550 5.7.25 The IP address sending this message does not have a PTR record setup
Gmail looked up the reverse DNS of the connecting IP and either found nothing or found a hostname that does not resolve back to that IP. Google treats a missing or mismatched PTR record as a hard requirement, so the message is refused before content is considered.
What the server replies
550-5.7.25 [203.0.113.10] The IP address sending this message does not have a 550-5.7.25 PTR record setup, or the corresponding forward DNS entry does not 550-5.7.25 point to the sending IP. As a policy, Gmail does not accept messages 550-5.7.25 from IPs with missing PTR records. For more information, go to 550 5.7.25 https://support.google.com/mail/answer/81126#ip-practices
- Sent by
- Gmail
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.25
Who sends it
Gmail inbound servers at the start of the session, for any connecting IP. It hits self-hosted mail servers, servers on new cloud instances and office networks that relay directly rather than through a provider.
Why it happens
- The server runs on a cloud or VPS IP whose reverse DNS was never set in the provider's console.
- The PTR record points to a generic hostname like 203-0-113-10.static.isp.net that has no matching A record.
- The PTR exists but names a hostname whose A record points at a different IP (forward-confirmed reverse DNS fails).
- Mail leaves through a NAT or residential connection whose IP you do not control.
How to fix it
Set the PTR record
Reverse DNS is managed by whoever owns the IP, not your domain's DNS. In your cloud or hosting console find "reverse DNS" or "PTR" for the server's IP and set it to the mail server's hostname, for example mail.example.com.
Match it forward
Publish an A record for that same hostname pointing to the IP. Gmail requires the loop to close in both directions.
Use the same name in HELO
Configure your MTA's HELO/EHLO hostname to that name as well. It is not required for this code but it removes the next complaint.
Or relay through a provider
If you cannot control the IP (home connection, shared NAT), send through an SMTP relay whose IPs already have proper reverse DNS.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 550 5.7.26 This mail has been blocked because the sender is unauthenticatedGmail refused the message because neither SPF nor DKIM passed for the sending domain.
- 554 5.7.0 Too many unauthenticated messagesGmail has stopped accepting mail from a sender that keeps arriving without working SPF or DKIM.
- 550 5.7.708 Service unavailable, access denied, traffic not accepted from this IPMicrosoft is declining all traffic from the sending IP, a softer cousin of the 5.7.606 ban.
- 501 5.5.4 Invalid HELO/EHLO argument / syntax error in parametersThe server did not like the arguments your client sent with a command, most often the hostname in HELO or EHLO.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.