Ffile2fix
Sign in Get started

How to fix 550 5.7.1 / 5.7.26 email rejected (SPF or DMARC fail)

550 5.7.26 Unauthenticated email from example.com is not accepted due to domain's DMARC policy. Please contact the administrator of example.com domain if this was a legitimate mail.

The receiving mail server checked whether your message was really authorised by the domain in the From address, and the check failed under the domain's SPF or DMARC policy, so it refused the message permanently. Typically the server that sent the email is not listed in SPF and DKIM is missing or signed by a different domain.

Also appears as: 550 5.7.1 Message rejected: SPF check failed for example.com · 550-5.7.26 This mail has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. · 550 5.7.509 Access denied, sending domain example.com does not pass DMARC verification and has a DMARC policy of reject. · 554 5.7.5 Permanent error evaluating DMARC policy

Common causes

  • The sending server or service (website host, SMTP relay, newsletter tool, CRM) is not included in the domain's SPF record
  • DKIM is not enabled, or the signature uses the provider's domain, so DMARC alignment fails
  • A website contact form sends with From: the visitor's address (e.g. a Gmail user) through your host, which fails that domain's DMARC
  • More than one SPF record, or more than 10 DNS lookups in SPF, causing a permerror
  • Email is forwarded through a server that breaks SPF and modifies the message (breaking DKIM)
  • DNS changes after a migration left SPF pointing at the old host

How to fix it

  1. Read the bounce headers. Open the full bounce or the Authentication-Results header of a delivered test message. It shows spf=fail/pass, dkim=fail/pass and dmarc=fail with the domains checked.
  2. List every service that sends as your domain. Include your mailbox provider, the web server (WordPress/PHP mail), transactional email services and marketing tools. Each must be in SPF or sign with DKIM for your domain.
  3. Fix the SPF record. Keep exactly one TXT record starting with v=spf1 on the domain and add each sender's include or IP, ending with ~all or -all. Stay under 10 DNS lookups.
  4. Enable DKIM with your domain. Turn on DKIM in your provider (cPanel Email Deliverability, Google Workspace, Microsoft 365, your SMTP service) and publish the CNAME/TXT records it gives you, so mail is signed with d=yourdomain.
  5. Fix contact form senders. Send form emails From: an address on your own domain (e.g. [email protected]) and put the visitor's address in Reply-To. Send via authenticated SMTP rather than PHP mail().
  6. Publish or adjust DMARC. Start with v=DMARC1; p=none; rua=mailto:[email protected] to collect reports, and move to quarantine/reject once all legitimate sources pass.
  7. Re-test. Send to a Gmail address, use 'Show original' and confirm SPF, DKIM and DMARC all show PASS before resending to the rejecting recipient.

DNS TXT records (example)

; SPF - one record only
example.com.        TXT "v=spf1 include:_spf.google.com include:spf.mailprovider.example ip4:203.0.113.10 ~all"

; DMARC - start in monitoring mode
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:[email protected]"

How to stop it happening again

  • Add every new email-sending service to SPF and set up its DKIM before going live
  • Never send from addresses on domains you do not control
  • Review DMARC aggregate reports monthly to catch unknown senders

File2fix tools for this error

Frequently asked questions

Do I need both SPF and DKIM?

DMARC passes if either SPF or DKIM passes and aligns with the From domain, but having both is strongly recommended. Gmail and Yahoo require SPF and DKIM plus DMARC for bulk senders, and DKIM survives forwarding where SPF does not.

Can I just add more includes to SPF?

Only up to 10 DNS-querying mechanisms in total; beyond that SPF returns permerror and fails. Remove services you no longer use or ask providers for a single include.

Why do emails to Gmail bounce but Outlook accepts them?

Providers enforce authentication differently, and Gmail strictly applies the sender domain's DMARC policy and its own sender requirements. Fixing SPF, DKIM and alignment resolves it for all providers.