Error codes

550 5.7.40 Gmail: "the sending domain doesn't have a DMARC record"

Last updated 2026-10-09

What Gmail says

Your message was blocked because the sending domain doesn't have a DMARC record or the DMARC record doesn't specify a DMARC policy. Gmail requires all bulk email senders to add a DMARC record to their sending domain. See Set up DMARC (https://knowledge.workspace.google.com/admin/security/set-up-dmarc). To learn more about Gmail requirements for bulk email senders, visit Email sender guidelines (https://support.google.com/mail/answer/81126).

Source: Google, Gmail SMTP errors and codes, section 550 5.7.40, fetched 2026-10-08.

What it means, in plain words

No TXT record was found at _dmarc.yourdomain.com, or the record found has no p= tag. Google's text addresses bulk email senders.

Check your own domain

dig +short TXT _dmarc.yourdomain.com

Expected: one answer that starts with v=DMARC1 and contains p=none, p=quarantine or p=reject. The DMARC checker reads the record and names what is missing.

The fix

  • Publish one TXT record at _dmarc.yourdomain.com. The minimum that satisfies this error is v=DMARC1; p=none.
  • Add rua=mailto:an address you read, so the aggregate reports tell you who sends as your domain before you tighten the policy.
  • One record only at that name. RFC 9989 section 4.10: "If multiple DMARC Policy Records are returned for a single target, they are all discarded."

This error is live on your domain right now. If you need it gone today, the Humerly Emergency Fix is the direct route: your DNS, every change on your approval, verified before we call it done. Details and the price are on the Emergency Fix page.

Request the fix

What this page covers: the authentication records the receiver checked and how to correct them. It does not predict where a message lands once accepted; authentication and inbox placement are separate questions.

FAQ

Is p=none enough?

For this error, yes. Gmail's text asks for a record with a policy; p=none is a policy. Moving to quarantine or reject is a separate decision made after reading reports.

I have a DMARC record on my apex. Why did a subdomain get 5.7.40?

If the sending subdomain has no _dmarc record of its own, DMARC falls back to a record higher in the domain tree. Check both names: dig +short TXT _dmarc.sub.yourdomain.com and dig +short TXT _dmarc.yourdomain.com.

Does a DMARC record fix 5.7.26 as well?

No. 5.7.26 is about SPF and DKIM results. 5.7.40 is only about the DMARC record existing with a policy.

Related