Email Compliance: Legal Rules Meet Google and Yahoo
CAN-SPAM fines now reach $53,088 per email. Google and Yahoo enforce their own rules too. See what actually satisfies both, and why DMARC sits at the center.
CAN-SPAM fines now reach $53,088 per email. Google and Yahoo enforce their own rules too. See what actually satisfies both, and why DMARC sits at the center.
Email compliance now means satisfying two different kinds of requirements at once, and most guides only cover one. The first track is legal: regulations like CAN-SPAM, GDPR, and HIPAA that carry real financial penalties for mishandled email. The second track is technical: rules that Google and Yahoo now enforce directly, which will bounce or spam-folder an email regardless of what the law says. One control, DMARC, sits at the center of both tracks, which is exactly why it belongs in a compliance conversation and not just a security one.
Table of Contents
ToggleThe numbers here are specific and current, not abstract. The FTC’s maximum civil penalty for a single non-compliant commercial email under CAN-SPAM reached $53,088 as of a January 2025 inflation adjustment, and that figure applies per email, not per campaign. The FTC’s largest CAN-SPAM settlement to date, $2.95 million against Verkada in August 2024, shows the penalty is not theoretical. A smaller but instructive case involved Experian paying $650,000 after labeling marketing messages as “important account information” to dodge the Act’s disclosure requirements entirely, a reminder that mislabeling an email’s purpose does not change which rules apply to it.
GDPR carries the steepest ceiling for organizations handling EU personal data over email: fines up to €20 million or 4% of global annual turnover, whichever is greater, under a strict opt-in consent standard rather than CAN-SPAM’s opt-out model. HIPAA-covered organizations face tiered penalties for exposed patient health information transmitted or stored over email, with the top tier reaching into the millions annually per violation category. In financial services, DMARC and email authentication carry specific weight for FINRA and SEC-regulated firms, whose recordkeeping rules require firms to retain business communications, email included, for years and produce them on request, which means an email compliance failure can surface long after the message was sent.
Canada’s CASL adds its own ceiling on top of these, up to CAD $10 million per violation for organizations under its opt-in consent model, and California’s state privacy law adds another layer of consent and disclosure obligations specific to commercial email sent to California residents. A single campaign that reaches recipients in multiple jurisdictions can trigger liability under several of these frameworks simultaneously, which is exactly why treating “email compliance” as one regulation rather than a stack of them is how organizations get caught off guard.
No legislature passed this next set of rules, and they matter just as much. Starting in February 2024, Google announced new authentication requirements for anyone sending bulk email to Gmail addresses, and Yahoo rolled out matching rules the same quarter. Any domain sending more than 5,000 messages a day to either provider must publish SPF and DKIM records, publish a DMARC policy, keep spam complaint rates below 0.3%, and support one-click unsubscribe on marketing mail. The threshold is measured per provider and applies whether an organization sends from its own infrastructure or through a third-party email service, and shared-IP senders can trigger the requirement without realizing it if others on the same pool push volume over the line.
Non-compliance here does not wait for an investigation. A message that fails authentication or DMARC alignment simply bounces or lands in spam, immediately, for every recipient at that provider. That makes this track faster-moving than any legal penalty and, for most organizations, the more immediate business risk, which is exactly why ongoing DMARC monitoring rather than a one-time setup has become the practical baseline.
Discover how Threatcop protects your workforce from modern cyber threats.
DMARC tells receiving mail servers what to do with a message claiming to be from a domain but failing authentication, and it reports back who is sending mail using that domain, authorized or not. Real-time visibility into that reporting is what turns DMARC from a record sitting in DNS into an actual control someone is watching. That single mechanism does three separate jobs at once: it is the specific control Google and Yahoo require of bulk senders, it is the technical safeguard that stops domain impersonation used in business email compromise, and it increasingly appears on the same underwriting checklists insurers use to assess an organization’s email risk before setting cyber insurance terms.
Getting DMARC right is not a one-time setup. Configuring DMARC correctly means starting in monitoring mode, reviewing the reports it generates to find every legitimate sender using the domain, and only then moving the policy toward actual enforcement, since jumping straight to a rejecting policy before every legitimate mail stream is accounted for will block real business email along with the fraudulent kind. Understanding how SPF, DKIM, and DMARC actually differ matters here specifically because DMARC’s enforcement depends on at least one of the other two passing and aligning with the visible From address, so a DMARC record alone, without correctly configured SPF or DKIM behind it, does not accomplish anything.
The standard itself is not static. DMARCbis, the IETF’s 2025 update to the DMARC specification, clarified ambiguities in the original standard that had led to inconsistent implementations across mail providers, which matters for any organization that set up DMARC years ago and has not revisited it since.
Email compliance stopped being a single checklist somewhere around the same time mailbox providers started enforcing their own rules alongside the law. An organization that treats CAN-SPAM, GDPR, or HIPAA compliance as separate from its DMARC configuration is managing half the actual risk, and the half it is missing is the one that can silence an entire domain’s email delivery within minutes, with no investigation required first.
The FTC’s maximum civil penalty is $53,088 per non-compliant email, following a January 2025 inflation adjustment. The penalty applies per individual email, not per campaign, which is why the FTC’s largest settlement to date, $2.95 million against Verkada in 2024, involved a relatively contained number of messages.
Any domain sending more than 5,000 emails a day to Gmail or Yahoo addresses must publish SPF and DKIM records, publish a DMARC policy, keep spam complaint rates below 0.3%, and support one-click unsubscribe on marketing email. Messages that fail these checks are bounced or routed to spam immediately, regardless of legal compliance status.
Both, depending on which track applies. No law mandates DMARC directly, but Google and Yahoo require it of any bulk sender as a condition of inbox delivery, and it is increasingly treated as a baseline control in cyber insurance underwriting and vendor risk assessments, which gives it practical force even without a specific statute naming it.
Email retention for compliance depends entirely on which regulation applies. Financial services firms under FINRA and SEC rules face multi-year retention and production requirements for business communications. Healthcare organizations under HIPAA, and organizations handling EU personal data under GDPR, each have their own documentation retention standards. There is no single universal retention period across industries.
Only until sending volume crosses 5,000 messages a day to either provider, and that threshold is easier to cross than it sounds once marketing platforms, support ticketing tools, and transactional email are all counted together on the same sending domain. Below the threshold, the same practices are still treated as best practice by both providers.

Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Domain blocklists miss most shadow AI. See how TLS fingerprinting, NAC, asset reconciliation, and OAuth audits actually find it...
Runtime AI governance is not free. See the real compute cost, why tiered monitoring cuts it 24-fold, and what...
AI agents need their own security model. See the real risks, why agent identity is the hardest part, and...
Table of Contents
×