Gmail troubleshooting

Gmail error 550-5.7.26: check the authentication failure

Reviewed 22 September 2026

Start with the full bounce message. The code alone does not tell you which DNS record to change.

Read the text after the code

Google documents several 550 5.7.26 cases, including unauthenticated senders, SPF hard-fail rejections and rejection under a domain’s DMARC policy. The accompanying text identifies the case. Nearby codes have different meanings: 5.7.25 concerns reverse DNS, while 5.7.27 and 5.7.30 identify SPF and DKIM failures. Google’s SMTP error reference.

Find the service that sent this message

Save the rejection text, sending time, sending IP if shown, and provider name. Check the actual application that sent it. Your newsletter platform, website form and everyday mailbox may use different sending infrastructure.

Check its authentication

Gmail requires SPF or DKIM for all senders to personal Gmail accounts. Bulk senders must use both and publish DMARC; p=none is permitted. Bulk mail also needs alignment and other sending requirements. Google’s sender guidelines.

Verify through the same sending service

After correcting the provider configuration and allowing for DNS cache expiry, send a new test. Inspect the recipient’s authentication results and confirm the original rejection is resolved. Repeat this for each affected service.

Inboxproof’s domain check can help inspect public records. Its header analyzer helps you review a received message. Neither a configuration score nor a successful test promises placement for future mail.

Start with the published records

Look up DMARC, SPF, MX and common DKIM selectors without creating an account.

Check the domain