Gmail returns 5.7.26 when a message arrives without the authentication its sender guidelines require. Since 2024 every sender needs SPF or DKIM to pass, and bulk senders need both plus DMARC alignment. The rejection text names the exact requirement that was not met.
Most common causes
- SPF did not pass for the actual envelope-sender path
- DKIM validation failed or no valid signature was present
- DMARC alignment did not have a passing aligned path
- A third-party sender is using an unconfigured bounce or signing domain
What to verify next
- Paste the full bounce into Mail Failure Doctor
- Analyze the domain’s SPF dependency graph
- Confirm the DKIM signing domain and selector from a real message
- Test DMARC alignment for the real sending service
Read the sentence after the code
Gmail appends a specific reason: no SPF or DKIM, SPF failure for the envelope domain, a DKIM signature that did not verify, or DMARC that did not pass. Each points at a different fix, and the numeric code alone does not distinguish them.
The envelope sender that SPF evaluates is frequently not the visible From address. Sending platforms use their own bounce domain unless a custom one is configured, so SPF can be correct for your domain and still irrelevant to the message Gmail evaluated.
- The diagnostic text after 5.7.26 identifies which mechanism failed.
- SPF is evaluated against the Return-Path domain, not From.
- Bulk senders (5,000+ per day to Gmail) need SPF, DKIM and DMARC alignment.
The usual causes
A new sending platform that was never authorized: the platform sends from its own infrastructure, SPF does not list it, and no DKIM selector was configured. This is the most common case after onboarding a marketing or transactional tool.
A DKIM signature that broke in transit — a gateway added a footer or rewrote a link — or a DNS change that removed the selector while mail was still being signed with the old key. Forwarding also strips SPF alignment, which matters once DMARC is enforced.
Confirm before changing DNS
Paste the complete bounce into Mail Failure Doctor to extract the affected domain and the mechanism Gmail named. Then send a test message through the same platform to a mailbox you control and read Authentication-Results in the header: it records spf, dkim and dmarc as Gmail saw them.
Fix the specific path. For SPF, add the platform to the record and check the lookup budget. For DKIM, publish the platform’s selector and verify it resolves. For DMARC, configure a custom bounce domain or custom DKIM signing so an aligned path exists.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisDMARC Alignment Lab
Compare visible From, envelope sender and DKIM identities without reducing the result to a pass/fail label.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- The rejection reflects the message Gmail evaluated; a passing DNS check today does not explain a historical bounce if DNS changed since.
- Gmail also applies reputation and content filtering that is not expressed through 5.7.26.
Common questions
SPF passes on my checker. Why does Gmail say it failed?
The checker tested your domain; Gmail tested the envelope sender of the actual message, which is often the platform’s bounce domain. Read the Return-Path in a delivered header.
Do I need DKIM if SPF passes?
For low volume, one passing mechanism satisfies the baseline. For bulk sending both are required, and DKIM is the mechanism that survives forwarding.
How long until the fix takes effect?
DNS changes propagate within their TTL. Retry after the previous TTL of the changed record has elapsed and verify with a real message.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Gmail SMTP errors and codes.