550 5.7.29 This message was blocked because it wasn’t sent over a TLS connection
Sample bounce line
550-5.7.29 This message was blocked because it wasn’t sent over a TLS connection. Gmail requires all bulk email senders to use TLS/SSL for SMTP connections. 550 5.7.29 For more information, go to https://support.google.com/mail/answer/81126
What it means
The connection that delivered this message to Gmail was not encrypted. Gmail requires bulk senders to use TLS, so the message was refused at the transport level, before anything about its content mattered.
Why it happens
- A sending server or appliance with opportunistic TLS switched off, or with no certificate configured at all.
- An old script or device that connects on port 25 and never issues STARTTLS.
- A firewall or inspection appliance in the path that strips the STARTTLS capability from the server's reply, which silently downgrades every connection it touches.
- An outbound relay that is itself a legacy host, even when the application that submitted the mail used TLS.
How to fix it
- Turn on TLS for outbound SMTP on the host that actually talks to Gmail, which is the last hop, not the first.
- If a security appliance sits in front of it, check whether it is removing STARTTLS from the server greeting and stop it doing so.
- Test the hop with a direct STARTTLS connection and confirm the handshake completes and the certificate is valid.
- Where a device genuinely cannot do TLS, relay it through a server that can, rather than sending straight to Gmail.
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.