550 5.7.26 This mail has been blocked because the sender is unauthenticated
Gmail refused the message because neither SPF nor DKIM passed for the sending domain. Since February 2024 Google will not accept mail from a domain that proves nothing about itself, no matter how small the sender. The reply tells you exactly which of the two failed and for which domain.
What the server replies
550-5.7.26 This mail has been blocked because the sender is unauthenticated. 550-5.7.26 Gmail requires all senders to authenticate with either SPF or DKIM. 550-5.7.26 Authentication results: 550-5.7.26 DKIM = did not pass 550-5.7.26 SPF [example.com] with ip: [203.0.113.10] = did not pass 550 5.7.26 For instructions on setting up authentication, go to https://support.google.com/mail/answer/81126#authentication
- Sent by
- Gmail
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.26
Who sends it
Gmail and Google Workspace inbound servers (mx.google.com), at the end of DATA, for any message whose From domain fails both checks. An older wording of the same code reads "Unauthenticated email from example.com is not accepted due to domain's DMARC policy".
Why it happens
- The domain has no SPF record at all, so there is nothing for Gmail to pass.
- Mail goes out through a server or service that is not listed in the SPF record (a new CRM, a form plugin, a contractor's SMTP relay).
- DKIM is enabled at the provider but the public key was never published in DNS, or was published under the wrong selector.
- The SPF record exceeds the ten-lookup limit, which makes receivers treat it as a permanent error rather than a pass.
- A forwarding step rewrote the message and broke the DKIM signature while the forwarder's IP is not in your SPF.
How to fix it
Read the two result lines
The reply lists SPF and DKIM separately. If SPF "did not pass" the IP in brackets is the server that sent the mail; it has to be covered by your SPF record. If DKIM "did not pass" the signature was missing or broken.
Publish or extend SPF
Add a TXT record at the domain itself of the form v=spf1 include:<your provider> ~all, with one include per service that sends as you. Keep exactly one SPF record.
Turn on DKIM and publish the key
Generate the DKIM key in your email provider's admin console and add the TXT or CNAME record it gives you at <selector>._domainkey.yourdomain.com. Then enable signing.
Send yourself a test
Mail a Gmail address you own, open "Show original" and read the SPF and DKIM lines. Both should say PASS with your domain.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
Related codes
- 550 5.7.1 Our system has detected that this message is likely unsolicited mailGmail's spam filter scored the message as spam before it reached a mailbox and rejected it at the SMTP level rather than placing it in the Spam folder.
- 550 5.7.25 The IP address sending this message does not have a PTR record setupGmail looked up the reverse DNS of the connecting IP and either found nothing or found a hostname that does not resolve back to that IP.
- 554 5.7.0 Too many unauthenticated messagesGmail has stopped accepting mail from a sender that keeps arriving without working SPF or DKIM.
- 550 5.7.509 Access denied, sending domain does not pass DMARC verificationYour domain publishes a DMARC policy of reject, the message failed DMARC, and Microsoft did what the policy asked.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.