550 5.7.30: DKIM authentication failed
Gmail returns 5.7.30 when a message’s DKIM signature does not verify. Either the public key is missing from DNS, it does not match the private key that signed the mail, or the message was altered after signing. The 421 4.7.30 form rate-limits; 550 5.7.30 blocks.
The exact messages
Gmail / Google Workspace
550 5.7.30 This message was blocked because it didn't pass DKIM authentication.
Gmail / Google Workspace
421 4.7.30 Your email has been rate limited because DKIM authentication didn't pass for this message.
Why it happens
- The DKIM TXT record is missing at <selector>._domainkey.<domain>, or was pasted with a line break or stray quote.
- DKIM was generated in the email provider but signing was never switched on.
- The key was rotated in the provider without publishing the new public key.
- A gateway, footer or tracking tool rewrote the body or signed headers after DKIM signing.
How to fix it
- Look up the selector your provider signs with (in the DKIM-Signature header, s=) and check that exact record.
- Re-copy the public key from the provider into DNS as a single TXT value, then start signing.
- Send a test to Gmail and confirm "DKIM: PASS" in Show original.
- If a relay modifies messages, sign after that relay, not before it.
If you send cold email
Link-tracking and open-tracking tools that rewrite the message after your mailbox provider signs it can break DKIM. If only tracked campaigns fail, test the same message with tracking off.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.26Unauthenticated sender (no SPF or DKIM pass)
- 5.7.27SPF authentication failed
- 5.7.32From: domain not aligned with SPF or DKIM
Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · Google: Email sender guidelines. Have a different bounce? Paste it into the decoder →
Questions
5.7.30 questions
What does 5.7.30 mean?+
Gmail returns 5.7.30 when a message’s DKIM signature does not verify. Either the public key is missing from DNS, it does not match the private key that signed the mail, or the message was altered after signing. The 421 4.7.30 form rate-limits; 550 5.7.30 blocks.
Is 5.7.30 a temporary or permanent error?+
Both forms exist. A reply starting with 4 (such as 4.7.30) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.
How do I fix 5.7.30?+
Look up the selector your provider signs with (in the DKIM-Signature header, s=) and check that exact record. Re-copy the public key from the provider into DNS as a single TXT value, then start signing. Send a test to Gmail and confirm "DKIM: PASS" in Show original. If a relay modifies messages, sign after that relay, not before it.