What this code means
The receiving system permanently rejected the message: at least one DKIM signature passed verification, but none was considered acceptable. Do not retry the attempt unchanged.
Technical meaning
The standard X.7.21 pattern is returned when a message contains one or more DKIM signatures that pass verification, but none of those signatures is acceptable. By definition, this violates the advice in Section 6.1 of RFC 6376. Code 5.7.21 applies this detail in the permanent-failure class.
Delivery status
The leading digit 5 denotes a permanent failure of the current attempt. The code confirms that at least one DKIM signature passed verification, but it does not explain why none was accepted or identify which party is responsible for the result.
- Class
- Permanent failure
- Retry
- Do not retry unchanged
- Suppression
- Check the full context
Retry decision
Operational guidance: stop automatic and manual retries of the same unchanged attempt. Consider a new, controlled attempt only after establishing the cause and making a confirmed change that allows at least one passing signature to be accepted; check suppression again first.
Suppression decision
Operational guidance: do not automatically suppress the recipient address or domain based on 5.7.21 alone. Inspect the complete response, DKIM results, configuration of the systems involved, and event history, then make the suppression decision according to the confirmed cause and applicable policy.
Common causes
- The direct reason for rejection was that at least one DKIM signature passed verification, but the receiving system did not consider any passing signature acceptable.
Diagnostic steps
- Inspect the raw SMTP response or nondelivery report and confirm the exact 5.7.21 code and a basic reply in the 5xx class; retain the complete response text.
- Correlate the response with the intended message, attempt time and stage, and system that returned the code. In the message copy from the evaluation point, inspect DKIM-Signature headers and available verification results to confirm that at least one signature passed.
- Inspect logs and configuration across signing, transport, and the receiving DKIM evaluation to establish why no passing signature was accepted; do not assign responsibility from the code alone.
- Stop unchanged retries. After a confirmed correction, verify that at least one passing signature is accepted, check suppression again, and make one controlled attempt.
Actions by owner
Sender
- Do not repeatedly send the same unchanged message; give the administrator the complete response and attempt time without exposing message content or secrets.
Sender administrator
- Inspect the sent-message copy and signing and transport logs and configuration; confirm which DKIM signatures passed verification and coordinate diagnosis of why none was accepted.
- After the correction, confirm that at least one passing signature is accepted, check suppression again, and make one controlled attempt instead of retrying the unchanged message.
Recipient administrator
- If you manage the system that returned the code, inspect its DKIM evaluation logs and configuration for the specified attempt; establish why no passing signature was acceptable and correct a confirmed problem or safely give the sender the result needed for remediation.
Provider
- If you operate a managed signing, transport, or DKIM evaluation layer, inspect its logs and configuration for the attempt, correct a confirmed problem in that layer, and do not trigger suppression from the code alone.
Sources and verification
The canonical Tier-0 meaning of X.7.21, its reference to the advice in Section 6.1 of RFC 6376, and its class-5 application were verified against the IANA registry and RFC 2034, RFC 5248, RFC 6376, and RFC 7372 as of July 17, 2026. Diagnostic, remediation, retry, and suppression recommendations are separate operational guidance; this record contains no provider-specific practice.
- iana-smtp-enhanced-status-codesT0 source
Enumerated Status Codes / X.7.21
- rfc5248T0 source
Section 2.1: registry fields and non-exclusive Associated Basic Status Code
- rfc2034T0 source
Section 4: enhanced status class agrees with SMTP reply class
- rfc7372T0 source
IANA registry reference for X.7.21
- rfc6376T0 source
IANA registry reference for X.7.21
Last verified:

