Gmail 550 5.7.26 Unauthenticated Email Error: How to Fix It
Gmail 550 5.7.26 rejects your email outright over failed authentication. Here is exactly what causes it and how to fix it in under an hour.

Gmail 550 5.7.26 means Gmail rejected your message outright because it could not confirm you are who you say you are. This is not a spam-folder problem, it is a bounce: the email never arrived at all. The fix is almost always the same, publishing SPF and DKIM correctly, and it usually takes under an hour once your DNS updates.
Some links in this article are affiliate links. If you buy through them, Mahatosoft may earn a small commission at no extra cost to you.
Google introduced this specific rejection as part of its authentication requirements for senders, rolled out through 2024. It affects any domain sending to Gmail addresses that has not published working SPF or DKIM, regardless of how much mail you send.
Check your records in two minutes
Put your domain into our free SPF, DKIM and DMARC checker. It reads your live DNS and tells you exactly which record is missing or broken, which is the direct cause of 550 5.7.26.
What 550 5.7.26 actually means
The full bounce message usually reads something like: “This mail is unauthenticated, which poses a security risk to the sender and Gmail’s users, and has been blocked.” The 550 status code means permanent rejection, and 5.7.26 is Google’s specific code for a sender that failed to prove its identity through SPF or DKIM. Gmail requires at least one of the two to pass, and for larger senders it requires more.
Who gets hit by 550 5.7.26
| Sending volume to Gmail | Minimum requirement |
|---|---|
| Any volume | At least SPF or DKIM must pass |
| Around 5,000 messages a day or more | SPF, DKIM and DMARC all required, with domain alignment |
| Bulk or marketing senders at that volume | One-click unsubscribe also required, plus a spam rate under 0.3% |
Most small businesses fall into the first row, which is good news: the fix is simpler than the full bulk sender checklist. Our bulk sender requirements guide covers the fuller list if you send newsletters or high-volume transactional mail.
Cause 1: no SPF record at all
SPF tells Gmail which servers are allowed to send mail for your domain. If none is published, Gmail has nothing to check, which alone is often enough to trigger 550 5.7.26 if DKIM is not set up either. Check for an SPF TXT record on your domain; if it is missing, this is your fix.
Cause 2: DKIM is not signing your mail
DKIM adds a cryptographic signature proving a message was not altered in transit. With Google Workspace, Microsoft 365 and most other providers, you publish the DKIM record in DNS and then separately enable signing in the admin console. Skipping the second step is a common reason DKIM shows as missing even though the DNS record exists.
Cause 3: sending from your website through unauthenticated PHP mail
WordPress, WooCommerce and contact form plugins default to sending through PHP’s built-in mail function, which sends from your hosting server rather than your real mail provider. Your SPF record does not list that server, and nothing signs it with DKIM, so it fails both checks and Gmail rejects it. Moving website mail onto authenticated SMTP, through your mail provider or a transactional service, fixes this directly.
Cause 4: alignment failures even with SPF and DKIM published
SPF and DKIM can both technically pass but still not satisfy Gmail if the domain they authenticate does not match the domain in your “From” address. This is called alignment, and it is what DMARC checks. If you send through a third-party platform using their sending domain instead of yours, your own domain gets no credit for that authentication.
Fixing 550 5.7.26 in order
- Check current records with the SPF checker.
- Publish or correct SPF, keeping it to a single record under the 10-lookup limit.
- Enable DKIM signing with your mail provider, not just the DNS record.
- Move website transactional mail onto SMTP through an authenticated account.
- Publish a DMARC record, starting at
p=noneso you can monitor before enforcing. - Send a test message to a Gmail address and check the result with “Show original.”
How to confirm the fix worked
Send a test email to a Gmail address you control, open it, click the three dots next to Reply, and choose Show original. You should see SPF, DKIM and DMARC each marked PASS at the top of the headers. Google’s own documentation on email sender guidelines explains exactly what each check looks for.
Does 550 5.7.26 only happen with Gmail?
The exact code is specific to Gmail, but the underlying requirement is not. Microsoft 365 and Outlook.com enforce a very similar rule through their own bounce code, and Yahoo Mail follows the same general standard. If you fix the authentication issue behind 550 5.7.26, you are very likely fixing the same root cause for every other major provider at the same time, since SPF, DKIM and DMARC are shared, open standards rather than something specific to Google.
Mistakes that keep 550 5.7.26 coming back
- Publishing a second SPF record instead of merging it into the existing one, which breaks SPF entirely rather than extending it.
- Enabling DKIM in DNS but forgetting to switch on signing in the mail provider’s admin console.
- Sending marketing or newsletter mail from a different domain to the one your main SPF and DKIM records cover.
- Assuming a fix is permanent after one passing test, without checking again after adding a new sending tool later.
Setting the records up for your provider
The exact DNS screen differs by registrar and mail provider. Our step-by-step setup guides cover 28 combinations, from Namecheap and GoDaddy through to Cloudflare DNS paired with Google Workspace, Microsoft 365, Zoho Mail or Titan.
Rather have it done for you?
We fix 550 5.7.26 and set up SPF, DKIM and DMARC correctly for $49 flat, usually the same day. Get it fixed, with a passing test sent back to you as proof.
Gmail 550 5.7.26: quick answers
Does 550 5.7.26 mean my email went to spam?
No. A 550 error is a hard bounce, meaning the message was rejected entirely and never delivered, not filtered into spam. You should have received a bounce notification back from your own mail server explaining the rejection.
Why did 550 5.7.26 start happening with no changes on my end?
Google’s authentication requirements were rolled out gradually through 2024 and continue to be enforced more strictly. A domain that used to get through without SPF or DKIM can start failing simply because Gmail’s checks caught up with it, not because you changed anything.
Will Google Workspace stop 550 5.7.26 automatically?
It helps, since Google Workspace mail is sent from trusted infrastructure, but you still need to publish your own domain’s SPF and enable DKIM signing. Without those, even Google Workspace mail can be rejected under your own domain’s failed authentication.
How long does it take to fix 550 5.7.26?
The DNS changes themselves usually take effect within an hour. If your domain also has a poor sending reputation from before the fix, some messages may still be filtered to spam for a few weeks even after authentication passes cleanly.



