550 5.7.26
Gmail blocked your email because the sender is unauthenticated. Here is the fix.
Since November 2025, Gmail rejects unauthenticated mail at the SMTP level instead of sending it to spam. If you got this bounce, Gmail could not verify that the message really came from your domain. The fix is in your DNS: SPF, DKIM and DMARC.
The bounce looks like this
550-5.7.26 This mail has been blocked because the sender is unauthenticated. 550-5.7.26 Gmail requires all senders to authenticate with either SPF or DKIM. 550-5.7.26 550-5.7.26 Authentication results: 550-5.7.26 DKIM = did not pass 550-5.7.26 SPF [example.com] with ip: [203.0.113.25] = did not pass 550-5.7.26 550-5.7.26 For instructions on setting up authentication, go to 550 5.7.26 https://support.google.com/mail/answer/81126#authentication
The lines under "Authentication results" are the diagnosis: they tell you whether SPF, DKIM or both failed for the message Gmail rejected.
First: check what Gmail sees for your domain
Run a free scan of your DMARC, SPF and DKIM records. It takes seconds and shows exactly which requirement you are failing.
How to fix it, step by step
- 1
Confirm which mechanism failed
The bounce itself tells you. "SPF ... did not pass" means the sending IP is not authorized in your SPF record. "DKIM = did not pass" means the message had no valid DKIM signature for your domain. If both failed, Gmail had no way to verify the mail at all and rejected it.
- 2
Fix SPF: authorize everything that sends as your domain
Your SPF record (a TXT record on your domain) must include every service that sends mail for you: your mailbox provider, CRM, invoicing tool, marketing platform. A missed include is the single most common cause of this bounce. Also check you have only ONE SPF record and stay under 10 DNS lookups - either mistake invalidates the whole record.
- 3
Fix DKIM: sign with your own domain
Enable DKIM in each sending service and publish the CNAME or TXT records they give you. Signing with the vendor default (like a shared sendgrid.net identity) is no longer enough for Gmail - the signature should be for your domain.
- 4
Publish a DMARC record
Gmail requires bulk senders to have at least v=DMARC1; p=none with a rua reporting address. Without it, even mail that passes SPF and DKIM can be throttled or rejected. Start at p=none to collect data, then move to p=quarantine or p=reject once reports confirm all legitimate senders pass.
Related guides
Managing this for multiple client domains?
If you are an MSP or agency, this bounce is now a recurring support ticket across your whole client base. DMARC Fleet is building continuous monitoring with per-client white-label reports - transparent pricing from $29/mo for 10 domains. Join the waitlist.