emailmarketing.net

Gmail SMTP Errors and Troubleshooting

Complete catalog of Gmail SMTP reply codes with their enhanced status codes, meanings, and fixes.

Reference8 min read

Who it is for Senders, ESP operators

Applies to senders on any platform

When Gmail rejects, defers or rate-limits your mail, the SMTP reply tells you why and what to fix. Google publishes the full list of reply codes its servers return for inbound mail, collected below with their meanings and fixes.

Every error that Gmail generates ends with the identifier gsmtp. Errors that also contain gcdp were triggered by a custom rule that a Google Workspace administrator set up on the receiving domain, not by Gmail's own filtering.

General rules of thumb:

  • 4xx codes are temporary, so retry later. Many 4.7.x codes are deliberate rate limiting, which escalates to a permanent 5.7.x block if you do not fix the underlying problem.
  • 5xx codes are permanent for that message. Fix the cause before you send again.
  • The 4.7.x and 5.7.x pairs about compliance (SPF, DKIM, DMARC, TLS, PTR, alignment) map directly to the Gmail sender requirements.

Temporary failures (4xx)

Code Message (abridged) Meaning and fix
450-4.2.1 User "is receiving email too quickly" / "at a rate that prevents delivery" Rate limit on the recipient's side; resend later
450-4.2.1 "Peak SMTP relay limit exceeded for this customer" Workspace SMTP relay limit; contact the account administrator
452-4.2.2 "The recipient's inbox is out of storage space" The recipient must free up Google storage
421-4.3.0 "Temporary System Problem. Try again later" Issue on Google's side; retry
451-4.3.0 "Email server has temporarily rejected this message" Retry later
451-4.3.0 "Multiple destination domains per transaction is unsupported" Send to one destination domain per SMTP transaction (RFC 5321)
451-4.4.2 "Timeout - closing connection" Network or session timeout; retry
421-4.4.5 "Server busy, try again later" Retry with backoff
451-4.5.0 "SMTP protocol violation" Fix how the client handles the protocol, following RFC 5321
452-4.5.3 "Domain policy size per transaction exceeded" Retry that recipient in a separate transaction
452-4.5.3 "Your message has too many recipients" Reduce the number of recipients per message
421-4.7.0 "Connection expired, try reconnecting" / "Try again later, closing connection" Reconnect and retry
421-4.7.0 "IP not in whitelist for RCPT domain" The receiving (Workspace) domain accepts only allowlisted IP addresses
421-4.7.0 "The IP address sending this message does not have a PTR record" Add matching PTR and forward DNS records
421-4.7.0 "TLS required for RCPT domain, closing connection" Deliver over TLS
421-4.7.0 "This message is suspicious due to the very low reputation of the sending IP / sending domain" Reputation block; see reputation recovery below
421-4.7.0 "This message is suspicious due to the nature of the content" Content flagged; review the message content
454-4.7.0 "Too many login attempts" / "Cannot authenticate due to a temporary system problem" Throttling of client authentication; retry later
451-4.7.23 "The sending IP address for this message doesn't have a PTR record" Add a PTR record
451-4.7.24 "The SPF record of the sending domain has one or more suspicious entries" Clean up the SPF record (remove compromised or suspicious includes)
421-4.7.26 "Rate limited because it is unauthenticated" Set up SPF or DKIM
451-4.7.26 "Unauthenticated email from domain is not accepted due to domain's DMARC policy" The DMARC policy of the From: domain itself rejects unauthenticated use; authenticate with aligned SPF or DKIM
421-4.7.27 "Rate limited because SPF authentication didn't pass" Fix SPF
421-4.7.28 "Unusual rate of email" from your IP address / IP netblock / DKIM domain / SPF domain / a URL domain in the body; or "sender exceeded the quota" Rate limiting for spam patterns, keyed to that identifier. To recover, wait ≥10 minutes, resume with one connection, and add connections one at a time
421-4.7.29 "Rate limited because you're not using a TLS connection" Turn on TLS
421-4.7.30 "Rate limited because DKIM authentication didn't pass" Fix DKIM
421-4.7.32 "Rate limited because the From: header isn't aligned" with the SPF or DKIM domain Achieve DMARC alignment; see DMARC
421-4.7.40 "Rate limited because the sending domain doesn't have a DMARC record" Publish a DMARC record (at minimum p=none)

Permanent failures (5xx)

Recipient and addressing

Code Message (abridged) Meaning and fix
550-5.1.1 "The email account that you tried to reach does not exist" Hard bounce: remove the address and check for typos
553-5.1.2 "We weren't able to find the recipient domain" Bad domain; check the spelling and the MX record
553-5.1.3 "The recipient address is not a valid RFC 5321 address" Fix the address syntax
553-5.1.7 "The sender address is not a valid RFC 5321 address" Fix the syntax of the envelope sender
550-5.2.1 "The email account that you tried to reach is inactive" Disabled account; suppress it
550-5.2.1 User "is receiving email at a rate that prevents delivery" Rate limit on the recipient
552-5.2.2 "The recipient's inbox is out of storage space and inactive" Suppress, or wait
550-5.4.5 "Daily user sending limit exceeded" / "Daily SMTP relay limit exceeded for user" Outbound limits of Gmail or Workspace reached
554-5.4.6 "Message exceeded 50 hops" Probably a mail loop; investigate forwarding chains
550-5.5.3 "Too many recipients for this sender" Reduce the number of recipients

Size limits

Code Message (abridged) Meaning and fix
552-5.3.4 Message exceeded size limits The whole message is too large
552-5.3.4 "The number of attachments exceeds Google's limit" Send fewer attachments
552-5.3.4 Header size limits exceeded: total headers, a header value, a header name, or the Subject: header Shrink the headers

