Blazalek.com

5.7.20No passing DKIM signature found

The receiving system permanently rejected the message because it contained no DKIM signature that passed verification. Do not retry the same unchanged attempt.

Category
Security, authentication and policy
Class
Permanent failure
Retry
Do not retry unchanged
Suppression
Check the full context

What this code means

The receiving system permanently rejected the message because it contained no DKIM signature that passed verification. Do not retry the same unchanged attempt.

Technical meaning

The standard X.7.20 pattern is returned when a message contains no passing DKIM signature; by definition, this violates the advice in Section 6.1 of RFC 6376. Code 5.7.20 applies this detail in the permanent-failure class.

Delivery status

The leading digit 5 denotes a permanent failure of the current attempt. The code alone does not distinguish between a missing DKIM signature and failure of every signature present, nor does it identify which layer caused that result.

Class
Permanent failure
Retry
Do not retry unchanged
Suppression
Check the full context

Retry decision

Operational guidance: stop automatic and manual retries of the same unchanged attempt because they will not change the DKIM result. Consider a new, controlled attempt only after a confirmed correction and verification that at least one DKIM signature passes; check suppression again first.

Suppression decision

Operational guidance: do not automatically suppress the recipient address or domain based on 5.7.20 alone. Inspect the complete response, DKIM result, configuration of the systems involved, and event history, then make the suppression decision according to the confirmed cause and applicable policy.

Common causes

  • The message contained no DKIM signature at the point where it was evaluated.
  • The message contained at least one DKIM signature, but none passed verification.

Diagnostic steps

  1. Inspect the raw SMTP response or nondelivery report and confirm the exact 5.7.20 code and a basic reply in the 5xx class; retain the complete response text.
  2. Correlate the response with the intended message, attempt time and stage, and system that returned the code. In the message copy from the evaluation point, inspect DKIM-Signature headers and available verification results or logs to distinguish an absent signature from failure of every signature.
  3. Inspect logs and configuration across the signing, transport, and verification path and establish the confirmed cause; do not assign it to the sender, recipient, or provider from the code alone.
  4. Stop unchanged retries. After a confirmed correction, demonstrate that at least one DKIM signature passes verification, check suppression again, and make one controlled attempt.

Actions by owner

Sender

  • Do not repeatedly send the same unchanged message; give the administrator the complete response and attempt time without exposing message content or secrets.

Sender administrator

  • Inspect the sent-message copy and signing and transport logs and configuration; establish whether the signature was absent or every signature present failed verification, then correct only the confirmed cause.
  • After the correction, confirm that at least one DKIM signature passes, check suppression again, and make one controlled attempt instead of retrying the unchanged message.

Recipient administrator

  • If you manage the system that returned the code, inspect its DKIM verification logs and configuration for the specified attempt; correct a confirmed receiving-side problem or safely give the sender the result needed for remediation.

Provider

  • If you operate a managed signing, transport, or verification layer, inspect its logs and configuration for the attempt, correct a confirmed problem in that layer, and do not trigger suppression from the code alone.

Sources and verification

The canonical Tier-0 meaning of X.7.20, its reference to the advice in Section 6.1 of RFC 6376, and its class-5 application were verified against the IANA registry and RFC 2034, RFC 5248, RFC 6376, and RFC 7372 as of July 17, 2026. Diagnostic, remediation, retry, and suppression recommendations are separate operational guidance; this record contains no provider-specific practice.

  • Enumerated Status Codes / X.7.20

  • rfc5248T0 source

    Section 2.1: registry fields and non-exclusive Associated Basic Status Code

  • rfc2034T0 source

    Section 4: enhanced status class agrees with SMTP reply class

  • rfc7372T0 source

    IANA registry reference for X.7.20

  • rfc6376T0 source

    IANA registry reference for X.7.20

Last verified:

Wojtek Blazalek

Email deliverability expert

Stuck on this error code? I help teams clear the root cause of rejections and fix authentication and reputation — so email lands in the inbox.

Hands-on deliverability work for teams that send at scale.