logo

Email error 550 5.7.26: Sender not authenticated (SPF/DKIM/DMARC)

The receiving provider requires authenticated mail and your message did not pass. Large providers reject or block bulk mail that fails SPF, DKIM or DMARC.

Sender or policy problem

What it means

The receiving provider requires authenticated mail and your message did not pass. Large providers reject or block bulk mail that fails SPF, DKIM or DMARC.

Common causes

  • No SPF record, or the sending service is not included in it.
  • DKIM signing is not set up, or the signature breaks in transit.
  • DMARC is missing, or the From domain does not align with SPF or DKIM.
  • Mail is sent through a new service that was never added to the domain settings.

How to fix it

  1. Publish an SPF record that includes every service that sends for your domain.
  2. Enable DKIM signing in your sending service and publish the key.
  3. Add a DMARC record, starting with a monitoring policy, and make sure the From domain aligns.
  4. Send a test to a mailbox you control and read the authentication results in the message headers.

How to prevent it

Most bounces come from addresses that were never checked. Verify each address before you send: syntax, domain, mailbox and risk are checked without sending a message. Test a single address with the free email checker or upload a whole list for bulk verification.

Verify an email address free · Clean a whole list · MX lookup · SPF, DKIM and DMARC checker

Frequently asked questions

Is this a problem with the recipient address?

No. It is about your domain setup. The same message to any address at that provider would be refused.

Which providers enforce this?

Major mailbox providers have tightened authentication rules for bulk senders, so treat SPF, DKIM and DMARC as required.

Other error codes

All email error codes