554 5.7.0 Too many unauthenticated messages

Gmail has stopped accepting mail from a sender that keeps arriving without working SPF or DKIM. Where 550 5.7.26 rejects one unauthenticated message and explains why, this reply is the escalation: the IP or domain has sent enough unauthenticated mail that Gmail refuses the session rather than evaluating the message.

What the server replies

554 5.7.0 Too many unauthenticated messages

Sent by
Gmail
Type
PermanentRetry fails
About
Authentication
Enhanced code
5.7.0

Who sends it

Gmail inbound servers, often at EHLO or MAIL FROM before the message body is sent, for IPs and domains with a sustained pattern of unauthenticated sending. Shared hosting servers that relay for many unconfigured domains are the usual source.

Why it happens

  • A mail server relays for dozens of customer domains, most of which have never set up SPF or DKIM.
  • A long-running cron job or application sends from a hostname that is not a real domain with DNS records.
  • DKIM signing is configured with a key that no longer exists in DNS, so every message fails verification.
  • The server's HELO name and envelope sender domain are made up and resolve to nothing.

How to fix it

  1. Authenticate every domain the server sends for

    On a shared server the fix is not one domain. Publish SPF for each sending domain and sign all outbound mail with DKIM, using a server-wide default key where customers have not set up their own.

  2. Give the server a real identity

    Set the HELO/EHLO name to a hostname with a matching A record and a PTR record pointing back to the IP. Use a real envelope sender domain with an SPF record.

  3. Find the stream that fails

    Grep the outbound log for messages to gmail.com with no DKIM-Signature header. Those senders are the ones that need fixing first.

  4. Wait it out after fixing

    Gmail clears the state once authenticated mail has been flowing for a while, typically a day or two. There is no form to request it.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.