Error codes

550 5.7.30 Gmail: "This message was blocked because it didn't pass DKIM authentication"

Last updated 2026-10-09

What Gmail says

This message was blocked because it didn't pass DKIM authentication. Gmail requires bulk email senders to authenticate their email with DKIM. Authentication results: DKIM = did not pass

To set up DKIM for your sending domains, visit Set up DKIM (https://knowledge.workspace.google.com/admin/security/set-up-dkim). To learn more about Gmail requirements for bulk email senders, visit Email sender guidelines (https://support.google.com/mail/answer/81126).

Source: Google, Gmail SMTP errors and codes, section 550 5.7.30, fetched 2026-10-08.

What it means, in plain words

The message carried no DKIM signature, or it carried one whose public key could not be fetched or did not verify. Google's text addresses bulk email senders.

Check your own domain

Find the selector in the bounced message: the s= value in the DKIM-Signature header. Then:

dig +short TXT selector._domainkey.yourdomain.com

An empty answer means the key is not published at that name. A CNAME answer means the sending service hosts the key; follow it with the same dig on the target name.

The DMARC analyzer shows which selectors your recent mail was signed with, if you receive aggregate reports.

The fix

  • Enable DKIM signing in the sending service and publish the record it gives you at exactly the name it gives you.
  • If the record is a CNAME, publish the CNAME as given; do not copy the key text into a TXT.
  • Google's sender guidelines state: "Sending to personal Gmail accounts requires a DKIM key of 1024 bits or longer." Use 2048 where the service offers it.
  • Send one message to a Gmail mailbox you control and read dkim=pass in Authentication-Results.

This error is live on your domain right now. If you need it gone today, the Humerly Emergency Fix is the direct route: your DNS, every change on your approval, verified before we call it done. Details and the price are on the Emergency Fix page.

Request the fix

What this page covers: the authentication records the receiver checked and how to correct them. It does not predict where a message lands once accepted; authentication and inbox placement are separate questions.

FAQ

I published the DKIM record an hour ago. Why does it still fail?

DNS changes propagate on the record's TTL. Check with dig against a public resolver; if the answer is there and the message still fails, the signing side is not enabled or signs with a different selector.

My SPF passes. Do I still need DKIM?

For this specific error, yes: Gmail's text says bulk senders must authenticate with DKIM.

Does a 1024-bit key cause 5.7.30?

A key that is present and verifies does not produce this text. Key length is a separate requirement in Google's sender guidelines.

Related