What 550 5.7.40 means
The message Gmail attaches to this code is “Your message was blocked because the sending domain doesn't have a DMARC record or the DMARC record doesn't specify a DMARC policy.”, as written on its reference page. The first digit says how final it is: a 5xx reply is permanent for that message, so the sending server gives up and returns a bounce. The enhanced status 5.7.40 says what class of problem it is: authentication. The receiver could not authenticate the message: SPF, DKIM or DMARC failed or is missing. A DNS fix, not a reputation fix.
Why it happens
The receiving server checked who sent the message and could not make the answer add up. Either the sending service is not listed in the domain's SPF record, the DKIM signature is missing or does not verify, or the domain that passed authentication is not the domain in the From header, which is what alignment means. Nothing about volume or reputation changes this: the record is either right or it is not.
What to do first: Publish v=DMARC1; p=none with an aggregate reporting address; p=none is the bulk-sender minimum.
Why warming does not fix this
Warming builds sender reputation. 550 5.7.40 in this form is a authentication problem, and no amount of engagement history changes it. Fix the cause and the bounce stops; warming is for what comes after, when the mail is accepted and the question becomes which folder it lands in. See how warming works for that part.
How to fix it, in order
- Run the auth checker on the sending domain
- Publish or repair the failing record (SPF, DKIM or DMARC)
- Check alignment with a message's headers in the auth checker
Related codes
- 421 4.7.32 (Gmail): From header not aligned
- 550 5.7.26 (Gmail): sender is unauthenticated
- 421 4.7.26 (Gmail): rate limited, unauthenticated
- 550 5.7.515 (Microsoft): authentication level not met
- 550 5.7.509 (Microsoft): DMARC verification failed
More on Gmail
- Google Workspace emails going to spam: the Postmaster-led diagnosis, dashboard by dashboard
- Gmail and Yahoo bulk sender requirements: the rules behind Google's authentication and spam-rate rejections
- Google Postmaster Tools domain reputation: what the reputation tiers and the spam rate mean
Questions about 550 5.7.40
What does 550 5.7.40 mean?
Gmail returns 550 5.7.40 with the message "Your message was blocked because the sending domain doesn't have a DMARC record or the DMARC record doesn't specify a DMARC policy.": no DMARC record or policy. The receiver could not authenticate the message: SPF, DKIM or DMARC failed or is missing. A DNS fix, not a reputation fix.
Is 550 5.7.40 a hard bounce or a soft bounce?
A hard bounce for that message: the 550 reply is permanent, and the message is not retried. Whether the address should be removed depends on the cause: here the fix is on the sending side, not the list.
How do I fix 550 5.7.40?
Publish v=DMARC1; p=none with an aggregate reporting address; p=none is the bulk-sender minimum. Gmail's own reference for the code is linked on this page.
Does email warmup fix 550 5.7.40?
No. 550 5.7.40 in this form is a authentication problem, and warming builds reputation, which is not what is failing here. Fix the cause and the bounce stops.