550 5.7.27: SPF authentication failed
Gmail returns 5.7.27 when a message fails SPF: the server that sent it is not listed in the sending domain’s SPF record. The 421 4.7.27 form rate-limits delivery; 550 5.7.27 blocks it. Add the sending server or service to SPF, keep the record under 10 lookups, and resend.
The exact messages
Gmail / Google Workspace
550 5.7.27 This message was blocked because it didn't pass SPF authentication.
Gmail / Google Workspace
421 4.7.27 Your email has been rate limited because SPF authentication didn't pass for this message.
Why it happens
- The sending IP or service is missing from the SPF record (an include: was never added).
- The domain has two SPF TXT records; receivers treat that as an error and SPF fails.
- The record goes over the 10-DNS-lookup limit, so evaluation stops with a permanent error.
- Mail is being forwarded, so the forwarding server’s IP is checked against your record.
How to fix it
- Run an SPF check and add the missing include: for your email provider or cold email tool.
- Merge duplicate SPF records into a single v=spf1 record.
- Remove unused includes or flatten nested ones until the lookup count is 10 or fewer.
- Make sure DKIM also passes, so a forwarded message can still authenticate through DKIM.
If you send cold email
Cold email setups often mix a mailbox provider with a sending or warmup tool that connects over SMTP. If the tool relays through its own servers instead of your mailbox provider, those servers must be in your SPF record too.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.26Unauthenticated sender (no SPF or DKIM pass)
- 5.7.24Suspicious entries in your SPF record
- 5.7.23Rejected for an SPF violation (Microsoft)
Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · Google: Email sender guidelines. Have a different bounce? Paste it into the decoder →
Questions
5.7.27 questions
What does 5.7.27 mean?+
Gmail returns 5.7.27 when a message fails SPF: the server that sent it is not listed in the sending domain’s SPF record. The 421 4.7.27 form rate-limits delivery; 550 5.7.27 blocks it. Add the sending server or service to SPF, keep the record under 10 lookups, and resend.
Is 5.7.27 a temporary or permanent error?+
Both forms exist. A reply starting with 4 (such as 4.7.27) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.
How do I fix 5.7.27?+
Run an SPF check and add the missing include: for your email provider or cold email tool. Merge duplicate SPF records into a single v=spf1 record. Remove unused includes or flatten nested ones until the lookup count is 10 or fewer. Make sure DKIM also passes, so a forwarded message can still authenticate through DKIM.