DMARC record that tells the receiving email server how to handle email that fails either check.
Could be that I misunderstood you, but: It tells what to do if no mechanism (DKIM or SPF) results in a pass. DMARC actually only requires one mechanism to pass. So an email with a DKIM fail, but an SPF pass is considered OK. And vice-versa.
Edit: good advice by the way regarding protecting your domain reputation, I'll check our non-email domains at work first thing tomorrow.
You are of course free to do with email what you want if you run your own email server. It's simply that the DMARC RFC states that only one mechanism has to pass, so if you rely on your server's DMARC implementation you won't get what you want.
Edit: reworded a bit, I made it sound as if only one pass is allowed by DMARC.