Skip to content
DMARC

More than one DMARC record: how to merge them

Two TXT records at _dmarc means receivers apply no DMARC policy at all. How to find the duplicates and merge them into one record.

By the Domain Health Hub team · Updated

In short
  • There must be exactly one TXT record starting v=DMARC1 at _dmarc.<domain>.
  • With two or more, RFC 7489 tells receivers to stop DMARC processing, so the domain behaves as if it had none.
  • Keep one record, merge any rua= addresses into it, and delete the rest.

What it means

We found more than one TXT record starting v=DMARC1 at _dmarc on this domain. It usually happens when a second service, such as a DMARC reporting tool or a newsletter platform's set-up wizard, adds its own record instead of editing the existing one.

Why it matters

Section 6.6.3 of RFC 7489 is blunt: if more than one DMARC record is returned, the receiver stops DMARC processing for that message. Your policy is ignored, so a domain set to reject is no better protected than one with no record, and receivers may send no reports either. Nothing bounces, so this can go unnoticed for months.

How to confirm it

The checker lists every record it found at _dmarc. Look in the DNS host too: some control panels show records at _dmarc and _dmarc.example.com as separate entries when they are the same name.

How to fix it

  1. Copy every DMARC record somewhere safe before changing anything.
  2. Pick the one with the policy you want to keep. If they disagree, keep the less strict policy until the reports show every sender passing.
  3. Merge the report addresses: rua=mailto:a@example.com,mailto:b@example.net.
  4. Delete the other records and check again.
Before
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com
and
v=DMARC1; p=none; rua=mailto:reports@vendor.example
After
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com,mailto:reports@vendor.example

Cloudflare DNS

  1. Open the domain in the Cloudflare dashboard and go to DNS, then Records.
  2. Add a record of type TXT with the name _dmarc. Cloudflare adds the domain for you.
  3. Paste the record as the content and save.

Microsoft 365

Microsoft 365 doesn't publish DMARC for your own domain: the record goes wherever the domain's DNS is hosted (your registrar, Cloudflare or similar). Only the onmicrosoft.com domain, or a domain whose DNS Microsoft hosts, is managed in the Microsoft 365 admin centre. Turn on DKIM in the Defender portal before you tighten the policy, so Microsoft 365 email passes on DKIM as well as SPF.

Google Workspace

The same applies: add the TXT record at your DNS host. Make sure Gmail is signing with DKIM for your domain first (Admin console, Apps, Google Workspace, Gmail, Authenticate email), or forwarded email will fail DMARC once you move past p=none.

Questions

Can I have one record for policy and another for reports?

No. Everything goes in one record. rua= takes several addresses separated by commas.

Does a CNAME at _dmarc count as a record?

Yes. A CNAME can't sit beside other records at the same name, so if you use a hosted DMARC CNAME, delete every TXT record at _dmarc first.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial