4.7.28 is Gmail asking you to slow down. It appears when the rate from an IP, a domain, or an authenticated identity rises faster than its recent history, and it clears when the rate returns to what Gmail considers normal for that sender.
Most common causes
- Message volume accelerated faster than the sender’s recent pattern
- A new or recently changed IP began sending significant traffic
- SPF or DKIM authenticated traffic crossed a temporary quota or reputation threshold
- A compromised application or credential caused an unexpected burst
What to verify next
- Preserve the complete 4.7.28 diagnostic because Gmail may identify the affected quota
- Pause aggressive retries and allow the temporary condition to cool down
- Compare recent volume, source IPs and authenticated domains
- Investigate unexpected traffic before resuming normal sending
Which identity is being rate-limited
Gmail’s text names the dimension: the sending IP, the SPF-authenticated domain, or the DKIM-signing domain. The distinction matters because the fix targets that identity. An IP limit affects everything from that address; a domain limit affects every platform sending as that domain.
Because it is temporary, your server should back off and retry. The queue will drain as Gmail’s view of the rate normalizes. Adding more connections or retrying faster makes it worse.
What causes a sudden rate
A new campaign much larger than usual, a new IP or platform with no history sending at full volume from the first hour, or an application bug — or compromised credential — sending in a loop. Investigate the last case first: an unexpected 4.7.28 with no planned campaign is a common early sign of abuse from your own infrastructure.
Warm new sending identities gradually and keep volume changes within a modest multiple of the previous day.
- The text names IP, SPF domain or DKIM domain.
- Unplanned rate spikes suggest a bug or compromise.
- New identities need warm-up.
Recovery
Reduce the rate from the named identity and let the queue retry. Check that the traffic is legitimate and expected. If a platform is involved, ask it to throttle Gmail delivery for your domain.
Persistent 4.7.28 with normal volume points at reputation rather than rate; review authentication alignment and Postmaster Tools for the domain.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Gmail’s rate model is relative to each sender’s history and is not published.
- Retry timing is decided by your mail server; Gmail does not specify a wait.
Common questions
Is 4.7.28 a block?
No. It is a temporary throttle. Mail delivers as the rate normalizes.
How long does it last?
Typically hours, depending on how far the rate exceeded history and how quickly it drops.
Can I avoid it for a big send?
Ramp over several days, spread the send over time, and keep authentication aligned so history accrues to your domain.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Gmail SMTP errors and codes.