Where this comes from
Every requirement traces to a published source
When the analyzer calls something required, someone published that requirement — and you can go read it. These are the documents it is built on, each with the date it was last read.
Standards and industry practice
The mailbox providers are themselves members, so this is the common ground behind the requirements each of them publishes separately. Its Consistency and Alignment section is the basis for the seven-identity panel; its glossary is the basis for ours.
Where the cousin-domain warning comes from, and the reason a subdomain of your own domain is treated as ordinary rather than as a fault.
Replaced RFC 7489. Removed pct, rf and ri; added np and psd; moved organisational-domain discovery from the Public Suffix List to a DNS tree walk.
The List-Unsubscribe-Post mechanism Google requires of marketing mail and Yahoo strongly recommends.
Complaint feedback requested from the message itself, valid only when the header is covered by the DKIM signature.
Mailbox providers
5,000 messages a day to Gmail addresses, in force since 1 February 2024. Source for every requirement on the Gmail card.
Also covers AOL, which runs on the same platform. Yahoo asks for DMARC to be published and to pass, which is one step beyond what Google asks.
5,000 a day since 5 May 2025, rejected outright with 550 5.7.515 rather than filed in junk. Also the 500-connection cap and the refusal of dynamic IP space.
93 documented enhanced status codes with example text. The richest single source for explaining a rejection.
Apple states plainly that it operates no feedback loop and no allow-list programme, which is why the tool says so rather than leaving the question open.
Registries
These pages move. Microsoft’s SNDS and Comcast’s postmaster have both relocated since this list was started, which is why every entry carries a date rather than only a link. If a date here has aged badly, treat the claim it supports as needing a fresh check.