Gmail SMTP Errors and Troubleshooting
Complete catalog of Gmail SMTP reply codes with their enhanced status codes, meanings, and fixes.
Reference8 min read
Who it is for Senders, ESP operators
Applies to senders on any platform
When Gmail rejects, defers or rate-limits your mail, the SMTP reply tells you why and what to fix. Google publishes the full list of reply codes its servers return for inbound mail, collected below with their meanings and fixes.
Every error that Gmail generates ends with the identifier gsmtp. Errors that also contain gcdp were triggered by a custom rule that a Google Workspace administrator set up on the receiving domain, not by Gmail's own filtering.
General rules of thumb:
- 4xx codes are temporary, so retry later. Many 4.7.x codes are deliberate rate limiting, which escalates to a permanent 5.7.x block if you do not fix the underlying problem.
- 5xx codes are permanent for that message. Fix the cause before you send again.
- The 4.7.x and 5.7.x pairs about compliance (SPF, DKIM, DMARC, TLS, PTR, alignment) map directly to the Gmail sender requirements.
Temporary failures (4xx)
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 450-4.2.1 | User "is receiving email too quickly" / "at a rate that prevents delivery" | Rate limit on the recipient's side; resend later |
| 450-4.2.1 | "Peak SMTP relay limit exceeded for this customer" | Workspace SMTP relay limit; contact the account administrator |
| 452-4.2.2 | "The recipient's inbox is out of storage space" | The recipient must free up Google storage |
| 421-4.3.0 | "Temporary System Problem. Try again later" | Issue on Google's side; retry |
| 451-4.3.0 | "Email server has temporarily rejected this message" | Retry later |
| 451-4.3.0 | "Multiple destination domains per transaction is unsupported" | Send to one destination domain per SMTP transaction (RFC 5321) |
| 451-4.4.2 | "Timeout - closing connection" | Network or session timeout; retry |
| 421-4.4.5 | "Server busy, try again later" | Retry with backoff |
| 451-4.5.0 | "SMTP protocol violation" | Fix how the client handles the protocol, following RFC 5321 |
| 452-4.5.3 | "Domain policy size per transaction exceeded" | Retry that recipient in a separate transaction |
| 452-4.5.3 | "Your message has too many recipients" | Reduce the number of recipients per message |
| 421-4.7.0 | "Connection expired, try reconnecting" / "Try again later, closing connection" | Reconnect and retry |
| 421-4.7.0 | "IP not in whitelist for RCPT domain" | The receiving (Workspace) domain accepts only allowlisted IP addresses |
| 421-4.7.0 | "The IP address sending this message does not have a PTR record" | Add matching PTR and forward DNS records |
| 421-4.7.0 | "TLS required for RCPT domain, closing connection" | Deliver over TLS |
| 421-4.7.0 | "This message is suspicious due to the very low reputation of the sending IP / sending domain" | Reputation block; see reputation recovery below |
| 421-4.7.0 | "This message is suspicious due to the nature of the content" | Content flagged; review the message content |
| 454-4.7.0 | "Too many login attempts" / "Cannot authenticate due to a temporary system problem" | Throttling of client authentication; retry later |
| 451-4.7.23 | "The sending IP address for this message doesn't have a PTR record" | Add a PTR record |
| 451-4.7.24 | "The SPF record of the sending domain has one or more suspicious entries" | Clean up the SPF record (remove compromised or suspicious includes) |
| 421-4.7.26 | "Rate limited because it is unauthenticated" | Set up SPF or DKIM |
| 451-4.7.26 | "Unauthenticated email from domain is not accepted due to domain's DMARC policy" | The DMARC policy of the From: domain itself rejects unauthenticated use; authenticate with aligned SPF or DKIM |
| 421-4.7.27 | "Rate limited because SPF authentication didn't pass" | Fix SPF |
| 421-4.7.28 | "Unusual rate of email" from your IP address / IP netblock / DKIM domain / SPF domain / a URL domain in the body; or "sender exceeded the quota" | Rate limiting for spam patterns, keyed to that identifier. To recover, wait ≥10 minutes, resume with one connection, and add connections one at a time |
