WarmHawk
Bounce codes · Temporary or permanent · also 4.7.29

550 5.7.29: Message not sent over TLS

Gmail returns 5.7.29 when a message was not sent over a TLS connection, and 421 4.7.29 when it rate-limits you for the same reason. Google’s sender guidelines require TLS. Enable STARTTLS on the sending server, or send through a provider that already uses it.

The exact messages

Gmail / Google Workspace

550 5.7.29 This message was blocked because it wasn't sent over a TLS connection.

Gmail / Google Workspace

421 4.7.29 Your email has been rate limited because you're not using a TLS connection.

Why it happens

How to fix it

  1. Enable opportunistic TLS (STARTTLS) for outbound mail on your server.
  2. Install a valid certificate for the server’s hostname.

If you send cold email

Google Workspace and Microsoft 365 send over TLS already. This code shows up only when mail leaves through your own server or an old relay.

How WarmHawk handles it

A Google Workspace or Microsoft 365 mailbox connected to WarmHawk sends through the provider’s own servers, which already use TLS. A temporary failure is retried with backoff (30 minutes, then doubling, capped at 48 hours) and the lead is suppressed after 4 attempts instead of being retried forever. How WarmHawk works →

Related bounce codes

Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · Google: Email sender guidelines. Have a different bounce? Paste it into the decoder →

Questions

5.7.29 questions

What does 5.7.29 mean?+

Gmail returns 5.7.29 when a message was not sent over a TLS connection, and 421 4.7.29 when it rate-limits you for the same reason. Google’s sender guidelines require TLS. Enable STARTTLS on the sending server, or send through a provider that already uses it.

Is 5.7.29 a temporary or permanent error?+

Both forms exist. A reply starting with 4 (such as 4.7.29) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.

How do I fix 5.7.29?+

Enable opportunistic TLS (STARTTLS) for outbound mail on your server. Install a valid certificate for the server’s hostname.