550 5.7.27 This message was blocked because it didn’t pass SPF authentication
Sample bounce line
550-5.7.27 This message was blocked because it didn’t pass SPF authentication. Gmail requires bulk email senders to authenticate their email with SPF. Authentication results: SPF with 203.0.113.10 = did not pass. 550 5.7.27 For more information, go to https://support.google.com/mail/answer/81126
What it means
Gmail refused the message because SPF did not pass for the sending domain. Gmail requires senders of bulk mail to authenticate with SPF, and the bounce names the IP address it checked, so the record either does not exist, does not list that IP, or fails to resolve.
Why it happens
- No SPF record published for the domain in the envelope sender (the Return-Path / MAIL FROM domain), which is the domain SPF checks - not the one in the From: header.
- An SPF record that does not include the service actually sending, which is common after moving to a new provider or adding a newsletter or ticketing tool.
- Two or more SPF TXT records on the same name: that is a permanent error and nothing passes.
- More than ten DNS lookups chained through include: and redirect=, which makes the record fail with permerror however correct it looks.
How to fix it
- Find the envelope sender domain in the bounce and check SPF for THAT domain, not for the address your recipients see.
- Publish one SPF TXT record for it, listing every service that sends on your behalf, and end it with ~all or -all.
- If a record already exists, add the missing provider to the existing record rather than publishing a second one.
- Count the lookups: include:, a, mx, ptr, exists: and redirect= each cost one, and ten is the hard limit.
- Send a test message and read Authentication-Results in the received headers: it must say spf=pass.
DNS record examples (replace example.com and the values with your own):
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; exactly one SPF record per domain; the include value comes from your provider
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.23 SPF validation failed
- 550 5.7.26 This email has been blocked because the sender is unauthenticated