The distinction that matters
On a normal DMARC rejection the message says the mail failed the policy. Here it says permanent error evaluating — the receiver never got as far as a verdict. The fault is in the record, not in the message.
The typical formatting mistakes
v=DMARC1is not first. RFC 7489 §6.3 requires the version tag to be the very first tag. A record startingp=reject; v=DMARC1is invalid even though every part is present.- No
p=tag. The policy is mandatory. A record of onlyv=DMARC1; rua=…is incomplete. - Multiple DMARC records at the same name. If
_dmarc.yourdomain.comreturns two TXT entries withv=DMARC1, the result is undefined under the RFC and treated as an error. Classic after a provider change. - An invalid
pctvalue or a duplicated tag. - The record sits at the wrong name. It belongs at
_dmarc.yourdomain.com, not on the domain itself. Many DNS panels append the domain name automatically. - Smart quotes. Typographic quotation marks pasted from a text document look right in a DNS panel and are not.
Checking it yourself
dig +short TXT _dmarc.yourdomain.com
Expected answer — exactly ONE line, starting with v=DMARC1:
"v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r"
If two lines come back, you have found the cause. If one line comes back that does not start with v=DMARC1, likewise.