How the message looks
554 5.7.5 Permanent error evaluating DMARC policy 554-5.7.5 Permanent error evaluating DMARC policy. For more information, go to https://support.google.com/mail/answer/2451690 smtp; 554 5.7.5 Permanent error evaluating DMARC policy

The distinction that matters

On a normal DMARC rejection the message says the mail failed the policy. Here it says permanent error evaluating — the receiver never got as far as a verdict. The fault is in the record, not in the message.

The typical formatting mistakes

  1. v=DMARC1 is not first. RFC 7489 §6.3 requires the version tag to be the very first tag. A record starting p=reject; v=DMARC1 is invalid even though every part is present.
  2. No p= tag. The policy is mandatory. A record of only v=DMARC1; rua=… is incomplete.
  3. Multiple DMARC records at the same name. If _dmarc.yourdomain.com returns two TXT entries with v=DMARC1, the result is undefined under the RFC and treated as an error. Classic after a provider change.
  4. An invalid pct value or a duplicated tag.
  5. The record sits at the wrong name. It belongs at _dmarc.yourdomain.com, not on the domain itself. Many DNS panels append the domain name automatically.
  6. Smart quotes. Typographic quotation marks pasted from a text document look right in a DNS panel and are not.

Checking it yourself

dig +short TXT _dmarc.yourdomain.com Expected answer — exactly ONE line, starting with v=DMARC1: "v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r"

If two lines come back, you have found the cause. If one line comes back that does not start with v=DMARC1, likewise.

Find the cause in the actual message

Send or forward the affected email to hello@analyzemy.email. For that exact message the report shows which IP sent it, how SPF, DKIM and DMARC turned out, and where the chain breaks.

Analyze your email now

Last updated: · All error messages