
Gmail and Yahoo changed the rules for bulk senders in 2024. What Nepali businesses need for authentication, deliverability and email that actually lands.
Most email marketing advice you will read was written before 2024, and it is now wrong in a way that matters.
For twenty years, email was governed by taste. Write a decent subject line, do not send too often, keep the design tidy. Getting into the inbox was mostly assumed. That assumption broke in February 2024, when Gmail and Yahoo began enforcing technical requirements on bulk senders, and Microsoft followed for Outlook in May 2025. Email stopped being a marketing discipline with a technical footnote and became a technical discipline with a marketing layer on top.
This matters more in Nepal than elsewhere, for an unglamorous reason. A lot of businesses here send marketing mail from a Gmail address, or from a hosting account set up years ago by whoever built the website, with no idea whether the domain is authenticated. That worked when filters were lenient. It fails now, quietly, and the business usually concludes that email does not work rather than that their mail never arrived.
Three DNS records decide whether your mail is trusted. They sound intimidating and are not.
SPF is a record listing which mail servers are allowed to send email for your domain, so receivers can check whether mail claiming to be from you came from a server you authorised. DKIM adds a cryptographic signature to each message, letting the receiver confirm it genuinely came from your domain and was not altered along the way. DMARC ties the first two to the "From" address the reader actually sees, tells receivers what to do when checks fail, and sends you reports.
That last point is the one most articles mangle. SPF and DKIM check domains buried in the message plumbing that no reader ever sees. Only DMARC connects those checks to the name in the From line, which is the only part a customer looks at. A business can pass SPF and DKIM and still be impersonated with ease if it has no DMARC record.
Gmail's requirements scale with volume. Every sender needs SPF or DKIM. Senders exceeding 5,000 messages a day to personal Gmail addresses need SPF and DKIM and DMARC, one-click unsubscribe on marketing mail, and a spam complaint rate below 0.30 percent. Two details get misreported constantly. That 5,000 counts only mail to personal Gmail accounts, not your total send volume. And it adds up per domain, not per mailbox. Google's rules also do not cover mail sent to Workspace accounts, so businesses here who mostly email other businesses face a softer version of this than those selling to the public.
Microsoft's rules for outlook.com arrived in May 2025 with the same 5,000-per-day threshold and the same authentication trio.
Enforcement has hardened since late 2025 — non-compliant mail can now meet outright rejection, not just spam filtering. My read, offered as reasoning rather than as anyone's announcement, is that the 5,000 threshold is a transitional courtesy rather than a permanent floor. A business setting this up today should configure all three records regardless of volume, because the work is identical and doing it later under pressure is worse.
One thing to skip: BIMI, the standard that puts your logo beside the message. Gmail requires a certificate issued by a recognised authority — usually a Verified Mark Certificate, which needs a registered trademark — involving a lengthy application and a recurring fee. For most Nepali businesses that is a distraction dressed as an opportunity.
Here is the uncomfortable part. Apple Mail downloads remote images in the background whether or not anyone opens the message, and routes the request through relays that hide the reader's address. Open tracking works by loading a hidden image. So an "open" recorded from an Apple device may represent nobody at all.
This is not a rumour or a vendor talking point. It is documented behaviour that has been in place since 2021, and it means open rate is not a slightly noisy metric — it is measuring a different thing than its name suggests. Be careful with the percentages that circulate about how much of your list this affects. The widely quoted figures trace back to a single email vendor's customer panel with no published methodology. The mechanism is enough to make the point; the numbers are not trustworthy.
Businesses often assume a rising open rate means rising interest. It can equally mean a larger share of your subscribers bought iPhones. That is not a small distinction when you are deciding whether a campaign worked.
So what do you use? Clicks and conversions, and one metric almost nobody watches: spam complaint rate. Because Gmail now enforces a 0.30 percent ceiling, complaints stopped being a soft signal about audience sentiment and became a hard operational limit on whether your mail is delivered at all. Google's own guidance treats anything above 0.10 percent as already harmful. A business that has never opened Google Postmaster Tools is flying without the one instrument that now determines the outcome.
The deeper shift is that engagement metrics have quietly become deliverability metrics. Mailbox providers weigh recipient behaviour — complaints most explicitly, and by wide practitioner consensus opens, replies and deletions too — when deciding placement. Sending to a stale list does not merely waste effort. It teaches Gmail that your domain sends unwanted mail, which damages delivery to the subscribers who do want it.
That last point reframes the old advice about buying lists. The usual objection is that purchased lists perform badly, which is true and understated. The real problem is that they poison the well for everything else you send from that domain.
Consent is worth getting right on its own terms, though. Nepal has no dedicated statute governing commercial email, which surprises people who assume there must be one. That does not mean domestic law is silent: the Individual Privacy Act 2075 requires consent to collect personal data and limits its use to the purpose stated at collection, which bears directly on how you build a list. Beyond that, the binding constraints on a Nepali sender are the mailbox providers' rules and, where you market abroad, foreign law. That distinction matters if you sell to the diaspora or to foreign clients. The EU's ePrivacy rules require prior consent for marketing email, with a narrow exception for your own similar products to existing customers. The US CAN-SPAM Act does not require opt-in at all, but does require accurate headers, a valid physical postal address in every message, and honouring opt-outs. GDPR reaches a Nepali business when it deliberately offers goods or services to people in the EU — deliberately being the operative word. A customer who happens to be travelling in Germany does not pull you into scope; running campaigns aimed at that market does.
Double opt-in, where subscribers confirm via a follow-up email, is not legally required anywhere that is likely to apply to you. Germany is the practical exception, and even there it comes from case law about proving consent rather than an explicit rule. Treat it as evidence and list hygiene rather than compliance. It will cost you some signups and remove many of the addresses that would have generated complaints. That trade looks bad on a signup report and good on a deliverability one.
Unsubscribing deserves the same honesty. One-click unsubscribe is a technical requirement, not a link in your footer: the message must carry the specific headers defined in RFC 8058, and Google requires requests be processed within two days. Google wants the visible link as well, not instead. Businesses that make leaving difficult do not retain subscribers. They convert them into complainants, and complaints now cost far more than an unsubscribe does.
Segmentation is usually pitched as a way to lift response rates. That is true, and it is the less interesting half.
Sending everything to everyone produces indifference, indifference produces deletions and complaints, and those now determine whether your mail reaches anyone. Segmentation is how you avoid teaching mailbox providers that your domain is noise. A clothing retailer separating winter-wear buyers from summer buyers is not just improving relevance; it is protecting its sending reputation.
The same logic explains frequency better than the standard advice about not annoying people. There is no correct number of emails per month. There is only the point at which your audience stops finding the mail worth opening. That point depends far more on whether each message earns its place than on the gap between them. A genuinely useful monthly newsletter outperforms a weekly one padded to hit a schedule. When a business asks how often to send, the more useful question is usually how much they have to say.
For Nepali businesses specifically, the calendar deserves attention nobody gives it. Buying behavior and send volumes move around Dashain and Tihar in ways no international email guide accounts for. Campaigns planned against a Gregorian marketing calendar routinely land at the wrong moment. This is one of those areas where local knowledge beats any imported playbook.
I should be honest about a limit here. There is no reliable data on email engagement in Nepal — no credible benchmarks for open rates, click rates, or send times specific to this market. The figures circulating in local agency blog posts have no stated methodology. Anyone quoting you a Nepali industry benchmark is repeating something they cannot source. Measure your own list and compare it against itself over time. That is the only benchmark available, and it happens to be the only one that matters.
If you take one structural point from this: email marketing has a setup problem and a maintenance problem, and most businesses solve neither because they are busy solving the writing problem.
Setup is authentication, a real signup process, and working measurement. It is a few days of technical work, mostly once. Maintenance is list hygiene, watching complaint rates, and removing people who have not engaged in a year. That last part feels like deleting your own audience. It is also the reason experienced senders outperform enthusiastic ones.
Writing is where everyone starts, and it is the part that matters least when the first two are broken. A brilliant subject line on an unauthenticated domain is a brilliant subject line nobody sees. When clients ask Web pal to help with email campaigns, the first work is almost always DNS records and list auditing rather than copy, which is never what anyone expects to hear.
Subject lines still matter once the plumbing works. Say what the email contains, resist manufactured urgency, and remember that a misleading subject line does not just underperform — it generates the complaints that now cap your deliverability. The incentive against dishonesty used to be reputational. It is now mechanical.
Mobile design matters for the same practical reason it always did: most people read email on a phone, and a layout that requires pinching gets deleted. Keep it single-column and keep the tap targets large. Check that the message still makes sense if images never load — some clients, notably Outlook on desktop, block them by default, and a design that carries its meaning entirely in pictures says nothing to those readers.
Email remains the only marketing channel where you own the audience list outright. No algorithm sits between you and the people who asked to hear from you. That ownership is real, and it is precisely why the mailbox providers have raised the entry requirements. The businesses that will benefit over the next few years are the ones treating email as infrastructure they maintain rather than a broadcast they perform.
Not sure whether your domain is authenticated? Web pal helps businesses across Nepal with email infrastructure, DNS configuration, and campaign strategy — starting with checking what you already have rather than selling you something new.