| 421-4.7.29 | "Rate limited because you're not using a TLS connection" | Turn on TLS |
| 421-4.7.30 | "Rate limited because DKIM authentication didn't pass" | Fix DKIM |
| 421-4.7.32 | "Rate limited because the From: header isn't aligned" with the SPF or DKIM domain | Achieve DMARC alignment; see DMARC |
| 421-4.7.40 | "Rate limited because the sending domain doesn't have a DMARC record" | Publish a DMARC record (at minimum p=none) |
Permanent failures (5xx)
Recipient and addressing
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 550-5.1.1 | "The email account that you tried to reach does not exist" | Hard bounce: remove the address and check for typos |
| 553-5.1.2 | "We weren't able to find the recipient domain" | Bad domain; check the spelling and the MX record |
| 553-5.1.3 | "The recipient address is not a valid RFC 5321 address" | Fix the address syntax |
| 553-5.1.7 | "The sender address is not a valid RFC 5321 address" | Fix the syntax of the envelope sender |
| 550-5.2.1 | "The email account that you tried to reach is inactive" | Disabled account; suppress it |
| 550-5.2.1 | User "is receiving email at a rate that prevents delivery" | Rate limit on the recipient |
| 552-5.2.2 | "The recipient's inbox is out of storage space and inactive" | Suppress, or wait |
| 550-5.4.5 | "Daily user sending limit exceeded" / "Daily SMTP relay limit exceeded for user" | Outbound limits of Gmail or Workspace reached |
| 554-5.4.6 | "Message exceeded 50 hops" | Probably a mail loop; investigate forwarding chains |
| 550-5.5.3 | "Too many recipients for this sender" | Reduce the number of recipients |
Size limits
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 552-5.3.4 | Message exceeded size limits | The whole message is too large |
| 552-5.3.4 | "The number of attachments exceeds Google's limit" | Send fewer attachments |
| 552-5.3.4 | Header size limits exceeded: total headers, a header value, a header name, or the Subject: header |
Shrink the headers |
Protocol and session
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 502-5.5.1 | "Unimplemented command" / "Unrecognized command" / "Too many unrecognized commands, goodbye" | Fix the behavior of the SMTP client |
| 503-5.5.1 | "Bad sequence of commands" / "EHLO/HELO first" / "RCPT first" / "No DATA after BDAT" (RFC 3030) | A bug in the order of commands in the client |
| 501-5.5.2 / 555-5.5.2 | "Syntax error" | Malformed SMTP command |
| 501-5.5.4 | "HELO/EHLO argument invalid" / "Empty HELO/EHLO argument not allowed" | Send a valid fully qualified domain name (FQDN) in HELO or EHLO |
| 530-5.7.0 | "Must issue a STARTTLS command first" (RFC 3207) / "Authentication required" | Start TLS, or authenticate, before sending |
| 523-5.7.10 | "No commands allowed to pipeline after STARTTLS" | Violation of RFC 3207 |
| 501-5.7.11 | "Syntax error (no parameters allowed)" | Violation of RFC 3207 |
| 554-5.7.0 | "Too many unauthenticated commands" | Session terminated |
| 503-5.7.0 | "No identity changes permitted" | Do not switch the authenticated identity during a session |
Content, format, and policy
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 554-5.6.0 | "Email message is malformed. Not accepted" | Fix compliance with RFC 5322 |
| 552-5.7.0 | "Content presents a potential security issue" | Blocked attachment or file type (see Gmail's list of blocked file types) |
| 550-5.7.1 | "The user or domain that you are sending to has a policy" prohibiting the mail | Policy of the receiving Workspace domain (gcdp errors); contact the recipient's administrator |
| 550-5.7.1 | "This message is likely unsolicited email" / "likely suspicious due to the very low reputation" of the sending IP or domain | Spam or reputation block; see recovery below |
| 550-5.7.1 | RFC 5322 violations: a missing or invalid From:, multiple From: headers, multiple addresses in From:, no valid Message-ID:, duplicate headers, a malformed header, a non-compliant From: value, encoded-word syntax in a header, a Unicode character in a header that does not allow it |
Fix how messages are generated, following RFC 5322 |
| 550-5.7.1 | "This message does not meet IPv6 sending guidelines" | Over IPv6, PTR records and authentication are mandatory; fix them or send over IPv4 |
| 550-5.7.1 | "This email has been rate limited" | Sending or receiving limits |
| 550-5.7.1 | "The IP you're using to send email is not authorized" | Mail sent directly from a dynamic or consumer IP address; relay through your provider's SMTP server instead |
| 550-5.7.1 | "Invalid credentials for relay" / "Daily SMTP relay sending limit exceeded for this customer" | Configuration or limits of the Workspace SMTP relay |
| 550-5.7.0 | "Email relay denied" (invalid credentials or suspended account) | Register the sending IP address in the Workspace SMTP relay settings, or the relay account is suspended for spam |
Authentication and sender-requirement blocks
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 550-5.7.24 | "SPF record of the sending domain has one or more suspicious entries" | Clean up the SPF record |
| 550-5.7.25 | "The sending IP address doesn't have a PTR record" | Add a PTR record |
| 550-5.7.26 | "Blocked because the sender is unauthenticated" | Set up SPF or DKIM |
| 550-5.7.26 | "The (E)MAIL FROM domain has an SPF record with a hard fail policy" (-all) but the message failed SPF |
Fix the SPF record, or send from an authorized IP address |
| 550-5.7.26 | "Unauthenticated email from domain is not accepted due to domain's DMARC policy" | The DMARC policy of the From: domain requires aligned authentication |
| 550-5.7.27 | "Didn't pass SPF authentication" | Fix SPF |
| 550-5.7.28 | "Unusual rate of unsolicited email originating from your IP address" | Block for spam volume; stop, fix list hygiene, and warm up again |
| 550-5.7.29 | "Wasn't sent over a TLS connection" | Turn on TLS |
| 550-5.7.30 | "Didn't pass DKIM authentication" | Fix DKIM |
| 5.7.32 | "Blocked because the From: header isn't aligned" with SPF or DKIM | Fix DMARC alignment |
| 550-5.7.40 | "The sending domain doesn't have a DMARC record" | Publish DMARC |
Client-authentication errors (submission, not deliverability)
| Code | Message (abridged) | Meaning and fix |
|---|---|---|
| 535-5.7.80 | "Username and Password not accepted" | Bad credentials, or sign-in blocked |
| 534-5.7.90 | "Application-specific password required" / "Please log in with your web browser" | Use app passwords or OAuth |
| 534-5.7.14 | "Please log in through your web browser and then try again" | Account security challenge |
| 504-5.7.40 | "Unrecognized authentication type" / "XOAUTH is no longer supported" | Use OAuth 2.0 (XOAUTH2) |
Recovering from blocks and throttling
- Temporary 4.7.x failures are throttling, not final verdicts. Google's guidance is to "completely stop sending for a short period of time, then resume sending at a slower rate", which in effect means warming up again.
- Rate-limit quota errors (4.7.28): wait at least 10 minutes, resume with a single connection, and add connections one at a time. If a single connection still fails, wait another 10 minutes.
- Reputation blocks ("very low reputation of the sending IP/domain"): check the IP Reputation and Domain Reputation dashboards in Postmaster Tools, fix the source of spam, and give it time. Reputation recovers only through sustained sending that follows the rules.
- Listings on public blocklists (RBLs): Gmail also consults public blocklists. Request delisting directly from the blocklist operator.
- Persistent blocks on compliant traffic: use Google's Bulk Sender Escalation Form. Mitigation is not available while your spam rate in Postmaster Tools is above 0.3% (see sender requirements).
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- Gmail Email Sender Guidelines
- Yahoo Sender Requirements & Best Practices
- Yahoo Complaint Feedback Loop (CFL)
- Yahoo SMTP Error Codes