Tools

550 5.7.26 This email has been blocked because the sender is unauthenticated

Provider: Gmail

Sample bounce line

550 5.7.26 This email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [example.com] with ip: [203.0.113.10] = did not pass. For instructions on setting up authentication, go to Email sender guidelines.

What it means

The sender is unauthenticated: Gmail requires every sender to authenticate with SPF or DKIM, and neither check passed, so the message was blocked.

Why it happens

How to fix it

  1. Publish an SPF record at the sending domain that includes all email senders for the domain (including the IP in the bounce).
  2. Turn on DKIM signing for the domain that sends the mail (DKIM key of 1024 bits or longer for personal Gmail, 2048 recommended).
  3. Make sure the authenticating domain is the same as the domain in the message From: header so DMARC alignment passes, and set up DMARC if you send 5,000 or more messages a day to Gmail.
  4. Send a test message and check the SPF, DKIM and DMARC results in the received message headers, then resend.

DNS record examples (replace example.com and the values with your own):

example.com.  IN  TXT  "v=spf1 include:_spf.your-mail-provider.example ~all"   ; one SPF record per domain; use your provider's real include value
selector1._domainkey.example.com.  IN  TXT  "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER"   ; selector and key come from your mail provider
_dmarc.example.com.  IN  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"   ; start at p=none, tighten only after reports look clean

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors