SMTP error code

550 5.7.26: Gmail blocked your unauthenticated email

Gmail answers 550 5.7.26 when it can't confirm that a message really comes from the domain it claims. The address is fine; your authentication isn't. Once SPF or DKIM passes for your domain, the same message goes through.

Updated October 9, 2026 · 4 min read

Reply code
550 (RFC 5321)
Enhanced code
5.7.26 Multiple authentication checks failed (RFC 7372)
Sent by
Gmail and Google Workspace
Retry?
After SPF or DKIM passes

Verification would not have caught it

The recipient's address is fine. 550 5.7.26 is about your domain's SPF, DKIM and DMARC setup, which a mailbox check doesn't look at.

550 5.7.26 at Gmail: SPF fails, there is no DKIM signature and DMARC fails, so the unauthenticated email is blocked

What 550 5.7.26 means

A 550 5.7.26 bounce means the message failed authentication and the receiver won’t take it. In the IANA registry, X.7.26 comes from RFC 7372 and reads “Multiple authentication checks failed”: the message “failed more than one message authentication check, contrary to local policy requirements.” The registry doesn’t say which checks. Gmail’s texts do.

Gmail requires every sender to authenticate. Its own reply puts it plainly: “Gmail requires all senders to authenticate with either SPF or DKIM.” A 550 5.7.26 is the permanent form of that rule, so the message is not delivered and your server doesn’t retry.

The three Gmail messages behind 550 5.7.26

Excerpts from Gmail SMTP errors and codes:

Text after 550 5.7.26What failed
This email has been blocked because the sender is unauthenticated.Neither SPF nor DKIM passed
The (E)MAIL FROM domain [domain-name] has an SPF record with a hard fail policy (-all) but it fails to …The envelope sender’s SPF record ends in -all, and the sending server isn’t in it
Unauthenticated email from domain-name is not accepted due to domain's DMARC policy.The From domain fails DMARC, and its DMARC record asks for rejection

Gmail has relatives of this code. 421 4.7.26 rate-limits unauthenticated mail instead of blocking it, and 451 4.7.26 is the DMARC rejection when “temporary DNS failures prevent authentication”. For bulk senders, 550 5.7.27, 5.7.30 and 5.7.40 name the single failed check: SPF, DKIM, or a missing DMARC record. The list of SMTP error codes has all of them.

What usually causes it

How to fix 550 5.7.26

  1. Find out which domains the message used. Open the headers of a copy that reached any mailbox and look at the Authentication-Results line: the SPF domain (envelope sender), the DKIM d= domain and the From domain. The email header analyzer lays them out.
  2. Fix SPF. Keep a single SPF record that names every service sending as your domain. The SPF record generator builds it, and the SPF checker tests it.
  3. Turn on DKIM signing with your own domain in every service, and publish the keys they give you. Check the result with the DKIM checker.
  4. Publish DMARC. Start with p=none and a report address, so you see every source that sends as your domain before you tighten the policy. The DMARC generator writes the record.

A minimal setup for a domain that sends through Google Workspace looks like this:

example.com.         TXT  "v=spf1 include:_spf.google.com ~all"
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

There’s no delisting step: Gmail checks every message, so new messages that pass are judged normally again. DNS changes need time to spread, so test again after the record’s TTL has passed.

If the failing mail is forwarded

When the block hits mail that a forwarding service or mailing list passes on to Gmail, the original sender can’t fix it alone. Yahoo’s sender help gives the standard workarounds for the forwarding side: mailing lists put the list’s own address in From and the author in Reply-To, and forwarders can add ARC headers. Where possible, forward to Gmail without changing the message, so the original DKIM signature still verifies.

Would email verification have prevented it?

No. The recipient’s mailbox exists, and a verification would report it as deliverable. 550 5.7.26 depends only on your domain’s authentication, so the SPF, DKIM and DMARC checkers above are the right tools. The Gmail and Yahoo sender requirements list everything else large mailbox providers check.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What does 550 5.7.26 mean?

Gmail refused the message because it isn't authenticated: neither SPF nor DKIM passed, the envelope domain's SPF hard fail rejected it, or the From domain's DMARC policy asks receivers to reject unauthenticated mail. The text after the code says which.

How do I fix 550 5.7.26 in Gmail?

Make every service that sends as your domain pass SPF or DKIM for that domain. Add each sending service to your SPF record, turn on DKIM signing with your own domain at each service, and check that the domain in the From header matches.

Why do I get 550 5.7.26 although I have an SPF record?

The record may not include the server that sent this message, it may have a syntax error, or SPF passes only for your email service's own bounce domain, which doesn't match your From domain for DMARC. DKIM signing with your domain avoids most of these cases.

Does 550 5.7.26 mean my domain is blacklisted?

No. It's an authentication failure, not a reputation listing. Fix SPF, DKIM and DMARC and the block lifts for new messages; there is nothing to request removal from.

Related codes and guides

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Start using our email validation software today!

Get 100 validations per month for free