logo
search
Send & Receive Issues

How to Fix Microsoft Encrypted Email Rejected by DMARC Policy

Adam DavisAdam Davis Sep 25, 2026 870 views

Question details

The recipient cannot receive the one-time passcode for a Microsoft encrypted email because their Google Workspace server rejects the message due to a DMARC policy failure.

Fix Microsoft Encrypted Email Rejected by a DMARC Policy
Product
Microsoft Outlook
Device & OS
not provided
Scenario
A recipient using a Google-hosted email address attempts to open a Microsoft encrypted message and needs to receive a one-time passcode.
Observed behavior
The one-time passcode email from microsoft.com is rejected with SMTP error 550-5.7.26 due to failing the recipient domain's DMARC policy.
Before you start

Ensure you have contact with the recipient's Google Workspace IT administrator, as this rejection happens at the recipient's mail provider level. Verify the exact SMTP error code received in the non-delivery report (NDR).

Solution 1Recommended

Contact Google Workspace Admin to Adjust Mail-Routing Rules

The most effective way to resolve this is by configuring the recipient's email environment to accept Microsoft's message-delivery domains.

Because the rejection occurs at the recipient's mail provider before the encrypted message sign-in process completes, the recipient's IT administrator must intervene. They should not disable DMARC broadly, but rather make verified adjustments to allow Microsoft's automated domains.

1
Review SMTP error logs

Identify the exact delivery domain failing the DMARC check by reviewing the SMTP error 550-5.7.26 logs in the non-delivery report.

2
Access Google Admin Console

Have the Google Workspace administrator navigate to their Google Admin Console and access the email security and routing settings.

3
Adjust quarantine rules

Add Microsoft's message-delivery domains to the allowed sender list or adjust quarantine rules to bypass DMARC rejection for these specific system emails.

4
Monitor security logs

Check the relevant email security logs to confirm the changes have propagated and that the passcodes are now being delivered.

Contact Google Workspace Admin to Adjust Mail-Routing Rules
Security Warning: Do not disable DMARC entirely for the domain, as this exposes the organization to spoofing and phishing attacks.
Free Microsoft Office alternative

Discover a Seamless Alternative with WPS Office

While email server routing rules are managed by IT administrators, managing your everyday documents shouldn't be complicated. WPS Office provides a lightweight, free alternative to Microsoft Office with high compatibility, enabling you to securely create, edit, and share files across platforms.

Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Built-in secure cloud sharing features to easily bypass email attachment restrictions.Lightweight design that uses fewer system resources and installs quickly.Familiar, easy-to-use interface that requires no learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

What does SMTP error 550-5.7.26 mean?

This error indicates that the email was rejected because it failed the recipient domain's DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy, meaning the sender's domain could not be successfully authenticated.

Why does the one-time passcode email fail DMARC?

The one-time passcode is generated by an automated Microsoft system. If the recipient's mail server strictly enforces DMARC, it may flag these automated emails as unauthenticated if Microsoft's delivery IPs or domains aren't explicitly whitelisted by the receiving server.

Can the sender fix this DMARC rejection issue?

No, the sender cannot fix this directly through their email client. The resolution requires the recipient's IT administrator (such as the Google Workspace admin) to adjust their mail-routing and quarantine rules to accept Microsoft's system emails.

Is it safe to disable DMARC to receive these emails?

No, broadly disabling DMARC is highly discouraged as it protects your domain from spoofing and phishing. Instead, administrators should make verified, provider-recommended adjustments for specific delivery domains.