List Building

Small email list? The 0.3% spam rule still applies

Google’s 0.3% spam rate limit is not a bulk-sender rule. It sits in the list headed “Requirements for all senders”, with no volume qualifier, and Google calculates it daily. That makes a small list the exposed one rather than the safe one: at or below 333 Gmail recipients in a day, one person tapping “report spam” is arithmetically enough to clear the threshold on its own.

Disclosure: Tool Income Lab is reader-supported. This page contains no affiliate links. Every requirement, threshold and date below was read from Google’s, Yahoo’s, Microsoft’s, MailerLite’s and Kit’s own pages in September 2026 and is cited inline. Arithmetic on those figures is ours and is labelled where it appears. We run no client sending programme and publish no deliverability results of our own.
Isometric illustration on a large round cream platform showing a small wooden tray heaped high with green sand beside a much wider wooden tray holding a thin flat layer of the same green sand, with two runs of stacked wooden blocks meeting at a corner behind
The same amount of green in both trays. In the small one it is spilling over the sides; in the wide one you can barely see it. A spam complaint rate behaves exactly like this — the number is the same, the percentage is not.

What This Covers

The short version Which rules actually apply to you Why a small list is the exposed one The number you cannot see The 5,000 line is a one-way door What your provider does not do What we could not verify FAQ

The short version

The 0.3% is an all-senders ruleIt appears in Google’s “Requirements for all senders” list, not only in the 5,000-a-day list. The genre reports it as a bulk rule almost without exception.
It is measured dailyGoogle states “Spam rate is calculated daily.” The denominator is one day’s Gmail messages, not your list size and not your month.
Small lists are coarser, not saferAt 333 Gmail recipients a day, one complaint is 0.3003%. At 1,000, one complaint already exceeds Google’s 0.1% target.
You cannot see the numberPostmaster Tools hides data when daily volume is “too low” and Google publishes no threshold at which it appears.

Sources: Google email sender guidelines, Google sender guidelines FAQ, Google subscription guidelines, Yahoo sender best practices, Microsoft Outlook sender requirements, MailerLite domain authentication and Kit domain verification, all read September 2026.

Which rules actually apply to you

Every guide to this subject is written for someone sending 5,000 messages a day, because that is the number Google put in a headline in February 2024. If your list is 400 people you conclude none of it is about you. That conclusion is wrong, for a reason sitting in plain sight on Google’s own page: the guidelines carry two requirement lists, not one.

RequirementAll senders5,000+ a day to Gmail
Email authenticationSPF or DKIMSPF and DKIM, plus DMARC
From-header alignmentRequired
One-click unsubscribeRequired
Valid forward and reverse DNSRequiredRequired
TLS for transmissionRequiredRequired
Spam rate below 0.3%RequiredRequired

The bottom row is the finding. “Keep spam rates reported in Postmaster Tools below 0.3%” is one of six bullets under “Requirements for all senders”, with no volume qualifier. What the 5,000 threshold adds is infrastructure: DMARC, both authentication methods instead of either, alignment, one-click unsubscribe.

Yahoo splits its guidance the same way — all senders “implement SPF or DKIM at a minimum” and “keep your spam rate below 0.3%”, with both methods plus “a valid DMARC policy with at least p=none” reserved for bulk senders. Yahoo publishes no message-per-day figure, so there is no way to know which bucket you are in.

Microsoft is the outlier and the strictest on consequences. Its Outlook requirements apply to “domains sending more than 5,000 emails per day”, demand that SPF and DKIM “must pass” plus DMARC at “at least p=none”, and carry a real enforcement date: after 5 May 2025, Outlook began “routing messages from high volume non‐compliant domains to the Junk folder”, with rejection “in the future (date to be announced)” carrying the error “550; 5.7.515 Access denied”.

Both Google lists are quoted from its sender guidelines page as structured there in September 2026. We have not tested how any of this is enforced for senders below the bulk threshold, and Google publishes no stated penalty for them.

Why a small list is the exposed one

A percentage sounds forgiving until you work out what it means at your volume, and one more first-party detail is what makes it bite. Google’s FAQ states flatly: “Spam rate is calculated daily.”

