Error codes

550 5.7.26 Gmail: "This email has been blocked because the sender is unauthenticated"

Last updated 2026-10-09

What Gmail says

Gmail uses 550 5.7.26 for three different situations. Match your bounce to one of them.

Text A

This email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [domain-name] with ip: [ip-address] = did not pass. For instructions on setting up authentication, go to Email sender guidelines (https://support.google.com/mail/answer/81126#authentication).

Text B

The (E)MAIL FROM domain [domain-name] has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks with the ip: [ip-address]. To best protect our users from spam and phishing, the message has been blocked. For more information, go to Email sender guidelines (https://support.google.com/mail/answer/81126#authentication).

Text C

Unauthenticated email from domain-name is not accepted due to domain's DMARC policy. Contact the administrator of domain-name domain if this was legitimate email. To learn about the DMARC initiative, go to Control unauthenticated email from your domain (https://support.google.com/mail/answer/2451690).

Source: Google, Gmail SMTP errors and codes, section 550 5.7.26, fetched 2026-10-08.

What it means, in plain words

  • Text A: neither SPF nor DKIM passed for this message. Google's text says "Gmail requires all senders to authenticate with either SPF or DKIM."
  • Text B: your SPF record ends in -all (hard fail) and the sending IP is not in it. Google's text gives that as the reason the message was blocked.
  • Text C: your DMARC record says p=reject or p=quarantine and the message did not pass aligned SPF or DKIM. Google's text names your DMARC policy as the reason.

Check your own domain

Replace yourdomain.com with the domain in the From address of the bounced message.

SPF record:

dig +short TXT yourdomain.com | grep v=spf1

DMARC record:

dig +short TXT _dmarc.yourdomain.com

DKIM, using the selector from the bounced message's DKIM-Signature header (s= value):

dig +short TXT selector._domainkey.yourdomain.com

Or paste the bounced message's headers into the header analyzer and read the Authentication-Results line.

The fix

  • Text A: publish SPF with the sending service's include, or set up DKIM signing for the sending service, or both. Text A asks for one of the two to pass.
  • Text B: add the sending IP or the sending service's include to the SPF record, keep -all. Do not switch to +all.
  • Text C: the rejection came from your DMARC policy working as designed. Either the sending service is not authorised (fix SPF or DKIM alignment for it) or the message is not yours (then nothing to fix; the policy did its job).
  • After the change, send one message to a Gmail mailbox you control and read its Authentication-Results header.

This error is live on your domain right now. If you need it gone today, the Humerly Emergency Fix is the direct route: your DNS, every change on your approval, verified before we call it done. Details and the price are on the Emergency Fix page.

Request the fix

What this page covers: the authentication records the receiver checked and how to correct them. It does not predict where a message lands once accepted; authentication and inbox placement are separate questions.

FAQ

Does 550 5.7.26 mean my domain is blocklisted?

No. It means this message did not pass authentication (SPF, DKIM, or your own DMARC policy).

I use Google Workspace. Why did Gmail reject my own mail?

SPF checks the IP of the server that sent the message, not where your mailbox is hosted (RFC 7208). A tool that sends on your behalf needs your SPF include, or a DKIM key published for your domain.

Will fixing SPF fix all three texts?

Text B yes. Text A needs SPF or DKIM. Text C needs the passing result to also align with the From domain.

Related