550 5.7.29: Message not sent over TLS
Gmail returns 5.7.29 when a message was not sent over a TLS connection, and 421 4.7.29 when it rate-limits you for the same reason. Google’s sender guidelines require TLS. Enable STARTTLS on the sending server, or send through a provider that already uses it.
The exact messages
Gmail / Google Workspace
550 5.7.29 This message was blocked because it wasn't sent over a TLS connection.
Gmail / Google Workspace
421 4.7.29 Your email has been rate limited because you're not using a TLS connection.
Why it happens
- A self-hosted mail server with STARTTLS turned off or misconfigured.
- An old appliance or script that sends in plain text.
How to fix it
- Enable opportunistic TLS (STARTTLS) for outbound mail on your server.
- Install a valid certificate for the server’s hostname.
If you send cold email
Google Workspace and Microsoft 365 send over TLS already. This code shows up only when mail leaves through your own server or an old relay.
How WarmHawk handles it
A Google Workspace or Microsoft 365 mailbox connected to WarmHawk sends through the provider’s own servers, which already use TLS. A temporary failure is retried with backoff (30 minutes, then doubling, capped at 48 hours) and the lead is suppressed after 4 attempts instead of being retried forever. How WarmHawk works →
Related bounce codes
- 4.7.0Temporarily deferred: low reputation, PTR or TLS
- 5.7.25Sending IP has no reverse DNS (PTR) record
Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · Google: Email sender guidelines. Have a different bounce? Paste it into the decoder →
Questions
5.7.29 questions
What does 5.7.29 mean?+
Gmail returns 5.7.29 when a message was not sent over a TLS connection, and 421 4.7.29 when it rate-limits you for the same reason. Google’s sender guidelines require TLS. Enable STARTTLS on the sending server, or send through a provider that already uses it.
Is 5.7.29 a temporary or permanent error?+
Both forms exist. A reply starting with 4 (such as 4.7.29) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.
How do I fix 5.7.29?+
Enable opportunistic TLS (STARTTLS) for outbound mail on your server. Install a valid certificate for the server’s hostname.