550 5.7.24 The SPF record of the sending domain has one or more suspicious entries
Sample bounce line
550-5.7.24 The SPF record of the sending domain has one or more suspicious entries. 550 5.7.24 For more information, go to https://support.google.com/mail/answer/81126
What it means
Gmail read the domain's SPF record and objected to what is in it, rather than to the result of the check. Something in the record authorises far more than it should, so Gmail will not treat a pass against it as meaningful.
Why it happens
- A mechanism that authorises an enormous range, such as a /8 or an all qualified with +all, which lets anyone pass.
- include: of a service that in turn authorises wide shared address space.
- Leftover mechanisms from providers the domain stopped using years ago, still authorising their whole estate.
- ptr mechanisms, which are deprecated and which receivers are entitled to distrust.
How to fix it
- Read your own SPF record and remove anything you cannot justify: every include and every ip4/ip6 range should correspond to a service you use today.
- Never publish +all, and prefer -all once you are confident the record is complete.
- Replace broad ranges with the specific addresses your provider documents.
- Drop ptr mechanisms entirely.
DNS record examples (replace example.com and the values with your own):
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; exactly one SPF record per domain; the include value comes from your provider
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.27 This message was blocked because it didn’t pass SPF authentication
- 550 5.7.23 SPF validation failed