Fix library / dmarc-policy-monitor-only
How to fix DMARC policy set to "monitor only" (p=none)
WHAT YOU'RE SEEING
A DMARC check shows "policy: none" and warns you're only monitoring, not protecting.
WHY IT'S HAPPENING
When you first published your DMARC record you set it to p=none (monitor mode). This tells receivers "watch for failures but deliver everything anyway." Spoofers can still impersonate your domain freely.
How to fix it
- 1
Make sure you've been collecting DMARC reports for at least 2 weeks via the rua= tag.
- 2
Review the reports — confirm no legitimate sources are failing DMARC.
- 3
In your DNS provider, update the _dmarc.<yourdomain> TXT record to change p=none to p=quarantine.
- 4
Wait 2-4 weeks. Re-check reports. If still clean, escalate to p=reject for maximum protection.
Where do I add these records? (by DNS host)
Records go in the DNS panel of whoever hosts your domain, not inside Gmail or Outlook. Find your host below.
Cloudflare
- 1.Log in and pick your domain.
- 2.Open the DNS tab, then Records.
- 3.Click Add record, choose the type (TXT/CNAME), paste the Name and Value, Save.
- 4.Tip: Conductor can apply Cloudflare records for you. Connect a token on your domain page instead of doing this by hand.
GoDaddy
- 1.Go to My Products, find your domain, click DNS.
- 2.Under Records, click Add.
- 3.Pick the type, enter the Name (Host) and Value, Save. Use "@" for the root domain.
Crazy Domains
- 1.Log in, go to My Account, then Manage next to your domain.
- 2.Open DNS / Manage DNS.
- 3.Add a record, choose the type, enter the Hostname and Value, Save.
VentraIP
- 1.Log in to VIPControl, open Domain Names, click your domain.
- 2.Choose Manage DNS / DNS Zone.
- 3.Add a record with the type, name and content shown above, Save.
Squarespace / Google Domains
- 1.Open Settings, then Domains, and pick your domain.
- 2.Choose DNS Settings, scroll to Custom Records.
- 3.Add the record type, host and data, Save.
Namecheap
- 1.Go to Domain List, click Manage next to your domain.
- 2.Open the Advanced DNS tab.
- 3.Click Add New Record, set the type, host and value, and save with the green tick.
Not listed? The steps are the same everywhere: find DNS or Manage DNS, add a record, pick the type, paste the name and value shown above.
Not sure if this is your problem?