550 5.7.26 Unauthenticated email from [domain] is not accepted due to domain's DMARC policy
Sample bounce line
550 5.7.26 Unauthenticated email from example.com is not accepted due to domain's DMARC policy. Contact the administrator of example.com domain if this was legitimate email. To learn about the DMARC initiative, go to Control unauthenticated email from your domain.
What it means
The message claims to come from a domain whose DMARC policy requires authentication, and it was not authenticated, so Gmail rejected it.
Why it happens
- The message failed both SPF and DKIM, or passed them without alignment to the From: header domain, under a domain DMARC policy that rejects unauthenticated mail.
- Mail is being sent from a server that does not match the sender's address or is not covered by the domain's SPF/DKIM setup.
- A DMARC policy with strict alignment increases the likelihood of rejection.
How to fix it
- Domain owners: confirm SPF and DKIM are both set up (Google advises having them enabled at least 48 hours before enabling DMARC) and that outgoing mail passes at least one of them.
- Verify the passing method aligns with the domain in the From: header.
- Review daily DMARC reports to see which outgoing messages fail authentication, and check SPF, DKIM and DMARC results in message headers.
- Move the DMARC policy gradually from monitor to quarantine to reject as confidence in authentication grows.
- Legitimate senders who get this bounce: send through the correct outgoing server for your address, and contact your email provider if that does not fix it.
DNS record examples (replace example.com and the values with your own):
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; one SPF record per domain; use your provider's real include value
selector1._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER" ; selector and key come from your mail provider
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]" ; start at p=none, tighten only after reports look clean
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.26 This email has been blocked because the sender is unauthenticated
- 550 5.7.509 Access denied, sending domain [sender domain] does not pass DMARC verification and has a DMARC policy of reject