The denominator is therefore not your list and not your month, but the messages you sent to personal Gmail accounts on that day — and a rate over a tiny denominator moves in enormous steps. One complaint is the smallest event that can happen. Here is what it is worth:

Gmail recipients that dayOne complaint equalsAgainst the 0.3% limit
2000.50%Over
3000.33%Over
3330.3003%Over, just
3340.2994%Under, just
1,0000.10%Under the limit, at the target
5,0000.02%Comfortably under

There is the break point: 333 Gmail recipients. Below that, the smallest possible non-zero spam rate you can record is already at or above the limit. You cannot score 0.15% on a list of 300 — the available values are 0% and 0.33%. And Google separately asks senders to “keep your user-reported spam rate below 0.1% and prevent it from reaching 0.3% or higher”, which below 1,000 daily Gmail recipients a single complaint also exceeds.

Now the part that inverts standard advice. Because the rate is daily, splitting a send into small daily batches makes the rate worse, not better. Batching does not reduce how many people dislike the email; it only shrinks the denominator on the day each one reacts. The same single complaint:

  • in one send of 1,000 → a daily rate of 0.10%
  • in a 200-a-day batch → a daily rate of 0.50%, five times worse

This does not make batching wrong — ramping volume on a new domain is about reputation building, a different mechanism. But the two goals pull against each other, and nobody selling “warm up slowly” mentions that the complaint rate is what you make worse while you do it.

So for a small sender the rate is not a dial you can tune. At 300 recipients there are two states, clean or over, and the only lever available before you send is who is on the list. Google is explicit there, and uses a phrase worth knowing: recipients should “confirm their email address after entering it on your website or app”, which it calls “double consent” — confirmed opt-in, asked for by the mailbox provider rather than by a newsletter guru.

Our arithmetic, on Google’s published 0.3% and 0.1% figures and its statement that the rate is calculated daily. Verified: 1/333 = 0.3003% and 1/334 = 0.2994%. Google publishes no consequence tied to any single day, and we assert none — the point is the granularity of the measure, not a prediction about enforcement.

The number you cannot see

Google’s wording is precise and easy to read past: keep spam rates “reported in Postmaster Tools” below 0.3%. The requirement is defined by a specific instrument, so the obvious move is to open it.

Google’s own Postmaster Tools documentation: “Data might be missing if the total number of messages for a given day is too low. This is to protect users’ privacy.” It advises checking the dashboards “when your email sending volume increases enough to populate” them.

No figure is attached to “too low” on any Google page we could find. Set that beside the previous section and the shape is plain: the requirement that binds you from your first send is expressed in a measurement you are not given, and the volume at which you are given it is unpublished. The smaller your list, the more a single complaint moves your rate — and the less likely you are to be shown it.

The privacy reasoning is sound: a spam rate over a handful of messages would identify individual recipients. But it does dispose of the genre’s most repeated instruction, “monitor your spam rate in Postmaster Tools”, which for the readers of this page describes an empty dashboard. Set it up anyway — the data starts the day you qualify, not the day you ask — but do not build a plan on watching it.

The 5,000 line is a one-way door

The threshold itself has two properties the roundups skip, both from Google’s sender guidelines FAQ.

First, it is approximate. A bulk sender is “any email sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period”. There is no exact line to sit just under. Only personal Gmail accounts count, not Google Workspace ones, and subdomains do not help: Google states it counts “all messages sent from the same primary domain”, and gives the worked example of 2,500 from a domain plus 2,500 from its subdomain adding up.

Second, and this is the one to plan around: “Bulk sender status doesn’t have an expiration date. Email senders that have been classified as bulk senders are permanently classified as such.” Google adds that “changes in email sending practices will not affect permanent bulk sender status once it’s assigned.”

