SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
Email New Added 28 August 2026

SMTP: 550 5.7.26 unauthenticated email from domain not accepted

Gmail and Yahoo require bulk senders to authenticate with SPF and DKIM, publish a DMARC policy, align the From domain, and offer one-click unsubscribe. Mail that fails these is rejected outright rather than filed as spam.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Check all three records
dig +short TXT example.com | grep spf
dig +short TXT selector._domainkey.example.com
dig +short TXT _dmarc.example.com

# Minimum viable DMARC record
# _dmarc.example.com  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"

# Bulk senders must also send:
#   List-Unsubscribe: <https://example.com/u/abc>, <mailto:[email protected]>
#   List-Unsubscribe-Post: List-Unsubscribe=One-Click
# and keep spam complaints below 0.3%.

How to diagnose Email errors

SMTP errors follow a strict convention: a 4xx code is temporary and will be retried, a 5xx is permanent and will not. Beyond delivery mechanics, most modern email problems are authentication problems (SPF, DKIM and DMARC alignment) which cause silent filtering into spam rather than an explicit bounce, and therefore need to be checked proactively.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Read the full bounce message. The enhanced status code (for example 5.7.1) is far more specific than the three-digit code and usually names the exact policy that rejected the message.
  2. Test the SMTP conversation manually with swaks --to [email protected] --server smtp.example.com --tls. It shows each command and response.
  3. Verify SPF, DKIM and DMARC records with dig TXT example.com, dig TXT selector._domainkey.example.com and dig TXT _dmarc.example.com.
  4. Check DMARC alignment, not just presence: the domain in the From: header must align with the SPF or DKIM domain, or DMARC fails even when both pass individually.
  5. Confirm the sending IP is not on a blocklist and has valid reverse DNS. Missing PTR records cause rejection by many large providers.

Tools worth reaching for

  • swaks
  • dig TXT
  • openssl s_client -starttls smtp
  • postfix mail logs
  • DMARC aggregate reports

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

support.google.com

Related Email errors

See all 8 Email errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.