Skip to main content
contreraspa
Staff
Staff
September 2, 2026

Troubleshooting Tip: FortiMail Cloud rejects Google Calendar notifications with a 550 domain not protected error

  • September 2, 2026
  • 0 replies
  • 29 views

Description

This article describes why email notifications generated by Google Calendar are rejected by FortiMail Cloud with a 550 error stating that the domain is not a protected domain and explains how to create a dedicated routing rule in Google Workspace so these notifications are delivered correctly.

Scope

FortiMail.

FortiMail Cloud.

Google Workspace.

Solution

Google Calendar generates meeting invitations and notification messages from the address calendar-notification@google.com, which belongs to Google rather than to a domain protected by FortiMail Cloud. Google Workspace delivers messages from this address through a path that differs from the normal mail flow used to route mail through FortiMail Cloud. FortiMail Cloud then rejects the message because the sending domain does not match a domain protected by the tenant. The rejection appears in the Google Workspace delivery log as a permanent error similar to the following:

550 5.7.1 Domain example.com is not a protected domain


Other Google-generated system notifications can show the same behavior, such as Drive share notifications sent from drive-shares-dm-noreply@google.com.


To resolve the issue, create a dedicated routing rule in Google Workspace so Google-generated notifications are routed directly to the FortiMail Cloud instance protecting the domain.

  1. Log in to the Google Admin Console and go to Apps -> Google Workspace -> Gmail -> Routing.

  2. Select Add another rule and configure the following settings.
    Name: enter a descriptive name, for example, Relay internal calendar invites.

    Email messages to affect: Select Internal, sending, and Internal, receiving.

    Add another expression: Select the Envelope filter, then Pattern match, and enter a regular expression that matches the sender address, for example, ^calendar-notification@google\.com$.


    If the above matches, do the following: Select Modify Message, then Route, then Change Route, and select the destination host configured to relay mail to FortiMail Cloud, for example, a custom relay pointing to the FortiMail Cloud MX hosts assigned to the domain:

    example-com-1.fortimailcloud.com
    example-com-2.fortimailcloud.com


  3. In the Envelope recipient section, select 'Only affect specific envelope recipients', and enter the internal domain pattern, for example, ^calendar-notification@google\.com$.

  4. Save the routing rule.

  5. Send a test Google Calendar invitation to a recipient within the protected domain, and confirm that the notification is delivered successfully.


FortiMail Cloud assigns two MX hosts to each protected domain, named after the domain.

Confirm that the routing rule points to the correct hosts before saving the rule.

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!