DMARC record invalid or missing its policy: how to fix
Why receivers ignore a DMARC record with a typo or no p= tag, the mistakes we see most, and how to write a record that parses.
By the Domain Health Hub team · Updated
- A DMARC record must start v=DMARC1 and carry a p= tag of none, quarantine or reject.
- If p= is missing but a valid rua= is there, receivers treat it as p=none. Otherwise the record is ignored.
- Most errors are small: a wrong separator, quotation marks, or mailto: left off an address.
What it means
There is a record at _dmarc, but it doesn't parse, or it has no policy. Under section 6.6.3 of RFC 7489, a record whose p= tag is missing or invalid is still used as if it said p=none, provided it has a valid rua= address. Without one, the receiver discards the record, and the domain is treated as having no DMARC at all. Either way you aren't getting the protection you meant to set up.
The usual mistakes
- v=dmarc1
- The version must be exactly v=DMARC1, and it must be the first tag.
- commas
- Tags are separated by semicolons. Commas only separate rua= addresses.
- quotes
- Some DNS hosts store the quotation marks you paste as part of the value.
- rua=a@b
- Each address needs mailto: in front: rua=mailto:a@example.com.
- p=monitor
- The only policies are none, quarantine and reject.
- pct=50%
- pct= takes a plain number from 0 to 100.
How to confirm it
The checker shows the record exactly as DNS returns it and says which part it couldn't read. Compare that with what you typed: a DNS host that added quotes or split the string shows up straight away.
How to fix it
Edit the record so it follows this shape, then check again:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
Optional tags go after these: sp= for subdomains, adkim= and aspf= for strict alignment, pct=. Leave them out unless you need them: the defaults are sensible.
Cloudflare DNS
- Open the domain in the Cloudflare dashboard and go to DNS, then Records.
- Add a record of type TXT with the name
_dmarc. Cloudflare adds the domain for you. - Paste the record as the content and save.
Microsoft 365
Microsoft 365 doesn't publish DMARC for your own domain: the record goes wherever the domain's DNS is hosted (your registrar, Cloudflare or similar). Only the onmicrosoft.com domain, or a domain whose DNS Microsoft hosts, is managed in the Microsoft 365 admin centre. Turn on DKIM in the Defender portal before you tighten the policy, so Microsoft 365 email passes on DKIM as well as SPF.
Google Workspace
The same applies: add the TXT record at your DNS host. Make sure Gmail is signing with DKIM for your domain first (Admin console, Apps, Google Workspace, Gmail, Authenticate email), or forwarded email will fail DMARC once you move past p=none.
Questions
Does the order of tags matter?
v=DMARC1 must come first. RFC 7489 expects p= straight after it, and some receivers are strict about that, so put it second.
Are tag names case-sensitive?
Write them in lower case, and the version exactly as v=DMARC1. Values such as reject are case-insensitive, but there's no reason to test that.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.