Check the policy record

  • The TXT record is at _dmarc followed by the policy domain.
  • There is only one valid DMARC policy record at that name.
  • v=DMARC1 appears first.
  • The rua URI is complete and begins mailto:.
  • The address is the unique value shown in the dashboard.

Check external authorisation

If the RUA host belongs to DMARC Analyst rather than the policy domain, the external verification TXT record must resolve and parse correctly. A compliant reporter may decline the destination when authorisation is absent.

policy-domain._report._dmarc.destination-host

Allow for time and traffic

  • DNS caches retain earlier values until their TTL expires.
  • Many aggregate reports cover daily periods and arrive after the period closes.
  • The domain must actually send mail to receivers that generate reports.
  • Not every mailbox provider participates or reports with the same cadence.

When to contact us

If setup verifies, ordinary mail has been sent and nothing appears after 48 hours, contact the team with the domain name and approximate setup time. Do not attach raw reports or passwords to the first message.

Further readingDMARC aggregate reporting — RFC 9990