When Gmail stops trusting a sending server, mail to Gmail addresses doesn't bounce straight away. It is delayed, retried and sometimes dropped days later. People often call this "Google greylisting". This guide explains what Gmail is really doing, how to confirm it from the error you get, what you can fix on shared hosting, and the recovery steps for your own mail server.
Gmail slows down or temporarily refuses mail (4xx errors such as 421-4.7.28) from servers and domains with a poor reputation, and the sending server keeps retrying. Recovery means stopping the source of bad mail, making sure SPF, DKIM and DMARC pass, and then sending normal, wanted mail at a steady rate. On Domain India shared hosting the sending IP is shared and managed by us, so fix what is in your account and open a ticket; on your own server you also control the queue, PTR and HELO.
1. What "Google greylisting" really is
Classic greylisting is a simple trick: a receiving server refuses the first message from an unknown sender with a temporary error and accepts it when the sender retries. Gmail does not publish a greylisting policy of that kind. What senders see instead is Gmail's temporary rate limiting and deferral:
- Gmail answers with a 4xx code, meaning "try again later", rather than a permanent 5xx rejection.
- The sending server keeps the message in its queue and retries.
- If the problem continues, the message eventually expires in the queue and the sender gets a bounce, often days later.
Gmail decides this from the reputation of the sending IP address and of the sending domain, together with whether the mail is authenticated and whether its users mark it as spam.
2. How to confirm it
Look at the error text in the bounce message or in the delivery report. The Gmail codes that matter most:
| Code | What Gmail is saying | Usual cause |
|---|---|---|
| 421-4.7.28 | Unusual rate of unsolicited mail from this IP or domain | A spam burst, a hacked form or mailbox, or sudden high volume |
| 421-4.7.0 or 450-4.7.x | Temporarily deferred or rate limited | Poor reputation or too many messages too fast |
| 550-5.7.26 | Message not authenticated | SPF and DKIM both failed, or DMARC failed |
| 550-5.7.1 | Message rejected as likely spam | Content or reputation, now a permanent refusal |
The 4xx codes are the "greylisting" symptom: mail is delayed but not lost yet. A 5xx code means the message was refused outright and will not be retried.
If mail to Gmail arrives hours late, check for 4xx deferrals. If it never arrives and you get a bounce straight away, read the 5xx code instead; that points to authentication or content, covered in email deliverability: SPF, DKIM, DMARC and BIMI.
3. What usually triggers it
- A spam burst from a compromised mailbox (a stolen password) or a hacked website contact form.
- Password-guessing attacks that succeed and then send through your account.
- Missing or broken authentication: no SPF, no DKIM signature, or a DMARC failure.
- Bulk mail sent from ordinary hosting: newsletters to large or old lists, with high complaint and bounce rates.
- Sudden volume from an IP or domain that normally sends little.
Gmail's sender rules apply to everyone. Senders of more than about 5,000 messages a day to Gmail users must also have DMARC, one-click unsubscribe on marketing mail, and a spam complaint rate below 0.3%, and Google advises staying below 0.1%.
4. If you are on Domain India shared hosting
On shared hosting your mail leaves through the server's shared IP address, which our team manages. You can't change the IP, its reverse DNS (PTR) or the server's HELO name, and support can't give a shared hosting account a different IP address. What you control is your account, your domain and what you send.
- Stop anything sending spam.Change the password of any mailbox you don't recognise sending from, and remove or protect contact forms that send mail without a CAPTCHA.
- Check your authentication.On cPanel, Email Deliverability shows the SPF and DKIM values your domain needs and whether they are valid. DKIM is on by default for new cPanel accounts.
- Add a DMARC recordif your domain has none. Start with
p=noneand a report address, then tighten it later. - Send newsletters elsewhere.Use an email marketing service for bulk mail, not your hosting mailbox.
- Open a ticket with the evidence.Send the full bounce or deferral text, the recipient domain and the time. Our team can see the server's queue and reputation, which you can't.
