554 5.7.0 Too many unauthenticated messages
Gmail has stopped accepting mail from a sender that keeps arriving without working SPF or DKIM. Where 550 5.7.26 rejects one unauthenticated message and explains why, this reply is the escalation: the IP or domain has sent enough unauthenticated mail that Gmail refuses the session rather than evaluating the message.
What the server replies
554 5.7.0 Too many unauthenticated messages
- Sent by
- Gmail
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.0
Who sends it
Gmail inbound servers, often at EHLO or MAIL FROM before the message body is sent, for IPs and domains with a sustained pattern of unauthenticated sending. Shared hosting servers that relay for many unconfigured domains are the usual source.
Why it happens
- A mail server relays for dozens of customer domains, most of which have never set up SPF or DKIM.
- A long-running cron job or application sends from a hostname that is not a real domain with DNS records.
- DKIM signing is configured with a key that no longer exists in DNS, so every message fails verification.
- The server's HELO name and envelope sender domain are made up and resolve to nothing.
How to fix it
Authenticate every domain the server sends for
On a shared server the fix is not one domain. Publish SPF for each sending domain and sign all outbound mail with DKIM, using a server-wide default key where customers have not set up their own.
Give the server a real identity
Set the HELO/EHLO name to a hostname with a matching A record and a PTR record pointing back to the IP. Use a real envelope sender domain with an SPF record.
Find the stream that fails
Grep the outbound log for messages to gmail.com with no DKIM-Signature header. Those senders are the ones that need fixing first.
Wait it out after fixing
Gmail clears the state once authenticated mail has been flowing for a while, typically a day or two. There is no form to request it.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
Related codes
- 550 5.7.26 This mail has been blocked because the sender is unauthenticatedGmail refused the message because neither SPF nor DKIM passed for the sending domain.
- 550 5.7.25 The IP address sending this message does not have a PTR record setupGmail looked up the reverse DNS of the connecting IP and either found nothing or found a hostname that does not resolve back to that IP.
- 421 4.7.0 Our system has detected an unusual rate of unsolicited mail originating from your IP addressGmail is throttling the sending IP.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.