550 5.7.40: No DMARC record, or no DMARC policy
Gmail returns 5.7.40 when the sending domain has no DMARC record, or the record has no valid policy tag. Google requires DMARC from bulk senders. Publish a TXT record at _dmarc.yourdomain with at least v=DMARC1; p=none, then move to quarantine or reject once reports look clean.
The exact messages
Gmail / Google Workspace
550 5.7.40 Your message was blocked because the sending domain doesn't have a DMARC record or the DMARC record doesn't specify a DMARC policy.
Gmail / Google Workspace
421 4.7.40 Your email has been rate limited because the sending domain doesn't have a DMARC record, or the DMARC record doesn't specify a DMARC policy.
Why it happens
- No TXT record exists at _dmarc.<your domain>.
- The record exists but is missing the p= tag, or has a typo such as "v=DMARC 1" or "p=nothing".
- The DMARC record was published on the wrong host, for example on the root domain instead of _dmarc.
How to fix it
- Publish v=DMARC1; p=none; rua=mailto:<an address you read> at _dmarc.<domain>.
- Check it with a DMARC checker to confirm the tags parse.
- After a week or two of clean aggregate reports, tighten to p=quarantine, then p=reject.
If you send cold email
Every outreach domain needs its own DMARC record; a record on your main domain does not cover separately registered lookalike domains. Subdomains inherit the parent’s policy, but new domains inherit nothing.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.32From: domain not aligned with SPF or DKIM
- 5.7.509DMARC failed and the policy is reject (Microsoft)
- 5.7.515High-volume sender fails Outlook.com authentication requirements
Sources, checked 2026-09-29: Google Workspace: Gmail SMTP errors and codes · Google: Email sender guidelines. Have a different bounce? Paste it into the decoder →
Questions
5.7.40 questions
What does 5.7.40 mean?+
Gmail returns 5.7.40 when the sending domain has no DMARC record, or the record has no valid policy tag. Google requires DMARC from bulk senders. Publish a TXT record at _dmarc.yourdomain with at least v=DMARC1; p=none, then move to quarantine or reject once reports look clean.
Is 5.7.40 a temporary or permanent error?+
Both forms exist. A reply starting with 4 (such as 4.7.40) is temporary, and the sending server will retry; a reply starting with 5 is permanent, and the message will not be retried until you fix the cause.
How do I fix 5.7.40?+
Publish v=DMARC1; p=none; rua=mailto:<an address you read> at _dmarc.<domain>. Check it with a DMARC checker to confirm the tags parse. After a week or two of clean aggregate reports, tighten to p=quarantine, then p=reject.