550 5.7.26: fix Gmail's 'unauthenticated email' bounce

Gmail rejects mail that fails SPF, DKIM or DMARC. How to find which check failed, the usual causes, and what Gmail, Yahoo and Outlook now require.

· 4 min read · By the Spot Downtime team

If your emails bounce back with 550 5.7.26, Gmail refused them because it couldn't confirm they really came from your domain. The full message is usually one of these:

text
550-5.7.26 Unauthenticated email from example.com is not accepted due to
domain's DMARC policy.

550-5.7.26 This mail has been blocked because the sender is unauthenticated.
Gmail requires all senders to authenticate with either SPF or DKIM.

Outlook.com has its own version for high-volume senders: 550 5.7.515 Access denied, sending domain does not meet the required authentication level. The cause and the fix are the same.

What it means

Email authentication has three parts. SPF lists the servers allowed to send for your domain. DKIM signs each message so it can't be forged. DMARC says what to do when a message fails, and requires that SPF or DKIM pass for the domain in the From address (alignment). A 5.7.26 means that check failed.

Find out which part failed

Send a message to a Gmail address, open it, and choose Show original. The top shows SPF, DKIM and DMARC as PASS or FAIL, and the headers below say why. Then check your records:

SPF, DKIM & DMARC checkerCheck a domain's SPF, DKIM and DMARC records and see what's missing or broken.

The usual causes

A sending service isn't in SPF or isn't signing with DKIM

You added a newsletter tool, CRM, helpdesk or invoicing app that sends “from” your domain, but never set up its SPF include or DKIM records. Mail from your main provider passes; mail from the new tool fails. Every service that sends as you needs its DKIM record published, and ideally its own SPF entry.

It passes, but for the wrong domain

The service signs with its own domain (d=sendingservice.com) and uses its own bounce address. SPF and DKIM pass, but not for your domain, so DMARC fails. Setting up a custom sending domain in the service fixes the alignment.

Forwarding breaks SPF

Forwarded mail arrives from the forwarder's servers, so SPF fails. DKIM usually survives forwarding, which is why DKIM is the one you can't skip.

A broken SPF record

Two SPF records, a typo, or more than 10 DNS lookups make SPF fail for everything. See SPF PermError: too many DNS lookups.

What Gmail and Yahoo require

RequirementAll sendersOver 5,000 a day
SPF or DKIMYesBoth
DMARC recordRecommendedYes, at least p=none
From domain aligned with SPF or DKIMYes
Valid reverse DNS for sending IPsYesYes
One-click unsubscribe for marketingYes
Spam complaint rateUnder 0.3%Under 0.3%

Fix order

1) Get DKIM signing working with your own domain for every service. 2) Clean up SPF into one record. 3) Publish DMARC at p=none with reports, read them for a couple of weeks, then tighten. The SPF, DKIM and DMARC guide walks through each step.
  • MX lookup: see which provider receives mail for a domain.
  • DNS monitoring: get alerted if your SPF or DMARC TXT record changes or disappears.

Keep reading