Half a year in, authentication is still the start
Answer Half a year in, authentication is still the start. On January 5, 2026, Al Iverson at Spam Resource wrote that bulk senders had reached a plain rule for inboxes hosted by Yahoo, Google, and Microsoft. No auth, no entry, unless SPF, DKIM, and DMARC are in place and passing. He said the older habit of getting by with one of them failing was over, and that loopholes were shrinking or closed. June 30 does not retire that paragraph. It is still the door. It is still not the room, and it is still not a price for a solo ad.
The note that started this: Email Deliverability in 2026: What's next?, Al Iverson, Spam Resource, January 5, 2026.
He told senders to configure DKIM for the sending domain. Platforms call that a custom domain or authenticating the domain. He noted that Klaviyo, as one example, had moved its language from a dedicated sending domain to a branded sending domain. The name on the invoice is less important than the fact that the domain on the message is one you intended, with the records in place. If you are screening safe solo ads sellers, ask them to show the pass on a test to a mailbox you open. A seller who says their platform finds authentication too hard is a seller he told readers to avoid, in those words, for Microsoft, Apple, Gmail, and Yahoo sender requirements.
He also wrote that artificial intelligence was not suddenly arriving in deliverability. Mailbox providers had been using machine learning in filters for years. Where he saw a faster change was elsewhere. Good actors using models for segmentation, bad actors using them to scale abuse, and Google announcing that Gmail was entering a Gemini era. His core sentence was the old one. Providers want to deliver mail people want and block mail they do not. Half a year later that sentence is still the one to keep. Do not promote his January note into a prediction of every product launch since. He was describing the bar he could already see.
What did Al Iverson say about authentication in January 2026?
He wrote that bulk senders are at no auth, no entry for inboxes hosted by Yahoo, Google, and Microsoft unless SPF, DKIM, and DMARC are in place and passing. He said earlier loopholes, such as getting by with one of them failing, were shrinking or closed.
Read it as a sending standard for bulk mail to those hosts, in his account, not as a statute this page is enforcing. The practical test is unchanged on the last day of June. The domain that will carry the solo either produces a pass on all three, or it does not. A pass on a different domain from the one in the From line is a magic trick. Ask for the alignment in ordinary language. Which domain signed, which domain is on the envelope, and which domain did the buyer see.
He added a second operational warning from work he did with SMTP rejection reporting that Google had added to DMARC reports in mid-2025. A lot of the rejection he saw was boring infrastructure. Reverse DNS missing or wrong, so the sending IP's name did not match in both directions. Records that were right at setup and wrong after a later change. His point was monitoring, not a one-time ceremony. A seller who authenticated in January and has not looked since is hoping. Ask when they last looked at the domain on your order.
- SPF, DKIM, and DMARC are shown passing on the sending domain.
- The visible From domain is the one that was tested.
- Reverse DNS is something they can answer about the sending IP.
- The January standard is not described as a new June trick.
Does a passing authentication result finish the job on June 30?
No. He called a branded or custom sending domain a must, and he said to avoid a platform that calls the sender requirements too hard. He also said mailbox providers have used machine learning in filters for years, and that the standing principle is to send mail people want. A pass gets you to the judgment. It does not replace it.
Wanted mail is the part a solo ad buyer can actually ruin. You can rent a clean domain and a careful platform, then put an offer in front of people who never asked, and the filters he is talking about will do what they have done for years. They will decide the mail is not wanted. Authentication will not argue with them. The list is the argument. A list with a join you can describe, a creative that matches the join, and a sender the people recognize is the rest of the job after the door.
Compare best solo ad vendors on those pieces, in that order. Door first, so you are not buying a refusal. List second, so you are not buying a stranger. Creative third, so the click has somewhere honest to land. A vendor who starts with a model, a tab, or a guarantee has started at the wrong end of his note.
Is there a shortcut he says will guarantee the inbox?
He says there is no magic text that guarantees primary-tab placement, no honest reason to trust a chart that ranks platforms by deliverability as a switch pitch, and no SMTP detour that guarantees inbox delivery. Ask for the domain's authentication result and for evidence the list wanted mail like yours.
He was blunt about hucksters. Charts that crown a platform are often an ad for switching platforms. A promise that routing through someone's SMTP service guarantees the inbox is the same promise in a different costume. He also set cold-email miracle claims aside as a different realm from ordinary marketing mail, the kind of advice that is not compatible with a normal program. You do not need the details of those schemes. You need the reflex. If the shortcut cannot be shown on your domain, with your test message, it is not a shortcut you can buy.
June 30 is a date on a calendar. Iverson's January 5 note is a standard you can still run this afternoon. Authenticate the domain that will send. Refuse the platform that calls that too hard. Then earn the open with a list that asked. Half a year in, authentication is still the start. The start is not the sale. The sale is a person who wanted the letter.