Tools

550 5.7.26 Unauthenticated email from [domain] is not accepted due to domain's DMARC policy

Provider: Gmail

Sample bounce line

550 5.7.26 Unauthenticated email from example.com is not accepted due to domain's DMARC policy. Contact the administrator of example.com domain if this was legitimate email. To learn about the DMARC initiative, go to Control unauthenticated email from your domain.

What it means

The message claims to come from a domain whose DMARC policy requires authentication, and it was not authenticated, so Gmail rejected it.

Why it happens

How to fix it

  1. Domain owners: confirm SPF and DKIM are both set up (Google advises having them enabled at least 48 hours before enabling DMARC) and that outgoing mail passes at least one of them.
  2. Verify the passing method aligns with the domain in the From: header.
  3. Review daily DMARC reports to see which outgoing messages fail authentication, and check SPF, DKIM and DMARC results in message headers.
  4. Move the DMARC policy gradually from monitor to quarantine to reject as confidence in authentication grows.
  5. Legitimate senders who get this bounce: send through the correct outgoing server for your address, and contact your email provider if that does not fix it.

DNS record examples (replace example.com and the values with your own):

example.com.  IN  TXT  "v=spf1 include:_spf.your-mail-provider.example ~all"   ; one SPF record per domain; use your provider's real include value
selector1._domainkey.example.com.  IN  TXT  "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER"   ; selector and key come from your mail provider
_dmarc.example.com.  IN  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"   ; start at p=none, tighten only after reports look clean

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors