Tools

550 5.7.30 This message was blocked because it didn’t pass DKIM authentication

Provider: Gmail

Sample bounce line

550-5.7.30 This message was blocked because it didn’t pass DKIM authentication. Gmail requires bulk email senders to authenticate their email with DKIM. Authentication results: DKIM = did not pass. 550 5.7.30 For more information, go to https://support.google.com/mail/answer/81126

What it means

Gmail refused the message because it carried no valid DKIM signature. Either nothing signed it, or a signature was present and did not verify against the public key in DNS.

Why it happens

How to fix it

  1. Turn on DKIM signing at every service that sends as your domain; a provider that cannot sign cannot be used for bulk mail to Gmail.
  2. Publish the provider's public key at the selector it tells you to use, and read it back from DNS before sending.
  3. After a key rotation, keep the old selector published until no mail signs with it any more.
  4. Send a test message and read Authentication-Results: it must say dkim=pass, and the d= value should be your own domain.

DNS record examples (replace example.com and the values with your own):

selector1._domainkey.example.com.  IN  TXT  "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER"   ; selector and key come from your mail provider

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors