Skip to content

Gmail's stricter enforcement: reading its 4xx and 5xx replies

Since late 2025 Gmail rejects more non-compliant mail outright. How to read Gmail's SMTP replies, separate temporary from permanent, and fix the cause.

Koltrix Team5 min read
A traffic light hanging from a metal pole
Photo by CARTER SAUNDERS on Unsplash
On this page(8 sections)
  1. Temporary versus permanent
  2. How Gmail's enforcement shows up
  3. Common reply patterns and their causes
  4. Triage: what to do with each class
  5. Temporary failures (4xx)
  6. Permanent failures (5xx)
  7. A worked investigation
  8. Instrument your sending system
  9. Prevention checklist
  10. Key takeaways

Gmail used to deal with most questionable mail by filtering it into spam. Starting in November 2025, Google said it was ramping up enforcement on traffic that does not meet its sender requirements, including temporary and permanent rejections.

That means more of your problems now show up as SMTP replies in your logs rather than as silent spam placement, which is actually good news if you know how to read them.

Temporary versus permanent

Every SMTP reply starts with a three-digit code:

  • 2xx: accepted.
  • 4xx: temporary failure. The sender should keep the message and retry later.
  • 5xx: permanent failure. The sender should stop retrying and generate a bounce.

Most replies also include an enhanced status code (RFC 3463) such as 4.7.0 or 5.7.26, written as class.subject.detail. The class matches the first digit; subject 7 means a security or policy reason. After the codes, Gmail usually includes human-readable text and often a link to a help article explaining the specific problem.

550-5.7.26 Unauthenticated email from example.com is not accepted due to
550-5.7.26 domain's DMARC policy. Please contact the administrator of
550 5.7.26 example.com domain if this was a legitimate mail. ...

The exact wording changes over time, so build your handling around codes and the help link rather than the full text.

How Gmail's enforcement shows up

Under the stepped-up enforcement, a non-compliant message may first be deferred with a 4xx reply, giving the sender time to fix the issue, and may later be rejected outright with a 5xx reply. Which one you see depends on the problem, its severity and your sending history. Google does not publish the exact thresholds, so treat any authentication-related deferral as an early warning, not as noise.

Common reply patterns and their causes

The categories below cover most enforcement-related replies. The specific code values are the ones commonly seen in Gmail responses at the time of writing; always read the accompanying text and help link.

Pattern Typical meaning First thing to check
5.7.26 with DMARC text Message failed DMARC and your policy says quarantine or reject, or the message is unauthenticated Alignment of SPF and DKIM with the From domain
5.7.27 with SPF text SPF failed for the sending IP SPF record includes the sending service
5.7.30 with DKIM text DKIM missing or failed where required Selector published, signing enabled
4.7.0 or 5.7.25 with reverse DNS text Sending IP has no valid PTR or PTR does not match PTR and forward DNS for the IP
4.7.28 or rate-related text Sending too fast or unusual volume from your IP or domain Throttle, review recent volume spikes
5.7.1 with policy or spam text Message blocked for content, reputation or policy Recent complaints, content, links
4.7.29 or TLS text Connection not using TLS where required Outbound TLS configuration

If a reply references the bulk sender guidelines or unsubscribe requirements, check your one-click unsubscribe headers and that DKIM covers them.

Triage: what to do with each class

Temporary failures (4xx)

Your sending system should retry automatically with backoff. Do not treat a 4xx as a bounce, and do not suppress the recipient. But do not ignore it either:

  • A few deferrals spread across many recipients during a busy hour are often rate limiting. Back off and let retries succeed.
  • Many deferrals with authentication text mean Gmail is warning you before rejecting. Fix the cause before retries run out and the deferrals turn into bounces.
  • Persistent deferrals for one IP suggest a reputation or reverse DNS problem specific to that IP.

Permanent failures (5xx)

The message will not be delivered. Your system should stop retrying and record a bounce. The important distinction is whether the failure is about the recipient or about you:

  • 5.1.1 (bad mailbox) is about the recipient: suppress the address.
  • 5.7.x policy and authentication failures are about your sending setup: do not suppress the recipient. The address is fine; your mail is the problem. Suppressing recipients on authentication failures quietly destroys your list.

That rule alone prevents a lot of damage. Classify bounces using the enhanced status code, not just the first digit.

A worked investigation

Suppose your logs show a sudden rise in 550 5.7.26 replies from Gmail for mail from your billing system.

  1. Isolate the stream. All failures share the From address [email protected] and come through one vendor.
  2. Send a test from that vendor to a personal Gmail account. If it is rejected, check the bounce; if delivered, look at "Show original."
  3. Read the authentication results. Suppose SPF passed for mail.vendor.example and DKIM passed for vendor.example. Neither aligns with example.com, so DMARC fails.
  4. Check recent changes. Your DMARC policy moved from none to quarantine last week, so Gmail now acts on the failure.
  5. Fix it. Enable custom-domain DKIM in the vendor's settings, publish the CNAMEs, and confirm a test message shows aligned DKIM.
  6. Confirm in data. Watch the 5.7.26 count fall and DMARC aggregate reports show aligned passes for the vendor's IPs.

Instrument your sending system

To catch these quickly, log every SMTP reply from Gmail with:

  • The full status code and enhanced status code.
  • The sending domain, IP and stream (transactional, marketing, a specific vendor).
  • The first line of the reply text.

Then alert on rates, not counts: the share of Gmail-bound messages receiving 4xx or 5xx replies with subject code 7, compared with a rolling baseline. If you send through a provider, their webhooks or event logs usually include the remote server's reply; capture it rather than just "bounced."

Prevention checklist

  • SPF and DKIM for every sending domain, aligned with the From domain.
  • DMARC published; policy changes made only after reports show all sources passing.
  • Valid PTR and forward DNS for every IP you operate.
  • TLS on all outbound connections.
  • One-click unsubscribe headers on marketing mail, signed by DKIM.
  • Spam rate monitored in Postmaster Tools.
  • Bounce classification based on enhanced status codes, never suppressing recipients for 5.7.x policy failures.

Key takeaways

  • Since November 2025, Gmail rejects or defers more non-compliant mail instead of only filtering it.
  • 4xx replies mean retry and investigate; 5xx replies mean stop and fix.
  • Enhanced status codes with subject 7 point at policy and authentication problems on your side.
  • Never suppress recipients because of your own authentication failures.
  • Log full reply codes and alert on rising rates so warnings are caught before they turn into bounces.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn