How to Fix Gmail SMTP Error 550-5.7.26 Authentication Failure
Question details
Users are experiencing email delivery rejections from Gmail, receiving an SMTP Error 550-5.7.26 due to unauthenticated senders and failed DKIM or SPF checks.

- Product
- Gmail / Microsoft 365 Exchange
- Device & OS
- not provided
- Scenario
- Sending emails to Gmail addresses from a custom domain, third-party application, or multifunction device.
- Observed behavior
- Gmail rejects the outgoing email and returns a Non-Delivery Report (NDR) citing Error 550-5.7.26, indicating that the email is unauthenticated and fails the domain's DMARC, SPF, or DKIM policies.
Ensure you have administrative access to your domain's DNS hosting provider and your email service admin portal (such as the Microsoft 365 Exchange Admin Center) before attempting to modify authentication records.
Configure SPF and DKIM Records for Your Domain
Setting up accurate Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) records is mandatory to pass Gmail's strict authentication checks and prevent email rejection.
Major email providers like Google have enforced strict email authentication rules. If your domain sends an email without proper cryptographic signatures or authorized IP addresses, Gmail will block it.
You must publish the correct TXT and CNAME records in your domain's DNS settings.
Determine whether your sending domain uses Microsoft 365, Google Workspace, or another SMTP relay service to find the exact SPF value required for your domain.
Log into your DNS hosting provider and add or update a TXT record for SPF. For Microsoft 365, this typically includes 'v=spf1 include:spf.protection.outlook.com -all'.
Generate a DKIM key pair in your email admin center (e.g., Microsoft 365 Defender portal) and publish the provided CNAME or TXT records in your DNS settings to enable cryptographic signing.
Wait up to 24-48 hours for the new DNS records to propagate globally across the internet before sending test emails to a Gmail address.

Run a Message Trace in Microsoft 365
If your domain uses Microsoft 365, running an extended message trace helps identify the exact application, device, or routing issue failing the authentication.
Improve Your Productivity with WPS Office
While troubleshooting email delivery issues and configuring complex DNS settings, you still need a reliable office suite to manage your IT reports, server configurations, and business documents. WPS Office is a lightweight, highly compatible alternative to Microsoft Office that is completely free to use.
- 1. Download WPS Office: Go to the official WPS Office website and download the free installer tailored for your operating system.
- 2. Install the Suite: Run the setup file and follow the straightforward on-screen prompts to install the software on your device.
- 3. Manage your files: Open WPS Office to view, edit, and organize your spreadsheets, reports, and Microsoft Office documents with seamless compatibility.

Frequently Asked Questions
What does Gmail SMTP Error 550-5.7.26 mean?
This error signifies that Gmail has rejected your incoming email because the sending domain failed necessary authentication checks. Gmail strictly requires all external senders to authenticate their emails using SPF or DKIM protocols to prevent spam, phishing, and spoofing.
How long does it take for SPF and DKIM changes to take effect?
DNS changes typically take anywhere from a few minutes up to 48 hours to propagate fully across the internet. If you have just updated your SPF or DKIM records, you may need to wait for this propagation period before Gmail successfully validates and accepts your emails again.
Can a multifunction printer cause SMTP Error 550-5.7.26?
Yes. If a scanner, multifunction printer, or third-party web application sends emails using your domain name without routing through your authenticated SMTP server, the emails will fail SPF and DKIM checks, resulting in this specific Gmail rejection error.
How do I check if my domain's DKIM is working correctly?
You can send a test email to a free DKIM testing service online, or use diagnostic tools like MXToolbox. Perform a DKIM lookup using your domain name and DKIM selector to verify that the public key is correctly published and readable in your DNS settings.




