How to Fix Microsoft Encrypted Email Rejected by DMARC Policy
Question details
The recipient cannot receive the one-time passcode for a Microsoft encrypted email because their Google Workspace server rejects the message due to a DMARC policy failure.

- Product
- Microsoft Outlook
- Device & OS
- not provided
- Scenario
- A recipient using a Google-hosted email address attempts to open a Microsoft encrypted message and needs to receive a one-time passcode.
- Observed behavior
- The one-time passcode email from microsoft.com is rejected with SMTP error 550-5.7.26 due to failing the recipient domain's DMARC policy.
Ensure you have contact with the recipient's Google Workspace IT administrator, as this rejection happens at the recipient's mail provider level. Verify the exact SMTP error code received in the non-delivery report (NDR).
Contact Google Workspace Admin to Adjust Mail-Routing Rules
The most effective way to resolve this is by configuring the recipient's email environment to accept Microsoft's message-delivery domains.
Because the rejection occurs at the recipient's mail provider before the encrypted message sign-in process completes, the recipient's IT administrator must intervene. They should not disable DMARC broadly, but rather make verified adjustments to allow Microsoft's automated domains.
Identify the exact delivery domain failing the DMARC check by reviewing the SMTP error 550-5.7.26 logs in the non-delivery report.
Have the Google Workspace administrator navigate to their Google Admin Console and access the email security and routing settings.
Add Microsoft's message-delivery domains to the allowed sender list or adjust quarantine rules to bypass DMARC rejection for these specific system emails.
Check the relevant email security logs to confirm the changes have propagated and that the passcodes are now being delivered.

Use an Alternative Secure-Sharing Method
If adjusting the recipient's server rules is not immediately possible, the sender should utilize a different secure method to deliver the information.
Discover a Seamless Alternative with WPS Office
While email server routing rules are managed by IT administrators, managing your everyday documents shouldn't be complicated. WPS Office provides a lightweight, free alternative to Microsoft Office with high compatibility, enabling you to securely create, edit, and share files across platforms.

Frequently Asked Questions
What does SMTP error 550-5.7.26 mean?
This error indicates that the email was rejected because it failed the recipient domain's DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy, meaning the sender's domain could not be successfully authenticated.
Why does the one-time passcode email fail DMARC?
The one-time passcode is generated by an automated Microsoft system. If the recipient's mail server strictly enforces DMARC, it may flag these automated emails as unauthenticated if Microsoft's delivery IPs or domains aren't explicitly whitelisted by the receiving server.
Can the sender fix this DMARC rejection issue?
No, the sender cannot fix this directly through their email client. The resolution requires the recipient's IT administrator (such as the Google Workspace admin) to adjust their mail-routing and quarantine rules to accept Microsoft's system emails.
Is it safe to disable DMARC to receive these emails?
No, broadly disabling DMARC is highly discouraged as it protects your domain from spoofing and phishing. Instead, administrators should make verified, provider-recommended adjustments for specific delivery domains.




