Authentication is no longer optional. What changed, who it applies to, and what a shop owner actually has to do about it.
In 2024 Gmail and Yahoo stopped treating email authentication as a recommendation. Both now enforce a baseline for everyone, and a stricter set of rules for anyone sending in volume. Microsoft has been moving the same direction. If your shop sends order confirmations, shipping notices and the occasional campaign, this affects you.
Any domain sending mail is expected to have at least one form of authentication — SPF or DKIM — plus valid forward and reverse DNS on the sending server. Mail from a domain with neither is increasingly filtered outright rather than merely scored down.
Sending roughly five thousand messages a day or more to a single provider puts you in the bulk category. Then all of the following are expected:
Two reasons. First, the daily volume threshold is per provider and easier to cross than it sounds during a busy campaign week. Second, and more importantly, the baseline already applies to you today. A shop with no SPF and no DKIM is exactly the profile these rules were written to filter.
There is also a Shopify-specific trap. Shopify sends your transactional mail on your behalf, from its own infrastructure. If your SPF record does not include Shopify, every order confirmation fails authentication — while the mail you send by hand from the same domain arrives perfectly. Shop owners chase this for weeks because their own tests always look fine.
The whole path usually takes a shop four to six weeks, most of which is waiting for reports rather than working. There is no benefit to rushing it, and a real cost to going straight to enforcement and blocking your own invoices.
If anything here was wrong, unclear or out of date, tell us — the article gets fixed the same day.