550 5.7.40 Your message was blocked because the sending domain doesn’t have a DMARC record or the DMARC record doesn’t specify a DMARC policy
Sample bounce line
550-5.7.40 Your message was blocked because the sending domain doesn’t have a DMARC record or the DMARC record doesn’t specify a DMARC policy. Gmail requires all bulk email senders to add a DMARC record to their sending domain. 550 5.7.40 For more information, go to https://support.google.com/mail/answer/81126
What it means
Gmail looked for a DMARC record on the sending domain and either found none at all or found a record with no usable policy, so it refused the message. This is a DNS problem, not a content problem: no amount of rewriting the message will clear it.
Why it happens
- No TXT record at _dmarc.<domain> - the most common case, and the one Gmail's bulk-sender rules made fatal.
- A record published at the domain itself instead of at the _dmarc subdomain name.
- A record present but with no p= tag, or with a p= value that is not none, quarantine or reject, which means it specifies no policy.
- Two DMARC TXT records on the same name, which no receiver will treat as a valid policy.
How to fix it
- Publish one TXT record at _dmarc.<your domain> with at least v=DMARC1 and a p= value.
- Start at p=none with a rua= address so you receive reports and can see what is really sending as you, then tighten to quarantine and reject.
- Get SPF or DKIM aligned with the From: domain first: DMARC only passes when one of them passes AND matches the domain the recipient sees.
- Read the record back from DNS with a public resolver before you retry the send; a record that exists only in your registrar's draft is not published.
DNS record examples (replace example.com and the values with your own):
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]" ; start at p=none, tighten only after the reports look clean
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; exactly one SPF record per domain; the include value comes from your provider
selector1._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER" ; selector and key come from your mail provider
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.26 Unauthenticated email from [domain] is not accepted due to domain's DMARC policy
- 550 5.7.509 Access denied, sending domain [sender domain] does not pass DMARC verification and has a DMARC policy of reject