emails.

3. Ensure You’re Sending Wanted Email: You wouldn’t want a stranger in your house making themselves tea uninvited, so you shouldn’t be sending emails without explicit consent.

Senders with spam complaints consistently averaging 0.3% or more will experience performance issues such as delays, spam foldering, or bounces if not properly addressed. All senders should aim to maintain spam complain levels at 0.1% or less to ensure their emails are successfully handed off for delivery to their contacts’ respective mailboxes.

Yahoo spam complaints are accounted for within the HubSpot app under the Spam Reports. However, Gmail spam complaints are not tracked within the HubSpot app, as they use a unique feedbackloop program that protects user privacy by generating aggregated reports by sender or campaign. Senders should instead enroll in Google Postmaster Tools (GPT) to monitor Gmail spam complaints externally.

GPT will give you a snapshot of your sending performance with Gmail, including insight into your spam rates, domain reputation, delivery errors, and more. As this is an external program managed outside of HubSpot, please visit the Gmail Help Center for additional assistance with set-up and troubleshooting.

While the 2024 Yahoo and Gmail requirements may seem daunting, remember that HubSpot is here to help ensure you are not alone in the email wilderness! You can comment on this community post with any questions or concerns. In the meantime, check out the official guidelines from Google, and remember, we’re all in this together!

Thanks for sharing this! Right now HubSpot’s unsubscribe function is two clicks. Will this be changing across the board to comply with the newly required “One-Click Unsubscribe” as laid out in the policy update? If so, when will that be happening? Thank you!

Hi @CFlaherty!
Based upon RFC standard (aka internet ‘rule’ book), HubSpot’s marketing email tool does currently meet one click unsubscribe through what is called “list unsubscribe header.” This is a code HubSpot automatically places within the headers of the email. This enables an email client like Yahoo or Gmail to enable a 1 click unsubscribe button in their tool.
Here is an example from Gmail.

If someone uses that link instead of the one in the footer, it requires only one click and they will be unsusbcribed from all.

We will continue to review our subscription process across tools to ensure compliance.

Currently HS allows the email footer to have:

  • Unsubscribe button,
  • Manage Preferences button
  • or Both

Will this be changing? What is best practices going forward (a recipient can still unsubscribe from the Manage Preferences page)

yes, we have always modified to “manage preferences” please let us know the go forward recommendation

Great resources and advice. Thank you @AmaraEllis!

The one-click unsubscribe requirement is two-fold from Google. You have to have both List-Unsubscribe-Post: List-Unsubscribe=One-Click and List-Unsubscribe: https://solarmora.com/unsubscribe/example\ in the header. I only see List-Unsubscribe in the headers. Is Hubspot planning on adding “List-Unsubscribe-Post: List-Unsubscribe=One-Click” to all headers before the deadline?

I’m a bit confused so does Hubspot’s Marketing emails already meet the one click unsubscribe requirement?
Also, what about Sales 1:1 emails? Does Hubspot do anything with that to help with compliance?

Hey all! Thanks for this resource. It looks like this advice largely focuses on Marketing Emails. What advice do you have for sequences / sales emails?

I just have a question about the authentication. Are all three methods required, will one do, or should we have a combination of some sort?

Question: When we say Google will require this, I assume this includes non-Google business domains running through Google Workspace (and not just Gmail accounts)?

Question: we have the “prefer fewer emails from me” unsubcribe enabled in our 1-2-1 emails (sequences) at the bottom after the email signature, but this appears at the end of the email so not very prominant. Will HubSpot be changing this to appear higher up or is this something we can/need to edit to place higher up? Manage unsubscribe links for one-to-one emails

I also worry about the “one-click” rule. We purposefully use “manage preferences” because there are cyber attack detection tools that some large companies use that click every link in an email before it goes to the end user. This has caused some clients to have unsubscribes from people who never meant to unsubscribe and get upset when they stop receiving the communications. How will this be handled if we’re forced to include the one click unsubscribe link?

Isn’t this just for the accounts that send more than 5k emails a day?

@CEberhardt For sales emails, the guidance is the same, but the requirements for all senders do not involve changes managed in HubSpot the way that marketing email does. You should work with your IT team to ensure you have SPF or DKIM authentication set up in your DNS records, and a DMARC policy configured. You should also be reviewing your spam rates in Google Postmaster Tools.
If you are a bulk sender, there are a few more requirements. Note: If you’re using the same domain for marketing and sales, it all counts towards that 5,000 email/day consideration, so it’s certainly possible to be a bulk sender of sales email if the overall volume of the sending domain is that high. The unsubscribe requirement for bulk senders is the reason we are recommending opting into unsubscribe links for sales emails. It is unclear how strictly Google will hold non-marketing emails to this standard, but reading the most recent FAQs mentioning “commercial” emails means it is likely. One important note is that Google is starting with personal gmail.com recipients, not Google Workspace accounts, so B2C senders might feel the impact of the changes sooner.
Ultimately, Google and Yahoo aren’t going to tell us everything, and they are going to continue tightening the requirements as time goes on. Our overall recommendation is to start following all the guidelines you can as quickly as you can. Check Google Postmaster Tools to understand what kind of volume and spam rates you have today. If you’re sending close to or over 5k/day, and to a lot of gmail.com recipients, you should strongly consider opting into unsubscribe links for sales email sends.

@MPhelps The placement of the unsubscribe link below the signature is the standard location and where recipients expect to find it. We don’t have any plans to change it at this time.

Is there a Hubspot recommended testing resource to check that DKIM, SPF and DMARC are set up correctly?

@MarkEdwards You can check DKIM, SPF, and DMARC configuration for your domain using e.g. https://mxtoolbox.com/
I find it a bit annoying that the required DKIM record is removed from the HubSpot UI after connceting the domain, so you have to trust the green checkmark on the “Domains & URLs” page. The SPF record is available, so you can compare it with what’s registered in DNS.

@JeffBell Gmail and Yahoo have stated that all three authentication methods are mandatory. DKIM requires you to connect a valid email-sending domain you own and update DNS records, as outlined in the following KB. You’re already covered with SPF, so no changes or actions are necessary there. Lastly, to meet the DMARC requirement, you’ll need to publish a DMARC record with a minimum policy of p=none. We suggest starting with a basic policy v=DMARC1; p=none; pct=100;
rua=mailto:youremail@example.com
It essentially means, “Apply this policy to all my messages, and if it does not pass SPF or DKIM authentication checks, do nothing.” This policy is meant to be neutral for those who haven’t configured DMARC previously and get comfortable with reading through the XML reports that will be sent for processing. If you need assistance generating a more robust custom policy, there are DMARC-specialized organizations such as DMARCIAN available.

@Rooper Gmail recently updated the email sender guidelines to clearly define these requirements for personal Gmail accounts, meaning those with addresses ending in @gmail.com or @googlemail.com.