ToolsJuly 19, 20266 min read

The big inboxes now check ID at the door. Here is what that means for a Providence hair salon.

Gmail, Yahoo and Outlook all now demand that senders prove who they are, and the DMARC standard behind it is in the final stage of becoming official internet law. A plain-English translation for salon owners, plus a 10-minute test you can run today for free.

By Joshua Amado

Share
The battleship at Battleship Cove, seen through a chain-link fence at dawn.
The battleship at Battleship Cove, seen through a chain-link fence at dawn.

A good salon runs on email more than most owners give it credit for. The confirmation when someone books online. The reminder the night before that keeps your no-show rate down. The "we miss you" note that quietly refills a slow Tuesday. A Providence salon with a full book is sending hundreds of these a month through its booking platform without ever thinking about how they get delivered.

That delivery just got stricter, again. Here is the short version of what changed, and what to do about it on Monday.

What actually changed#

Three dates tell the story.

February 2024. Google and Yahoo began enforcing new rules for bulk senders: authenticate your email with SPF, DKIM and DMARC, offer one-click unsubscribe, and stay under a spam-complaint threshold. Google's announcement is here: New Gmail protections for a safer, less spammy inbox. In that same post, Google reported that after it started requiring some form of authentication in 2022, the number of unauthenticated messages reaching Gmail users fell by 75 percent.

May 5, 2025. Microsoft joined. Outlook now requires SPF, DKIM and DMARC for domains sending 5,000 or more messages a day to outlook.com, hotmail.com and live.com addresses, and began routing non-compliant mail to junk. The announcement: Strengthening the email ecosystem: Outlook's new requirements for high-volume senders.

This month. The updated DMARC specification, known as DMARCbis, is in the last stage of publication at the IETF, the body that writes the internet's technical standards. As of July 19, 2026, the IETF datatracker shows it in the RFC Editor's final author-review queue, slated to be published as RFC 9989 and to replace the 2015-era spec. In plain English: email authentication is graduating from "industry best practice" to the official rulebook.

75%
Drop in unauthenticated messages reaching Gmail users
Reported by Google after its 2022 authentication requirement
5,000/day
Message volume where Gmail and Outlook's strictest rules kick in
Smaller senders still benefit from the same setup
3
Records that prove your email is really yours
SPF, DKIM and DMARC, all free to set up
Sunlight through the columns of the Braga Bridge at the end of the day.
Sunlight through the columns of the Braga Bridge at the end of the day.Fall River, MA

"I don't send 5,000 emails a day"#

Correct, and that is exactly the trap. The 5,000-a-day threshold is where the mailbox providers guarantee punishment. It is not where trouble starts.

Three ways this lands on a salon that sends a few hundred emails a month:

Your booking platform sends on your behalf. Vagaro, Square, GlossGenius, Mailchimp and the rest either send from their own domains, which are already compliant, or from your domain, which is only compliant if someone set it up. If your reminders come "from" bookings@yoursalon.com and your domain has no authentication records, you are asking Gmail to trust mail that fails its ID check.

An unauthenticated domain can be worn like a costume. Without a DMARC record, nothing tells the world's inboxes to reject mail that merely claims to be from your domain. That is how a scammer emails your clients "from" your salon about a gift-card promotion that doesn't exist. The fence in front of the battleship exists for a reason; DMARC is that fence for your name.

The bar keeps ratcheting down. Google's rules started with bulk senders and Microsoft followed within fifteen months. With the standard itself about to be republished as official, betting that small senders stay exempt forever is not a strategy.

You shouldn't need to worry about the intricacies of email security standards, but you should be able to confidently rely on an email's source.
Neil Kumaran Group Product Manager, Gmail Security & Trust, Google Source

That sentence is aimed at the person receiving the email. Flip it around and it becomes the sender's job description: your clients should be able to rely on the fact that a message from your salon is actually from your salon.

The local reality check#

We have not yet measured SPF or DMARC records for salons in Providence or Fall River, so we will not pretend to know how many pass. Not measured means not claimed.

But we did audit five Fall River hair salons this month, and the "getting reached" picture was rough even before email enters it. One of the five had no website at all. Of the four with live sites, two offered no contact form of any kind, so a client who wanted to write to them had no way to do it from the site. Median mobile load time (Largest Contentful Paint) across the live sites was 6.8 seconds against Google's 2.5-second threshold. These same shops collectively hold about 1,706 Google reviews at a weighted average of 4.88 stars.

Read that combination again: nearly five-star businesses that clients love, wired up so the internet can barely reach them. The craft is not the problem. The plumbing is. Email authentication is one more piece of that plumbing, and unlike a redesign, it costs nothing.

What to do on Monday, cheapest first#

1. The 10-minute test (free). Book a fake appointment with yourself, or trigger any email your platform sends, to a Gmail address you control. Open the message, click the three-dot menu, choose Show original. At the top you'll see three verdicts: SPF, DKIM, DMARC. Three PASSes and you are in good shape today. A FAIL or a blank next to DMARC is your homework. This one test tells you more than any vendor's sales pitch.

2. Check your domain's records (free, 10 minutes). Put your domain into Google's free Admin Toolbox Check MX tool. It will flag missing SPF and DMARC records in plain language.

3. Finish your platform's "domain authentication" page (free, 20 to 30 minutes). Every major booking and marketing platform has a settings page called some variation of "domain authentication" or "verify your domain," which walks you through adding two or three DNS records at your registrar (GoDaddy, Squarespace, wherever you bought the domain). This is the single highest-leverage half hour in this article.

4. Add a starter DMARC record (free, 10 minutes). A record of v=DMARC1; p=none; rua=mailto:you@yourdomain.com changes nothing about delivery yet, but starts sending you reports on who is sending mail as you, and satisfies the "have a DMARC policy" requirement at its entry level.

Sunset behind the Braga Bridge, seen through the trees of the park.
Sunset behind the Braga Bridge, seen through the trees of the park.Fall River, MA

If the test comes back with FAILs and you would rather spend your Monday on clients than on DNS records, that is a reasonable choice. This is the kind of thing we set up in an afternoon.

Joshua Amado · Avalon Partner · 774.559.8992 · Joshua.Amado@AvalonPartner.com

Want help putting this into practice?

Avalon Partner helps Fall River and South Coast businesses fix the gaps that cost them leads. Call 774.559.8992 or email Joshua.Amado@AvalonPartner.com.

Keep reading