WarmHawk
Bounce codes · Temporary or permanent · also 4.7.30

550 5.7.30: DKIM authentication failed

Gmail returns 5.7.30 when a message’s DKIM signature does not verify. Either the public key is missing from DNS, it does not match the private key that signed the mail, or the message was altered after signing. The 421 4.7.30 form rate-limits; 550 5.7.30 blocks.

The exact messages

Gmail / Google Workspace

550 5.7.30 This message was blocked because it didn't pass DKIM authentication.

Gmail / Google Workspace

421 4.7.30 Your email has been rate limited because DKIM authentication didn't pass for this message.

Why it happens

How to fix it

  1. Look up the selector your provider signs with (in the DKIM-Signature header, s=) and check that exact record.
  2. Re-copy the public key from the provider into DNS as a single TXT value, then start signing.
  3. Send a test to Gmail and confirm "DKIM: PASS" in Show original.
  4. If a relay modifies messages, sign after that relay, not before it.

If you send cold email

Link-tracking and open-tracking tools that rewrite the message after your mailbox provider signs it can break DKIM. If only tracked campaigns fail, test the same message with tracking off.

How WarmHawk handles it

WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →

Check your domain now

These free checkers read your live DNS: no account, up to 15 domains at once.

Related bounce codes

Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · Google: Email sender guidelines. Have a different bounce? Paste it into the decoder →

Questions

5.7.30 questions

What does 5.7.30 mean?+

Gmail returns 5.7.30 when a message’s DKIM signature does not verify. Either the public key is missing from DNS, it does not match the private key that signed the mail, or the message was altered after signing. The 421 4.7.30 form rate-limits; 550 5.7.30 blocks.

Is 5.7.30 a temporary or permanent error?+

Both forms exist. A reply starting with 4 (such as 4.7.30) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.

How do I fix 5.7.30?+

Look up the selector your provider signs with (in the DKIM-Signature header, s=) and check that exact record. Re-copy the public key from the provider into DNS as a single TXT value, then start signing. Send a test to Gmail and confirm "DKIM: PASS" in Show original. If a relay modifies messages, sign after that relay, not before it.