One documented variant begins: “550 5.7.26 This email has been blocked because the sender is
unauthenticated.” Google’s SMTP list includes variants for SPF and DKIM failing, an SPF
hard-fail policy (-all) rejecting the sending IP, and a domain DMARC policy rejecting
unauthenticated mail. Start with the complete NDR and its authentication results. See
Gmail SMTP errors and codes.
Google says all senders to personal Gmail accounts must authenticate with SPF or DKIM. Bulk senders
must use SPF, DKIM, and DMARC, and direct mail must align the visible From: domain with
the SPF or DKIM domain. See Gmail email sender guidelines.
This page covers personal Gmail recipients—addresses ending in @gmail.com or
@googlemail.com. Google’s FAQ excludes Google Workspace inbound and intra-domain mail, so
do not transfer this scope to an enterprise tenant. See the
Gmail sender guidelines FAQ.
Classify the complete NDR
Do not treat every 5.7.26 as “add DMARC.” Read the text after the code: it may show both
SPF and DKIM failed, an SPF -all hard fail for the evaluated envelope domain, or rejection
under the sender domain’s DMARC policy. These are different branches. See
Google’s SMTP error variants.
Preserve the exact NDR, including the domain and IP Gmail names, before assigning a DNS or ESP change.
Diagnostic decision table
Use separate evidence and unknown fields so an operator can hand over one bounded action.
| Evidence | Unknown | Owner | Action |
|---|---|---|---|
NDR has 550 5.7.26; recipient is @gmail.com or @googlemail.com; full text is saved. |
Whether this is personal Gmail, a forwarded message, or another Google scope; whether it repeats on the same path. | Campaign or deliverability operator. | Record recipient scope, sender, ESP or SMTP path, message type, time, and NDR. Keep credentials and raw customer data out of the handoff. |
| NDR reports SPF and DKIM did not pass. | Which envelope and DKIM signing domains Gmail evaluated, and whether the ESP used the intended account. | ESP operator with the DNS owner. | Inspect a sanitized receiver header or ESP event for 5321.MailFrom, DKIM d=, selector, and results. |
NDR identifies an SPF hard fail (-all) for the (E)MAIL FROM domain. |
Whether every authorized sender is represented in that domain’s SPF record and whether the IP belongs to the intended provider. | DNS owner and ESP operator. | Compare the evaluated envelope domain and IP with the ESP’s documented sending setup. Update only the reviewed, provider-supported record. |
| NDR cites the sender domain’s DMARC policy. | Whether SPF or DKIM passed and aligned with the visible From: domain on this message. |
DNS owner, ESP operator, and domain policy owner. | Review the DMARC record, evaluated SPF/DKIM identities, and alignment. Do not weaken a policy just to hide an unverified sending path. |
| Sender is near Google’s bulk threshold or sends from several subdomains. | Whether the sender is permanently classified as bulk and whether all messages from the same primary domain were counted. | Campaign operations owner. | Google defines bulk as close to 5,000 or more messages to personal Gmail within 24 hours, counting the same primary domain; classify the route before applying bulk requirements. See Google’s bulk-sender FAQ. |
Collect evidence in the sending path
- Name the recipient scope. Record the exact recipient domain and whether it is personal Gmail.
- Name the message path. Record the ESP or SMTP service, visible
From:, envelope or return-path domain, and message type; a mailbox reply, marketing platform, and form relay can use different identities. - Check SPF, DKIM, and alignment as Gmail evaluated them. Google says SPF should include all senders for the domain, DKIM verifies the signing domain, and direct mail must align
From:with SPF or DKIM. Bulk senders also need DMARC; Google says its enforcement policy can benone. See Google’s sender guidelines. - Check forwarding only when relevant. Google notes that ARC can show a forwarded message previously failed authentication even when SPF or DKIM now passes. See Google authentication help.
Constructed example: an agency sends from client.example through an ESP.
The NDR reports SPF failed for bounce.vendor.example and DKIM failed. That is enough to
route the case to the ESP and DNS owners; it is not enough to say whether the record is missing, the
selector is wrong, the service used another path, or the visible sender is misaligned. Those
distinctions require the evaluated header and current ESP settings.
What establishes resolution—and what does not
For one direct path to personal Gmail, useful resolution evidence is a new authorized test that is
accepted without 550 5.7.26, with Gmail’s message details or the receiver header showing
SPF or DKIM pass and the expected aligned domain. A bulk sender should also show the required SPF, DKIM,
and DMARC state. See Google’s sender guidelines.
Keep the test date, recipient scope, sender domain, ESP, and sanitized result together.
That result cannot prove inbox placement, domain or IP reputation, list consent, message content quality, forwarding behavior, or delivery to every Gmail recipient. It cannot certify a Google Workspace tenant or another provider. Google also says authentication alone does not guarantee delivery; it is one part of classification and acceptance. See Google’s authentication guidance.
Scope fit / one sending path
When a scoped handoff helps
If one real domain, one ESP path, and one unresolved Gmail rejection still need an accountable interpretation, request scope for one sending path. Folderly Launch Audit remains the existing US$495 manual service for one domain or subdomain and one ESP/CRM path. After payment and complete intake, the agreed start begins a 48-hour report window with up to five prioritized actions and owners, a 45-minute handoff, and one recheck within seven days of the report. It is read-only advice; your authorized operator makes DNS and ESP changes. There is no implementation, warming, reputation recovery, list repair, multidomain review, or inbox-placement guarantee. Do not send credentials, raw headers, or customer lists in the request.
Prepare an editable scope draft
Sources and applicability. Sources reviewed 28 September 2026:
Gmail SMTP errors and codes,
Gmail email sender guidelines,
Gmail sender guidelines FAQ,
Control unauthenticated mail from your domain,
and Check if your Gmail message is authenticated.
The SMTP page lists multiple 550 5.7.26 variants, so the code alone cannot identify the
failed mechanism. The sender guidelines and FAQ are scoped to personal Gmail; the FAQ says bulk status is
based on close to 5,000 or more messages in 24 hours, counts the same primary domain, and becomes
permanent after the threshold is met. Google’s public guidance can change, and this page reports no
tested domain, customer launch, benchmark, ranking, traffic, or payment result.