Tools

550 5.7.26 The (E)MAIL FROM domain has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks

Provider: Gmail

Sample bounce line

550-5.7.26 The (E)MAIL FROM domain [example.com] has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks with the ip: [203.0.113.10]. To best protect our users from spam and phishing, the message has been blocked. 550 5.7.26 For more information, go to https://support.google.com/mail/answer/81126

What it means

The envelope sender's domain publishes SPF ending in -all, which tells receivers to reject anything from an unlisted address, and the IP that delivered this message is unlisted. Gmail did exactly what the record asked for. The record is strict and incomplete at the same time.

Why it happens

How to fix it

  1. Add the sending service to the existing SPF record; the bounce names the IP it rejected, which tells you which service is missing.
  2. If mail must survive forwarding, consider ~all with DKIM and DMARC doing the real work, because DKIM survives forwarding and SPF does not.
  3. Check the lookup count: ten is the limit, and a permerror under -all looks the same as an unauthorised sender.
  4. Retest and confirm spf=pass in Authentication-Results before resuming the send.

DNS record examples (replace example.com and the values with your own):

example.com.  IN  TXT  "v=spf1 include:_spf.your-mail-provider.example ~all"   ; exactly one SPF record per domain; the include value comes from your provider
selector1._domainkey.example.com.  IN  TXT  "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER"   ; selector and key come from your mail provider

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors