Gmail returns 550 5.7.26 when it can't authenticate your email: neither SPF nor DKIM passed, your SPF record told Gmail to refuse the sending server, or your own DMARC policy told Gmail to reject email that fails. The fix is to make SPF or DKIM pass for your own domain, in the service that actually sent the email.
The bounce is permanent, so the email was not delivered. Once you've fixed the cause, send it again.
The three versions of the 5.7.26 bounce
Google's list of SMTP errors has three different messages under 550 5.7.26. Your bounce usually starts with "550-5.7.26" on each line. Find the wording that matches yours.
Version 1: "the sender is unauthenticated"
The message says the email was blocked because the sender is unauthenticated, and that Gmail requires all senders to authenticate with either SPF or DKIM. It then lists the results, showing that DKIM did not pass and SPF did not pass for your domain and sending server.
What it means: neither check passed. The email came from a server your SPF record doesn't list, and it had no valid DKIM signature. This usually happens when:
- a new tool (a CRM, invoicing app, booking system or website form) sends email as yourbusiness.com, and you never set it up in DNS
- your website sends email through your web host's server
- DKIM was never switched on for your email provider
Version 2: "an SPF record with a hard fail policy (-all)"
The message says the envelope sender domain has an SPF record ending in -all, but the sending server's IP address failed SPF, so Gmail blocked it.
What it means: your SPF record ends in -all, which tells receivers to refuse any server not on the list, and this server wasn't on it. SPF is a DNS record that lists the servers allowed to send email for your domain. Gmail is doing exactly what your record asked.
Version 3: "not accepted due to domain's DMARC policy"
The message says unauthenticated email from your domain is not accepted due to the domain's DMARC policy, and suggests contacting the domain's administrator.
What it means: your DMARC record is set to p=reject (or p=quarantine), and the email failed DMARC. DMARC is a DNS record that tells receivers what to do with email that fails SPF and DKIM. To pass, SPF or DKIM must pass for the domain in your From address, not just for your email service's domain. This is called alignment.
Why you're seeing it now
Since February 2024, Google has required every sender to personal Gmail accounts to pass SPF or DKIM. Since November 2025, Google has been tightening enforcement, and email that fails these rules can now be rejected rather than filtered to spam.
Google's error list also has a temporary version, 421 4.7.26. It means Gmail rate-limited unauthenticated email, or that a DNS lookup failed while checking a DMARC policy. Your server retries, but the cause and the fix are the same.
How to fix it
Step 1: find out what sent the email
Look at the bounce, or ask yourself which app sent the email. A bounce from a website form needs a different fix from one sent by Google Workspace or Mailchimp. A test makes this quicker: send an email from the same app to your private test address, and the report names the sending service and shows exactly which check failed.
Step 2: turn on DKIM for that service
DKIM is the most reliable fix because it survives forwarding. DKIM is a digital signature that proves an email came from your domain and wasn't changed on the way. In most services, this is called "domain authentication".
Google Workspace: in the Google Admin console go to Apps → Google Workspace → Gmail → Authenticate email. Generate a DKIM key for yourbusiness.com, add the TXT record it shows at google._domainkey.yourbusiness.com, then click "Start authentication".
Other services: turn on DKIM signing for yourbusiness.com in the service that sends this email, and add the DKIM record it gives you to your DNS.
Step 3: add the service to your SPF record
If Google Workspace sends your email, your SPF record should include it:
v=spf1 include:_spf.google.com ~all
For any other service, add the include: value from its help pages to the same record. Keep only one SPF record for yourbusiness.com. If you see version 2 of the bounce and don't recognize the server that sent the email, don't add it. That email didn't come from you, and someone may be sending email pretending to be yourbusiness.com.
Step 4: if it was the DMARC version, fix alignment
For version 3, SPF or DKIM must pass for yourbusiness.com itself. Steps 2 and 3 usually do this. Our report's Alignment section shows exactly what passed for which domain and what to change.
Avoid simply switching your DMARC policy to p=none. It may stop the bounce, but personal Gmail still requires SPF or DKIM to pass, and your domain loses its protection against spoofing.
Step 5: test, then resend
DNS changes can take some time to be picked up. Send another test. When SPF or DKIM passes for yourbusiness.com and the Gmail verdict shows a pass, resend the bounced email.
Checked against: Google Workspace Admin Help, Gmail SMTP errors and codes · Google Workspace Admin Help, Email sender guidelines · Google, Email sender guidelines FAQ · Google Workspace Admin Help, Set up DKIM.