421 4.7.0: Temporarily deferred: low reputation, PTR or TLS
4.7.0 is a temporary security or policy deferral. From Gmail it most often means very low sending IP or domain reputation, a missing PTR record, or that the recipient domain requires TLS. The server will retry, but repeated 4.7.0 deferrals that end in a bounce mean the underlying reputation problem needs fixing.
The exact messages
Gmail / Google Workspace
421 4.7.0 This message is suspicious due to the very low reputation of the sending IP address.
Gmail / Google Workspace
421 4.7.0 This message is suspicious due to the very low reputation of the sending domain.
Gmail / Google Workspace
421 4.7.0 The IP address sending this message does not have a PTR record, or the corresponding forward DNS entry does not point to the sending IP.
Gmail / Google Workspace
421 4.7.0 TLS required for RCPT domain, closing connection.
Any mail server (RFC standard meaning)
4.7.0 Other or undefined security status
Why it happens
- Sending IP or domain reputation has dropped after complaints or spam-trap hits.
- The sending IP has no reverse DNS.
- Your server is not using TLS and the recipient requires it.
How to fix it
- Check the domain and IP against blocklists and in Google Postmaster Tools.
- Reduce volume and send only to engaged, verified recipients until deferrals stop.
- Set a PTR record and enable STARTTLS on self-hosted servers.
If you send cold email
A run of 4.7.0 deferrals on a cold email mailbox is an early warning. Pause the campaigns on that mailbox before the deferrals turn into 5.7.1 rejections.
How WarmHawk handles it
WarmHawk pauses a mailbox on its own once its hard-bounce rate passes 5% over at least 20 sends, and pauses a campaign at that campaign’s own bounce threshold, so a bad list stops before it drags the domain down. Every sending domain is re-checked against DNS blocklists hourly, and a mailbox only reaches campaign volume after at least 14 days of warmup with a 90% inbox rate. A mailbox whose inbox rate falls below 70% goes back to warmup. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.28Unusual rate of unsolicited mail
- 5.7.1Delivery not authorized, message refused
- 5.7.25Sending IP has no reverse DNS (PTR) record
- 5.7.29Message not sent over TLS
Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · RFC 3463: Enhanced Mail System Status Codes. Have a different bounce? Paste it into the decoder →
Questions
4.7.0 questions
What does 4.7.0 mean?+
4.7.0 is a temporary security or policy deferral. From Gmail it most often means very low sending IP or domain reputation, a missing PTR record, or that the recipient domain requires TLS. The server will retry, but repeated 4.7.0 deferrals that end in a bounce mean the underlying reputation problem needs fixing.
Is 4.7.0 a temporary or permanent error?+
Temporary. The sending server keeps the message and retries it for a while. It only becomes a bounce if every retry fails before the message expires.
How do I fix 4.7.0?+
Check the domain and IP against blocklists and in Google Postmaster Tools. Reduce volume and send only to engaged, verified recipients until deferrals stop. Set a PTR record and enable STARTTLS on self-hosted servers.