Tools

550 5.7.27 This message was blocked because it didn’t pass SPF authentication

Provider: Gmail

Sample bounce line

550-5.7.27 This message was blocked because it didn’t pass SPF authentication. Gmail requires bulk email senders to authenticate their email with SPF. Authentication results: SPF with 203.0.113.10 = did not pass. 550 5.7.27 For more information, go to https://support.google.com/mail/answer/81126

What it means

Gmail refused the message because SPF did not pass for the sending domain. Gmail requires senders of bulk mail to authenticate with SPF, and the bounce names the IP address it checked, so the record either does not exist, does not list that IP, or fails to resolve.

Why it happens

How to fix it

  1. Find the envelope sender domain in the bounce and check SPF for THAT domain, not for the address your recipients see.
  2. Publish one SPF TXT record for it, listing every service that sends on your behalf, and end it with ~all or -all.
  3. If a record already exists, add the missing provider to the existing record rather than publishing a second one.
  4. Count the lookups: include:, a, mx, ptr, exists: and redirect= each cost one, and ten is the hard limit.
  5. Send a test message and read Authentication-Results in the received headers: it must say spf=pass.

DNS record examples (replace example.com and the values with your own):

example.com.  IN  TXT  "v=spf1 include:_spf.your-mail-provider.example ~all"   ; exactly one SPF record per domain; the include value comes from your provider

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors