Google has started automatically blocking spoofed emails sent by mass message senders that do not meet the strictest anti-spam and checks, as required by new guidelines to strengthen protection against spam and phishing attacks.
See also: Gemini comes to Google Messages in beta

As announced in October, the company now requires those who wish to send more than 5,000 messages per day to Gmail accounts to set up SPF/DKIM and DMARC email authentication for their domains.
The new guidelines require mass email senders to avoid sending unsolicited messages, provide a one-click unsubscribe option, and respond to unsubscribe requests within two days. Spoofed email rates must also be kept below 0.3% , and “ From ” headers must not pretend to come from Google’s Gmail. Failure to comply can result in email delivery issues, including email bounces or emails automatically being sent to recipients’ spam folders.
“Senders of bulk emails that do not meet our sender requirements will begin to receive temporary errors with error codes on a small portion of messages that do not meet the requirements,” Google states.
“These temporary errors help senders identify emails that don't comply with our guidelines so they can address issues that prevent them from complying.“
Starting in April 2024, Google will begin rejecting spoofed emails. The rejection will be gradual and will only affect those who are not compliant. Senders are strongly encouraged to use the adjustment period to make any required changes and become compliant.
See also: Google Messages: Gradual release of Screen Effects
The company also plans to implement these requirements starting in June, with an accelerated timeline, for domains used to send bulk emails starting January 1, 2024.

As Google said when the new guidelines were announced, AI-powered defenses can effectively block nearly 15 billion spoofed emails every day, preventing over 99.9% of spam, phishing attempts, and malware from reaching users' inboxes.
“You shouldn’t have to worry about the details of email security standards, but you should be able to confidently rely on the source of an email,” said Neil Kumaran, Group Product Manager for Security & Trust at Gmail in October.
“Primarily, this will close the loopholes that attackers and threaten everyone who uses email.“
See also: Google Pixel: January system update renders them useless
A spoofed email often contains details that seem unlikely or inaccurate. This can include errors in spelling, grammar, or language usage that are unusual for the sender who appears to have sent the email. Spoofed emails, such as the ones Google wants to block, often contain links that lead to websites that appear to be genuine, but are actually fake. These websites may ask the user to enter personal information, such as a username and password. Another common feature of spoofed emails is that they often contain urgent messages that pressure the recipient to react quickly. This can include warnings about security threats or requests to immediately update personal information. Finally, spoofed emails can contain attachments that can be dangerous. These files can contain malware that can be installed on the computer without their knowledge.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
