logo
search
Email Migration

Fix Gmail to Microsoft 365 Migration Routing Error 450 4.7.26

Guest WriterGuest Writer Sep 27, 2026 869 views

Question details

The user needs to resolve an SMTP routing failure occurring during a staged email migration from Google Workspace to Exchange Online.

Fix Gmail to Microsoft 365 Migration Routing Error 450 4.7.26
Product
Microsoft 365
Device & OS
not provided
Scenario
Performing a staged email migration from Gmail to Microsoft 365 where Exchange Online Protection blocks incoming mail.
Observed behavior
Microsoft 365 rejects incoming IPv6 mail from Gmail with SMTP error 450 4.7.26, indicating a DKIM body-hash failure or failed SPF authorization.
Before you start

Ensure you have administrative access to both your Google Workspace admin console and the Microsoft 365 Exchange admin center, as well as access to modify your domain's DNS records.

Solution 1Recommended

Validate and Update SPF and DKIM DNS Records

Ensure that your domain's DNS records correctly authorize both Gmail and Microsoft 365 senders to prevent Exchange Online Protection from rejecting the emails.

Error 450 4.7.26 indicates that the message sent over IPv6 is failing Sender Policy Framework (SPF) or DomainKeys Identified Mail (DKIM) validation. Configuring both correctly ensures the destination server trusts the email source.

1
Update SPF Record

Log in to your domain registrar's DNS management portal and ensure your SPF TXT record includes both Google Workspace and Microsoft 365 IP addresses (e.g., v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all).

2
Verify DKIM Status in Gmail

Log in to the Google Workspace Admin console, navigate to Apps > Google Workspace > Gmail > Authenticate email, and ensure DKIM is enabled with the correct selector.

3
Confirm DKIM DNS Record

Check that the DKIM TXT record in your DNS portal exactly matches the value generated by the Google Workspace Admin console.

DNS Propagation Time: DNS changes can take up to 48 hours to propagate globally. You may need to wait for the changes to take effect before testing the migration routing again.
Free Microsoft Office alternative

Streamline Your Work with WPS Office

While resolving Microsoft 365 and Gmail migration issues, consider WPS Office as a free, lightweight, and powerful alternative for your everyday document needs. It offers complete compatibility with Microsoft Office files without complex administrative overhead.

  1. 1. Download the Installer: Visit the official WPS Office website and click the Free Download button for your operating system.
  2. 2. Install the Software: Run the downloaded installer file and follow the straightforward on-screen instructions.
  3. 3. Start Creating: Open WPS Office to instantly view, edit, and create Word, Excel, and PowerPoint compatible files.
Fully compatible with Microsoft Office file formats (.docx, .xlsx, .pptx)Free and lightweight suite for Writer, Spreadsheet, and PresentationFamiliar, tabbed user interface for a seamless transitionBuilt-in PDF editing and format conversion tools
microsoft office alternative - wps office

Frequently Asked Questions

What does SMTP error 450 4.7.26 mean in Microsoft 365?

This error indicates that Microsoft Exchange Online Protection is temporarily rejecting incoming mail, typically over IPv6, because the message failed SPF (Sender Policy Framework) or DKIM (DomainKeys Identified Mail) authentication checks.

Why does a DKIM body-hash failure occur during a staged migration?

A DKIM body-hash failure happens when the email's content or headers are modified after the DKIM signature is applied by the sender. During migration, this is often caused by intermediate routing rules, anti-spam filters, or automatic disclaimers adding text to the message before it reaches Microsoft 365.

How can I fix the IPv6 inbound mail flow rejection in Exchange Online?

Ensure that your SPF record explicitly includes both the Google Workspace and Microsoft 365 IP addresses. Additionally, verify that your inbound connectors in the Exchange admin center are correctly configured to trust the migration path and that DKIM is strictly aligned.