DMARC: Multiple policies detected
What this means
Multiple records have been detected with a record name of ‘_dmarc’ in the same domain.
Why this is a problem
The DMARC standard only permits one DMARC record in a given email sending domain.
Presence of multiple records may cause DMARC processing to fail and therefore your DMARC policy will not be enforced.
This increases the chances of spoofed emails being sent from your domain, and in some circumstances it can affect email deliverability.
How to check if the problem is there
Check your DNS zone for presence of multiple records named ‘_dmarc’ in the same domain.
You might want to use the following online tools to check for this issue:
- National Cyber Security Centre’s (NCSC) check your email security tool
- Hardenize’s domain report tool
How to fix this
You will need to remove your incorrect DMARC record, ensuring that only one DMARC record remains and is configured in accordance with your requirements.
It is acceptable to have separate DMARC record for subdomains as these will have a different fully qualified domain name.