550 5.7.26: Why did Gmail block my email as unauthenticated?

Updated 9 October 2026 · 4 min read

ID please

Gmail returns 550 5.7.26 when it can't authenticate your email: neither SPF nor DKIM passed, your SPF record told Gmail to refuse the sending server, or your own DMARC policy told Gmail to reject email that fails. The fix is to make SPF or DKIM pass for your own domain, in the service that actually sent the email.

The bounce is permanent, so the email was not delivered. Once you've fixed the cause, send it again.

The three versions of the 5.7.26 bounce

Google's list of SMTP errors has three different messages under 550 5.7.26. Your bounce usually starts with "550-5.7.26" on each line. Find the wording that matches yours.

Version 1: "the sender is unauthenticated"

The message says the email was blocked because the sender is unauthenticated, and that Gmail requires all senders to authenticate with either SPF or DKIM. It then lists the results, showing that DKIM did not pass and SPF did not pass for your domain and sending server.

What it means: neither check passed. The email came from a server your SPF record doesn't list, and it had no valid DKIM signature. This usually happens when:

  • a new tool (a CRM, invoicing app, booking system or website form) sends email as yourbusiness.com, and you never set it up in DNS
  • your website sends email through your web host's server
  • DKIM was never switched on for your email provider

Version 2: "an SPF record with a hard fail policy (-all)"

The message says the envelope sender domain has an SPF record ending in -all, but the sending server's IP address failed SPF, so Gmail blocked it.

What it means: your SPF record ends in -all, which tells receivers to refuse any server not on the list, and this server wasn't on it. SPF is a DNS record that lists the servers allowed to send email for your domain. Gmail is doing exactly what your record asked.

Version 3: "not accepted due to domain's DMARC policy"

The message says unauthenticated email from your domain is not accepted due to the domain's DMARC policy, and suggests contacting the domain's administrator.

What it means: your DMARC record is set to p=reject (or p=quarantine), and the email failed DMARC. DMARC is a DNS record that tells receivers what to do with email that fails SPF and DKIM. To pass, SPF or DKIM must pass for the domain in your From address, not just for your email service's domain. This is called alignment.

Why you're seeing it now

Since February 2024, Google has required every sender to personal Gmail accounts to pass SPF or DKIM. Since November 2025, Google has been tightening enforcement, and email that fails these rules can now be rejected rather than filtered to spam.

Google's error list also has a temporary version, 421 4.7.26. It means Gmail rate-limited unauthenticated email, or that a DNS lookup failed while checking a DMARC policy. Your server retries, but the cause and the fix are the same.

How to fix it

Step 1: find out what sent the email

Look at the bounce, or ask yourself which app sent the email. A bounce from a website form needs a different fix from one sent by Google Workspace or Mailchimp. A test makes this quicker: send an email from the same app to your private test address, and the report names the sending service and shows exactly which check failed.

Step 2: turn on DKIM for that service

DKIM is the most reliable fix because it survives forwarding. DKIM is a digital signature that proves an email came from your domain and wasn't changed on the way. In most services, this is called "domain authentication".

Google Workspace: in the Google Admin console go to Apps → Google Workspace → Gmail → Authenticate email. Generate a DKIM key for yourbusiness.com, add the TXT record it shows at google._domainkey.yourbusiness.com, then click "Start authentication".

Other services: turn on DKIM signing for yourbusiness.com in the service that sends this email, and add the DKIM record it gives you to your DNS.

Step 3: add the service to your SPF record

If Google Workspace sends your email, your SPF record should include it:

v=spf1 include:_spf.google.com ~all

For any other service, add the include: value from its help pages to the same record. Keep only one SPF record for yourbusiness.com. If you see version 2 of the bounce and don't recognize the server that sent the email, don't add it. That email didn't come from you, and someone may be sending email pretending to be yourbusiness.com.

Step 4: if it was the DMARC version, fix alignment

For version 3, SPF or DKIM must pass for yourbusiness.com itself. Steps 2 and 3 usually do this. Our report's Alignment section shows exactly what passed for which domain and what to change.

Avoid simply switching your DMARC policy to p=none. It may stop the bounce, but personal Gmail still requires SPF or DKIM to pass, and your domain loses its protection against spoofing.

Step 5: test, then resend

DNS changes can take some time to be picked up. Send another test. When SPF or DKIM passes for yourbusiness.com and the Gmail verdict shows a pass, resend the bounced email.

Checked against: Google Workspace Admin Help, Gmail SMTP errors and codes · Google Workspace Admin Help, Email sender guidelines · Google, Email sender guidelines FAQ · Google Workspace Admin Help, Set up DKIM.

Questions people ask

Why did I start getting 550 5.7.26 bounces when my emails used to arrive?

Since November 2025, Google has been tightening enforcement of its sender requirements. Email that used to slip through to the Spam folder can now be rejected outright. Usually nothing changed on your side; Gmail just stopped tolerating it.

What's the difference between 550 5.7.26 and 421 4.7.26?

550 is a permanent rejection, so the email won't be delivered. 421 is a temporary deferral, so your server will retry for a while. Both point to the same authentication problem, and the same fix applies.

Should I change my DMARC policy to p=none to stop the bounces?

Only as a short-term step while you fix the real problem. Lowering the policy also lowers your protection against people faking your domain, and personal Gmail still needs SPF or DKIM to pass. Fix authentication for the service that sent the email instead.

I got a 5.7.26 bounce for an email I never sent. What does it mean?

Someone may be sending email pretending to be your domain, and Gmail is refusing it, often because of your own SPF or DMARC record. That means your records are doing their job. Don't add servers you don't recognize to your SPF record.