550 5.7.23 SPF validation failed
Sample bounce line
550 5.7.23 SPF validation failed
What it means
RFC 7372 registers X.7.23 with sample text 'SPF validation failed' and basic status code 550. It is returned when a message completed an SPF check that produced a 'fail' result, contrary to local policy, and it is used in place of 5.7.1 as described in section 8.4 of RFC 7208. The receiving server decided to reject because the sending IP is not authorized by the envelope domain's SPF record.
Why it happens
- The connecting IP is not listed in the SPF record of the domain that was checked (the 'fail' result, usually a -all policy)
- The message was sent through a provider or forwarder whose IP is not included in the sender domain's SPF record
- The sender domain's SPF record is outdated or missing a legitimate sending service
How to fix it
- Sender domain owner: add every legitimate sending host or service to the domain's SPF TXT record, or send through a service already authorized
- Recipient admin: SPF 'fail' is a local policy decision (RFC 7208 section 8.4), so review the policy if legitimate mail is being rejected
- For errors rather than an SPF fail, RFC 7372 defines X.7.24 'SPF validation error' (basic code 451 or 550)
DNS record examples (replace example.com and the values with your own):
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; one SPF record per domain; use your provider's real include value
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
No related errors listed yet.