What 550 5.7.26 means
A 550 5.7.26 bounce means the message failed authentication and the receiver won’t take it. In the IANA registry, X.7.26 comes from RFC 7372 and reads “Multiple authentication checks failed”: the message “failed more than one message authentication check, contrary to local policy requirements.” The registry doesn’t say which checks. Gmail’s texts do.
Gmail requires every sender to authenticate. Its own reply puts it plainly: “Gmail requires all senders to authenticate with either SPF or DKIM.” A 550 5.7.26 is the permanent form of that rule, so the message is not delivered and your server doesn’t retry.
The three Gmail messages behind 550 5.7.26
Excerpts from Gmail SMTP errors and codes:
Text after 550 5.7.26 | What failed |
|---|---|
This email has been blocked because the sender is unauthenticated | Neither SPF nor DKIM passed |
The (E)MAIL FROM domain [domain-name] has an SPF record with a hard fail policy (-all) but it fails to … | The envelope sender’s SPF record ends in -all, and the sending server isn’t in it |
Unauthenticated email from domain-name is not accepted due to domain's DMARC policy | The From domain fails DMARC, and its DMARC record asks for rejection |
Gmail has relatives of this code. 421 4.7.26 rate-limits unauthenticated mail instead of blocking it, and 451 4.7.26 is the DMARC rejection when “temporary DNS failures prevent authentication”. For bulk senders, 550 5.7.27, 5.7.30 and 5.7.40 name the single failed check: SPF, DKIM, or a missing DMARC record. The list of SMTP error codes has all of them.
What usually causes it
- A new sending service. A newsletter tool, CRM, helpdesk or invoicing system sends with your domain in From, but isn’t in your SPF record and doesn’t sign with DKIM for your domain.
- A broken SPF record. A typo, two separate SPF records, or a record that has grown with too many includes. The SPF record guide explains the syntax.
- No DKIM, or DKIM with someone else’s domain. If a service signs with its own domain, DKIM passes but doesn’t match your From domain, and that doesn’t satisfy DMARC.
- Forwarding and mailing lists. Microsoft’s DMARC documentation notes that forwarding changes the envelope sender and can break DKIM. Mail you forward from another account to Gmail can fail although the original sender did everything right.
- Spoofing. Someone else sent mail claiming to be your domain. Then the block is doing its job.
How to fix 550 5.7.26
- Find out which domains the message used. Open the headers of a copy that reached any mailbox and look at the
Authentication-Resultsline: the SPF domain (envelope sender), the DKIMd=domain and the From domain. The email header analyzer lays them out. - Fix SPF. Keep a single SPF record that names every service sending as your domain. The SPF record generator builds it, and the SPF checker tests it.
- Turn on DKIM signing with your own domain in every service, and publish the keys they give you. Check the result with the DKIM checker.
- Publish DMARC. Start with
p=noneand a report address, so you see every source that sends as your domain before you tighten the policy. The DMARC generator writes the record.
A minimal setup for a domain that sends through Google Workspace looks like this:
example.com. TXT "v=spf1 include:_spf.google.com ~all"
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
There’s no delisting step: Gmail checks every message, so new messages that pass are judged normally again. DNS changes need time to spread, so test again after the record’s TTL has passed.
If the failing mail is forwarded
When the block hits mail that a forwarding service or mailing list passes on to Gmail, the original sender can’t fix it alone. Yahoo’s sender help gives the standard workarounds for the forwarding side: mailing lists put the list’s own address in From and the author in Reply-To, and forwarders can add ARC headers. Where possible, forward to Gmail without changing the message, so the original DKIM signature still verifies.
Would email verification have prevented it?
No. The recipient’s mailbox exists, and a verification would report it as deliverable. 550 5.7.26 depends only on your domain’s authentication, so the SPF, DKIM and DMARC checkers above are the right tools. The Gmail and Yahoo sender requirements list everything else large mailbox providers check.