550 5.7.26 unauthenticated email: passing the Gmail and Yahoo sender rules.

Gmail is refusing your mail because it could not tie the message to your domain. Since 2024 Gmail and Yahoo require authentication from everyone and full SPF, DKIM and DMARC from bulk senders. The bounce tells you which rule you broke; the DNS tells you why.

Written by · Published 2026-09-30 · 7 min read

Two different 5.7.26 bounces

Read the text after the code. Gmail uses 5.7.26 for two distinct failures, and they have different fixes:

550-5.7.26 This mail is unauthenticated, which poses a security risk to the
550-5.7.26 sender and Gmail users, and has been blocked. The sender must
550-5.7.26 authenticate with at least one of SPF or DKIM.

Unauthenticated: neither SPF nor DKIM passed for the message. Gmail has nothing to link it to your domain at all.

550-5.7.26 Unauthenticated email from example.com is not accepted due to
550-5.7.26 domain's DMARC policy.

DMARC policy: SPF or DKIM may have passed, but not for a domain that aligns with the From address, and your own DMARC record says to reject such mail. Gmail is doing what you asked.

A 421 4.7.26 is the temporary form, used while a sender is being rate limited for the same reasons. Treat it as a warning that the 550 is coming.

What the rules require

RequirementEveryoneBulk senders (5,000+ a day to Gmail)
SPF or DKIM passesYes, at least oneBoth
DMARC record publishedRecommendedYes, p=none is enough
From domain aligned with SPF or DKIMRecommendedYes
Forward and reverse DNS for sending IPsYesYes
TLS for transmissionYesYes
Spam complaint rateUnder 0.3%Under 0.3%, ideally under 0.1%
One-click unsubscribe (RFC 8058) on marketing mailNoYes

Yahoo's requirements are essentially the same, and Microsoft's consumer mail (Outlook.com, Hotmail) began enforcing similar rules for high-volume senders in 2025 with its own code, 550 5.7.515. Fixing one fixes all three.

Find the cause

Run your sending domain (the one in the From address) through the email deliverability checker. For the unauthenticated bounce, look at:

For the DMARC policy bounce, the question is alignment. Open a message that was delivered somewhere (or a DMARC aggregate report) and read Authentication-Results:

DMARC needs at least one of those to pass for example.com (or a subdomain of it, with the default relaxed alignment). SPF vs DKIM vs DMARC walks through alignment with examples.

The other requirements

Before you change DNS

Do not respond to a DMARC bounce by weakening the policy unless you have to. The bounce means the policy is working: something is sending as you without authentication. Fix that sender and the policy can stay. For a quick overall view, Domain Health grades SPF, DKIM and DMARC alongside DNS, TLS and HTTP in one run.

All guides · All tools