550 5.7.26 The (E)MAIL FROM domain has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks
Sample bounce line
550-5.7.26 The (E)MAIL FROM domain [example.com] has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks with the ip: [203.0.113.10]. To best protect our users from spam and phishing, the message has been blocked. 550 5.7.26 For more information, go to https://support.google.com/mail/answer/81126
What it means
The envelope sender's domain publishes SPF ending in -all, which tells receivers to reject anything from an unlisted address, and the IP that delivered this message is unlisted. Gmail did exactly what the record asked for. The record is strict and incomplete at the same time.
Why it happens
- A new or changed sending service whose addresses were never added to the record.
- Mail forwarded by another host: the forwarder's IP is not in your record, and -all makes that fatal rather than merely a soft fail.
- A record that is correct for your main platform but excludes a secondary sender such as a CRM, helpdesk or invoicing tool.
- An SPF record that already fails with permerror from too many lookups, which under -all is treated as a failure to authorise.
How to fix it
- Add the sending service to the existing SPF record; the bounce names the IP it rejected, which tells you which service is missing.
- If mail must survive forwarding, consider ~all with DKIM and DMARC doing the real work, because DKIM survives forwarding and SPF does not.
- Check the lookup count: ten is the limit, and a permerror under -all looks the same as an unauthorised sender.
- Retest and confirm spf=pass in Authentication-Results before resuming the send.
DNS record examples (replace example.com and the values with your own):
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; exactly one SPF record per domain; the include value comes from your provider
selector1._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER" ; selector and key come from your mail provider
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.27 This message was blocked because it didn’t pass SPF authentication
- 550 5.7.26 This email has been blocked because the sender is unauthenticated