Outgoing mail from shared hosting is also limited: 200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin. These limits are there to stop exactly the kind of burst that damages an IP's reputation. For contact forms, see how to use PHPMailer for contact forms; for a suspected break-in, see the security checklist for a hacked website.
5. Test and monitor your domain
- Send a test to a Gmail address and open Show original. SPF, DKIM and DMARC should all say PASS.
- Mail-Tester (mail-tester.com) scores a test message and lists problems.
- Google Postmaster Tools (postmaster.google.com) shows your domain's spam rate and whether you meet Gmail's sender requirements. You verify a domain, not an IP, and data appears only once you send enough mail to Gmail users.
Our guide how to test email deliverability for your own website covers these tools step by step.
6. Recovery on your own mail server
This section needs root access to a mail server you run, such as your own VPS. It does not apply to Domain India shared hosting. Before running a mail server on a Domain India VPS, ask support about outbound port 25 and reverse DNS (PTR) for your IP.
Stop the source and clear the queue. Find the account or script sending the spam, lock it, then remove its messages from the queue so they don't keep retrying.
# Exim
exim -bp | exiqsumm # queue summary by domain
exiqgrep -i -f [email protected] | xargs -r exim -Mrm
# Postfix
postqueue -p # list the queue
postsuper -d ALL deferred # delete deferred mail (check first)Make identity consistent. The IP's PTR record should name a host, that host's A record should point back to the same IP, and the server should use the same name in HELO. Publish SPF for the IP, sign with DKIM and publish DMARC.
Slow down, then build back. Lower your sending rate to Gmail for a few days, send only mail people expect, and increase gradually as deferrals stop. In Exim you can limit senders with a ratelimit condition in the ACL; in Postfix, use a transport with a concurrency and rate delay for Gmail. Settings copied from forum posts often use option names that don't exist, so check them against your MTA's documentation and test with exim -bV or postfix check.
Consider a separate sending IP only after the source is fixed. Moving bad mail to a new IP just damages the new IP. If you split mail, keep marketing and transactional mail on separate IPs or services, and warm the new IP up slowly.
There is no form to be removed from Gmail's deferrals. Reputation recovers as Gmail sees clean, authenticated, wanted mail over time; for low-volume senders that is often days rather than weeks, but there is no fixed timeline.
7. Where Domain India fits
If important business mail keeps running into trouble on shared hosting, Business Email is a separate mail service that signs every message with DKIM and provides SPF and DMARC records for your domain. The card shows the live price, excluding 18% GST.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
If you want to run and tune your own mail server, a Domain India VPS is self-managed and gives you root access.
Frequently asked questions
Does Gmail use greylisting?
Not in the classic sense. Gmail temporarily defers or rate limits mail from senders with a poor reputation, using 4xx codes such as 421-4.7.28. The sending server retries, so mail arrives late or eventually bounces.
Can I ask Google to remove my IP from greylisting?
No. There is no delisting form for Gmail deferrals. Reputation recovers as Gmail sees clean, authenticated mail that recipients want, after the source of spam has been stopped.
Will sending on port 587 get around Gmail's deferrals?
No. Port 587 is for your mail app to submit mail to your own server. Your server still delivers to Gmail from its own IP address, and Gmail judges that IP and your domain.
How long does recovery take?
It depends on how bad the spam was and how much mail you send. Low-volume senders with fixed authentication often see deferrals stop within days, but there is no fixed timeline.
Can Domain India give my shared hosting account a different IP?
No. Shared hosting accounts send from the server's shared IP and support cannot change it. Fix spam sources and authentication in your account, and open a ticket with the bounce text; for your own IP, you need a VPS.
What is the Gmail spam rate limit?
Google asks bulk senders to keep the spam complaint rate below 0.3% and advises staying below 0.1%. Google Postmaster Tools shows your domain's spam rate once you send enough mail to Gmail users.
Ready to fix delayed Gmail delivery? Check your records with our deliverability guide, and if mail is still deferred, open a support ticket with the full bounce text.
Send us the full bounce or deferral message, the recipient address and the time. We will check the server side for you.
Open a ticket