Gmail stopped being lenient about its own rules in 2026. Google’s bulk sender guidelines, in place since February 2024, require anyone sending more than 5,000 messages a day to Gmail addresses to authenticate with SPF, DKIM, and an aligned DMARC record, and to keep spam complaints reported in Postmaster Tools under 0.3 percent, ideally under 0.1 percent. For nearly two years Google mostly re-routed violations to spam folders. According to deliverability vendor GMass, that changed in November 2025, when Google began issuing permanent 5xx rejections at the SMTP level to mail that fails authentication or trips the spam threshold, refusing the message outright instead of filtering it.
Most senders already fixed the part a DNS lookup can catch. SPF, DKIM, and DMARC are configuration, and configuration is the easier half of this problem. Years after Google first announced the rule, setting up authentication records is close to table stakes for any company sending outbound email at volume. That makes the 0.3 percent spam complaint ceiling the more interesting number, because a properly authenticated domain can still breach it. Spam complaints and hard bounces track who you are mailing, not how you signed the message, and that is the half most compliance checklists skip.
The contact list is decaying faster than most teams replace it. ZeroBounce, an email verification vendor, processed more than 11 billion addresses through its own platform in 2025 and found only 62 percent came back valid, with roughly 23 percent of a typical list degrading within a year by its account, down slightly from 28 percent in 2024. Compiled figures collected by data vendor Landbase, citing Gartner, IndustrySelect, and Forbes Business Council, put annual B2B contact decay as high as 70 percent in fast moving sectors like technology and recruiting, though those specific figures are secondhand citations rather than fresh proprietary data. Either way, a list built two years ago is mailing a meaningful share of addresses that no longer belong to anyone.
That is where catch-all and risky addresses do the most damage. A dead or catch-all address does not just bounce quietly, it can land as a hard bounce or a spam trap hit, and both count against the complaint rate Google now enforces with a rejection instead of a warning. EmailAddress.ai, a company related to mGrowTech, works specifically on the catch-all problem. It says its combination of deep SMTP analysis and secure email gateway detection resolves 85 to 95 percent of catch-all addresses that standard verification tools can only mark as risky, scoring each contact from 0 to 100 and guaranteeing under 2 percent bounces on verified lists. The specific vendor matters less than the sequence: verifying a list before a send catches the decay that authentication was never designed to catch.
Authentication and list hygiene now run on the same clock. Checking DNS records once and walking away stopped being sufficient when Google turned its spam threshold into a hard rejection. The same discipline has to apply to the list itself: ongoing verification, not an annual cleanup, because a list decaying at roughly 2 percent a month can cross from compliant to rejected within a single quarter. The companies still getting flagged in 2026 are rarely missing a DNS record. They are mailing the share of their list that already turned over.
Sources referenced in reporting: Google, Email sender guidelines, ZeroBounce, The Email List Decay Report for 2026, GMass, Gmail Bulk Sender Guidelines Explained, Landbase, Data Decay Rate Statistics.