So one unusually large send attaches the stricter rule set to your domain for good, with no way back under. For a growing list the question is not whether you will cross it, but whether DMARC, aligned authentication and one-click unsubscribe are in place before you do — because the day they become mandatory is a day you might not notice. Against the free plans this site has priced at source:

  • Kit’s free plan runs to 10,000 subscribers. A single send to a full free list crosses 5,000 Gmail messages as soon as more than half your list is on Gmail — so the largest free plan in the category tops out roughly where Google’s bulk threshold begins.
  • MailerLite’s free plan allows 2,500 emails a month to 250 subscribers. Even sent in a single day at 100% Gmail, that cannot reach 5,000 — but at 250 recipients it sits deep inside the zone where one complaint is 0.4%.

The two free plans sit at opposite ends of one problem: the big one walks you into the bulk rules, the small one keeps you out of them and hands you the coarsest possible spam rate instead.

What your provider does not do

The reasonable assumption is that your email platform handles all of this. It handles some of it, and the two providers this site has read at source split the work differently.

Kit states that it “authenticates DKIM and SPF for you, while DMARC authentication is managed within your domain host settings”. Read against the table above, the record Kit leaves to you is precisely the one the 5,000 threshold adds — so the provider covers you until the day you become a bulk sender, and not after.

MailerLite asks you to add all of it: “the DKIM as a CNAME record, the SPF as a TXT record, and a Domain verification as a TXT record”. It states that “it is required to authenticate your domain if you are using a custom domain for sending”, with one exception — “new MailerLite accounts can send their first campaigns without authenticating a domain during the 14 day trial period only”. Separately it notes that “accounts that send around 5,000 emails at a time also need to set up a DMARC policy”.

That also settles a question this site has had open for months: whether a custom sending domain is genuinely required. MailerLite never says you must own one, but it does say “emails sent from free domains can’t be authenticated, which can significantly affect your email deliverability and sender reputation”. Since Google’s all-senders list requires SPF or DKIM on your sending domain, and a gmail.com address is not a domain you can publish records for, both statements point the same way without either using the word mandatory. Treat a domain you own as a prerequisite, not an upgrade.

One requirement crosses every provider and is easy to break with an automation: Google’s subscription guidelines say to “process and honor unsubscribe requests within 48 hours”, and Yahoo independently asks senders to “honor unsubscribes within 2 days”. If you sync subscribers between tools on a slower schedule, that sync is the compliance risk.

MailerLite and Kit were chosen because they are the two providers this site has already read at source, not because they are better on this than the alternatives. We did not read GetResponse, Brevo, beehiiv or Mailchimp documentation on authentication this cycle and state nothing about them. Our comparison of what each platform allows you to send covers a different question on the same vendors.

What we could not verify

Stated plainly rather than filled in.

  • The Postmaster Tools volume threshold. Google says data may be missing when daily volume is “too low” and publishes no number. Widely repeated third-party figures exist; none appears above.
  • Any consequence for a small sender. Google documents the requirement and not a penalty below 5,000 a day. We state no outcome for exceeding 0.3% on a small list, because none is published. The finding here is about the measure, not about enforcement.
  • How spam rate is computed exactly. Google states it is calculated daily and reported in Postmaster Tools, but no page we read gave the formal numerator and denominator. Our arithmetic treats it as complaints over that day’s Gmail messages, which is the common reading and which Google does not confirm in those terms.
  • Yahoo’s bulk threshold. Yahoo splits its requirements between all senders and bulk senders without publishing the volume that separates them, so a sender cannot tell which list applies.
  • Microsoft’s complaint rate. Microsoft’s announcement covers authentication, opt-out and list hygiene but states no percentage. No Microsoft spam rate figure appears above.
  • Whether Kit requires domain verification. Kit says verification “is now required by mailbox providers like Gmail and Yahoo” but we found no statement that Kit itself blocks unverified sending, and no description of what it does on your behalf if you never verify.
  • Enforcement, entirely. Everything here is published wording. We have not tested how any of it is applied, and no rate of blocking, junking or rejection appears anywhere on this page.

FAQ

Do the Gmail sender rules apply to a small email list?

