Google Resurrects Its Verified Political Sender Program


Remember Google's program to verify US political senders? (Which Jennifer Nespola Lantz covered for Spam Resource back in 2022, see here and here to revisit that bit of history.) Well, it's back.

The Gmail Verified (Political) Sender Program returns, re-launching September 8, 2026. Detailed in Google's Gmail Verified Sender Program guidelines, the program establishes identity verification and technical compliance standards for US political senders looking to successfully deliver email to Gmail-hosted inboxes.

On paper, the requirements sound solid. Senders must authenticate via SPF and DKIM, follow Google's standard bulk sender requirements, refrain from sending spam, and maintain a 14-day average spam complaint rate under 0.3%. These make for OK starting points at a glance, but I’d like to see this running for a while, maybe even a whole campaign cycle, before passing my own judgement. I worry; If requirements end up too loose, or enforcement is lax, or other loopholes are exploited, it risks frustrating end users with a surge in unwanted political email messages.

Fellow email industry expert Brian Sisolak notes that this iteration of this program expands significantly on Google's earlier 2022 pilot. As detailed in his breakdown on LinkedIn, this is not being framed as a temporary test program, scope is expanded to cover more potential senders, and Campaign Verify will be used to validate senders.

Progressive campaign tool provider NGP VAN provides more details on this as well, you’ll want to see their political sender guide to learn more.

Side notes: Are senders required to have dedicated sending IP addresses? This was in the original announcement, but has since been clarified. My understanding is that no, dedicated IPs are not required. And is DMARC required? It isn’t called out in the program’s high level compliance bullet points, but they do link to the broader Gmail bulk email sender requirements, which do mandate DMARC. I interpret this as indicating that DMARC is required.

Post a Comment

Comments