5.7.32: From: domain not aligned with SPF or DKIM
Gmail returns 5.7.32 when SPF or DKIM passed, but for a different domain than the one in the visible From: address. DMARC needs at least one of them to align with the From: domain. Sign DKIM with your own domain and use a custom return-path on your sending service.
The exact messages
Gmail / Google Workspace
421 5.7.32 Your email was blocked because the From: header (RFC5322) in this message isn't aligned with either the authenticated SPF or DKIM organizational domain.
Gmail / Google Workspace
421 4.7.32 Your email has been rate limited because the From: header (RFC5322) in this message isn't aligned with either the authenticated SPF or DKIM organizational domain.
Why it happens
- A sending service signs DKIM with its own domain (d=theirservice.com) instead of yours.
- The envelope sender (return-path) belongs to the sending service, so SPF passes for their domain, not yours.
- You send "From: you@yourbrand.com" through a mailbox on a different domain.
How to fix it
- Set up custom DKIM in the sending service so signatures use d=yourdomain.
- Configure a custom return-path (bounce domain) on your domain if the service offers it.
- Send each From: address through a mailbox on that same domain.
If you send cold email
Sending "From: name@brand.com" through a mailbox that actually lives on an outreach domain fails alignment every time. Keep the From: address and the mailbox on the same domain.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.40No DMARC record, or no DMARC policy
- 5.7.509DMARC failed and the policy is reject (Microsoft)
- 5.7.30DKIM authentication failed
Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes. Have a different bounce? Paste it into the decoder →
Questions
5.7.32 questions
What does 5.7.32 mean?+
Gmail returns 5.7.32 when SPF or DKIM passed, but for a different domain than the one in the visible From: address. DMARC needs at least one of them to align with the From: domain. Sign DKIM with your own domain and use a custom return-path on your sending service.
Is 5.7.32 a temporary or permanent error?+
Both forms exist. A reply starting with 4 (such as 4.7.32) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.
How do I fix 5.7.32?+
Set up custom DKIM in the sending service so signatures use d=yourdomain. Configure a custom return-path (bounce domain) on your domain if the service offers it. Send each From: address through a mailbox on that same domain.