Some of them apply from your very first send, and this is the most widely misreported part of the subject. Google splits its email sender guidelines into two lists. The heading Requirements for all senders carries six items including Set up SPF or DKIM email authentication for your sending domains and Keep spam rates reported in Postmaster Tools below 0.3%. A separate heading, Requirements for sending 5,000 or more messages per day, adds DMARC, requires both SPF and DKIM rather than either, requires From header alignment, and requires one-click unsubscribe. So the spam rate limit is not a bulk sender rule. It sits in the all-senders list, with no volume qualifier, and almost every guide in this genre presents it as something that starts at 5,000 messages a day.

What happens if one person marks your newsletter as spam?

On a small list it can put you over the threshold by itself, because the limit is a rate rather than a count and Google states that spam rate is calculated daily. One complaint out of 333 Gmail recipients in a day is 0.3003 percent, which is over the 0.3 percent line. One complaint out of 334 is 0.2994 percent, which is under it. So at or below 333 Gmail addresses in a single day, a single person tapping report spam is enough on its own. Google also asks senders to keep the rate below 0.1 percent, and below 1,000 Gmail recipients in a day one complaint already exceeds that target. None of this means a small sender is punished for one complaint, and Google publishes no consequence tied to a single day. It means the metric is far coarser at small volumes than the percentage makes it sound.

Can you see your own spam rate on a small list?

Probably not, and Google does not say at what point you can. The requirement is worded as keeping spam rates reported in Postmaster Tools below 0.3 percent, but Postmaster Tools withholds data at low volume. Google states that data might be missing if the total number of messages for a given day is too low, and that this is to protect users privacy, and advises checking the dashboards when your email sending volume increases enough to populate them. No threshold figure is published anywhere we could find. The practical result is that the one requirement which applies to you from your first send is expressed in terms of a number you are not shown.

What counts toward the 5,000 messages a day bulk sender threshold?

Only personal Gmail accounts, counted across your whole primary domain in any 24 hour period, and Google words the threshold loosely. Its sender guidelines FAQ defines a bulk sender as any email sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period, so there is no exact line to engineer against. Messages to Google Workspace accounts do not count. Subdomains do not help, because Google states that when it calculates the 5,000-message limit it counts all messages sent from the same primary domain, and gives an example of two lots of 2,500 from a domain and its subdomain adding up. The classification is also permanent: bulk sender status does not have an expiration date, and Google states that changes in email sending practices will not affect permanent bulk sender status once it is assigned.

Does your email provider handle SPF and DKIM for you?

Partly, and the split differs by provider. Kit states that it authenticates DKIM and SPF for you, while DMARC authentication is managed within your domain host settings, so the record you are most likely to be missing is the one your provider does not add. MailerLite asks you to add each record yourself, specifically the DKIM as a CNAME record, the SPF as a TXT record, and a domain verification as a TXT record, and says it is required to authenticate your domain if you are using a custom domain for sending, with new accounts able to send their first campaigns without authenticating during the 14 day trial period only. MailerLite also states that emails sent from free domains cannot be authenticated, which is the clearest published reason on either provider to send from a domain you own rather than from a gmail.com address.

What we would actually do

Building a list from nothing, the order that follows from these documents is not the order the genre teaches, and it starts before the first subscriber.

Send from a domain you own and authenticate it on day one rather than at some later milestone — it is an all-senders requirement, and MailerLite’s note that free domains cannot be authenticated makes a gmail.com sending address a dead end. Add DMARC yourself even though nothing requires it yet, because your provider probably does not and because the day it becomes mandatory is permanent and easy to miss. Use confirmed opt-in, which Google asks for by name. Make unsubscribing trivial and effective inside 48 hours, including across any tool you sync to.

Then accept what the arithmetic says about the phase you are in. Below a few hundred recipients you cannot manage a spam rate, because one complaint sets it — you can only manage who is on the list and whether the email is what they expected. That argues for a slow, consent-heavy list over a fast one, not for the usual reason, but because the percentage is unforgiving precisely while the list is small. Buying a bigger sending plan does nothing for any of it. Weigh platforms instead on what the free tiers allow and which permit the content you intend to send — an account closed for a terms breach is a deliverability problem no DNS record fixes.

Related reads: free email tool limits compared, the MailerLite review, which email tools allow affiliate links, Substack vs beehiiv vs Ghost fees, and MailerLite vs Kit.