Protocol and session

Code Message (abridged) Meaning and fix
502-5.5.1 "Unimplemented command" / "Unrecognized command" / "Too many unrecognized commands, goodbye" Fix the behavior of the SMTP client
503-5.5.1 "Bad sequence of commands" / "EHLO/HELO first" / "RCPT first" / "No DATA after BDAT" (RFC 3030) A bug in the order of commands in the client
501-5.5.2 / 555-5.5.2 "Syntax error" Malformed SMTP command
501-5.5.4 "HELO/EHLO argument invalid" / "Empty HELO/EHLO argument not allowed" Send a valid fully qualified domain name (FQDN) in HELO or EHLO
530-5.7.0 "Must issue a STARTTLS command first" (RFC 3207) / "Authentication required" Start TLS, or authenticate, before sending
523-5.7.10 "No commands allowed to pipeline after STARTTLS" Violation of RFC 3207
501-5.7.11 "Syntax error (no parameters allowed)" Violation of RFC 3207
554-5.7.0 "Too many unauthenticated commands" Session terminated
503-5.7.0 "No identity changes permitted" Do not switch the authenticated identity during a session

Content, format, and policy

Code Message (abridged) Meaning and fix
554-5.6.0 "Email message is malformed. Not accepted" Fix compliance with RFC 5322
552-5.7.0 "Content presents a potential security issue" Blocked attachment or file type (see Gmail's list of blocked file types)
550-5.7.1 "The user or domain that you are sending to has a policy" prohibiting the mail Policy of the receiving Workspace domain (gcdp errors); contact the recipient's administrator
550-5.7.1 "This message is likely unsolicited email" / "likely suspicious due to the very low reputation" of the sending IP or domain Spam or reputation block; see recovery below
550-5.7.1 RFC 5322 violations: a missing or invalid From:, multiple From: headers, multiple addresses in From:, no valid Message-ID:, duplicate headers, a malformed header, a non-compliant From: value, encoded-word syntax in a header, a Unicode character in a header that does not allow it Fix how messages are generated, following RFC 5322
550-5.7.1 "This message does not meet IPv6 sending guidelines" Over IPv6, PTR records and authentication are mandatory; fix them or send over IPv4
550-5.7.1 "This email has been rate limited" Sending or receiving limits
550-5.7.1 "The IP you're using to send email is not authorized" Mail sent directly from a dynamic or consumer IP address; relay through your provider's SMTP server instead
550-5.7.1 "Invalid credentials for relay" / "Daily SMTP relay sending limit exceeded for this customer" Configuration or limits of the Workspace SMTP relay
550-5.7.0 "Email relay denied" (invalid credentials or suspended account) Register the sending IP address in the Workspace SMTP relay settings, or the relay account is suspended for spam

Authentication and sender-requirement blocks

Code Message (abridged) Meaning and fix
550-5.7.24 "SPF record of the sending domain has one or more suspicious entries" Clean up the SPF record
550-5.7.25 "The sending IP address doesn't have a PTR record" Add a PTR record
550-5.7.26 "Blocked because the sender is unauthenticated" Set up SPF or DKIM
550-5.7.26 "The (E)MAIL FROM domain has an SPF record with a hard fail policy" (-all) but the message failed SPF Fix the SPF record, or send from an authorized IP address
550-5.7.26 "Unauthenticated email from domain is not accepted due to domain's DMARC policy" The DMARC policy of the From: domain requires aligned authentication
550-5.7.27 "Didn't pass SPF authentication" Fix SPF
550-5.7.28 "Unusual rate of unsolicited email originating from your IP address" Block for spam volume; stop, fix list hygiene, and warm up again
550-5.7.29 "Wasn't sent over a TLS connection" Turn on TLS
550-5.7.30 "Didn't pass DKIM authentication" Fix DKIM
5.7.32 "Blocked because the From: header isn't aligned" with SPF or DKIM Fix DMARC alignment
550-5.7.40 "The sending domain doesn't have a DMARC record" Publish DMARC

Client-authentication errors (submission, not deliverability)

Code Message (abridged) Meaning and fix
535-5.7.80 "Username and Password not accepted" Bad credentials, or sign-in blocked
534-5.7.90 "Application-specific password required" / "Please log in with your web browser" Use app passwords or OAuth
534-5.7.14 "Please log in through your web browser and then try again" Account security challenge
504-5.7.40 "Unrecognized authentication type" / "XOAUTH is no longer supported" Use OAuth 2.0 (XOAUTH2)

Recovering from blocks and throttling

  • Temporary 4.7.x failures are throttling, not final verdicts. Google's guidance is to "completely stop sending for a short period of time, then resume sending at a slower rate", which in effect means warming up again.
  • Rate-limit quota errors (4.7.28): wait at least 10 minutes, resume with a single connection, and add connections one at a time. If a single connection still fails, wait another 10 minutes.
  • Reputation blocks ("very low reputation of the sending IP/domain"): check the IP Reputation and Domain Reputation dashboards in Postmaster Tools, fix the source of spam, and give it time. Reputation recovers only through sustained sending that follows the rules.
  • Listings on public blocklists (RBLs): Gmail also consults public blocklists. Request delisting directly from the blocklist operator.
  • Persistent blocks on compliant traffic: use Google's Bulk Sender Escalation Form. Mitigation is not available while your spam rate in Postmaster Tools is above 0.3% (see sender requirements).

Check your own record

The free check reads what your domain publishes in DNS.

In this topic

All 15 in Mailbox Providers →