550 5.7.26 This mail has been blocked because the sender is unauthenticated

Gmail refused the message because neither SPF nor DKIM passed for the sending domain. Since February 2024 Google will not accept mail from a domain that proves nothing about itself, no matter how small the sender. The reply tells you exactly which of the two failed and for which domain.

What the server replies

550-5.7.26 This mail has been blocked because the sender is unauthenticated. 550-5.7.26 Gmail requires all senders to authenticate with either SPF or DKIM. 550-5.7.26 Authentication results: 550-5.7.26 DKIM = did not pass 550-5.7.26 SPF [example.com] with ip: [203.0.113.10] = did not pass 550 5.7.26 For instructions on setting up authentication, go to https://support.google.com/mail/answer/81126#authentication

Sent by
Gmail
Type
PermanentRetry fails
About
Authentication
Enhanced code
5.7.26

Who sends it

Gmail and Google Workspace inbound servers (mx.google.com), at the end of DATA, for any message whose From domain fails both checks. An older wording of the same code reads "Unauthenticated email from example.com is not accepted due to domain's DMARC policy".

Why it happens

  • The domain has no SPF record at all, so there is nothing for Gmail to pass.
  • Mail goes out through a server or service that is not listed in the SPF record (a new CRM, a form plugin, a contractor's SMTP relay).
  • DKIM is enabled at the provider but the public key was never published in DNS, or was published under the wrong selector.
  • The SPF record exceeds the ten-lookup limit, which makes receivers treat it as a permanent error rather than a pass.
  • A forwarding step rewrote the message and broke the DKIM signature while the forwarder's IP is not in your SPF.

How to fix it

  1. Read the two result lines

    The reply lists SPF and DKIM separately. If SPF "did not pass" the IP in brackets is the server that sent the mail; it has to be covered by your SPF record. If DKIM "did not pass" the signature was missing or broken.

  2. Publish or extend SPF

    Add a TXT record at the domain itself of the form v=spf1 include:<your provider> ~all, with one include per service that sends as you. Keep exactly one SPF record.

  3. Turn on DKIM and publish the key

    Generate the DKIM key in your email provider's admin console and add the TXT or CNAME record it gives you at <selector>._domainkey.yourdomain.com. Then enable signing.

  4. Send yourself a test

    Mail a Gmail address you own, open "Show original" and read the SPF and DKIM lines. Both should say PASS with your domain.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.

Questions people ask