← Blog
DMARC Adoption, September 2026: The Library of Congress Locks Down 18 Domains

By DMARCdrift Team

DMARC Adoption, September 2026: The Library of Congress Locks Down 18 Domains

5 min readdmarcresearchgovernment

Every month we scan 2,240 domains across 10 categories, from the Fortune 100 to every federal .gov domain, and record their DMARC policy. The September scan ran on September 1 and is compared here against the August 19 scan. The full domain-level results are on the DMARC adoption research page, and the year-to-date picture is in our 2026 DMARC adoption statistics.

The numbers

  • 83.3% publish a DMARC record, up from 82.7%.
  • 68.5% enforce p=reject, up from 67.9%.
  • 1,534 domains are fully enforcing, up 12.

Much of that gain is measurement, not policy. In August, 8 Fortune 100 lookups timed out. In September all 8 resolved, and all 8 already had DMARC. A domain whose lookup fails counts against the percentage, so a quiet month for timeouts looks like a good month for adoption.

Counting only domains that resolved in both scans, 24 changed. Twenty moved to p=reject, three dropped DMARC entirely, and one raised its enforcement percentage. Eighteen of the twenty belong to a single agency.

The Library of Congress locks down its parked domains

Between the two scans, 18 Library of Congress domains went from no DMARC record at all to p=reject:

  • Legacy and program sites: thomas.gov, americanmemory.gov, americaslibrary.gov, read.gov, literacy.gov, law.gov, lis.gov, section108.gov, currencyreader.gov, tps.gov, loctps.gov
  • Name variants: libraryofcongress.gov, uscongress.gov, unitedstatescongress.gov
  • Heritage-month sites: blackhistorymonth.gov, africanamericanhistorymonth.gov, asianpacificheritage.gov, nativeamericanheritagemonth.gov

Some of these still serve a website and some redirect to loc.gov or congress.gov, but none of them receives email: not one has an MX record. Each now publishes a bare v=DMARC1; p=reject with no reporting address, and 17 of the 18 also publish an SPF record of v=spf1 -all, which says no server is allowed to send as the domain. That is the complete lockdown for a domain that never sends mail: receivers reject anything claiming to be from it, and there are no reports to read because there is no legitimate traffic to report on.

thomas.gov is a good example of why this matters. THOMAS was Congress's legislative database until congress.gov replaced it in 2016. A retired domain with a name people still recognize is exactly what a phisher wants, because nobody at the agency is watching it. We cover the pattern in more detail in parked domain spoofing.

The contrast is loc.gov itself, the domain that actually sends the Library's mail. As of September 23 it is still at p=none, with aggregate and forensic reporting turned on. crb.gov, the Copyright Royalty Board, was at p=reject in the September 1 scan and had moved back to p=none with reporting by September 23.

That split is the normal shape of a DMARC rollout. Parked domains are the easy win because no legitimate mail can break. The sending domain is the hard part, because moving to enforcement means first knowing every service that sends as you. Reporting at p=none is how you find them.

Also moving

  • Marathon Petroleum (Fortune 100) raised its p=quarantine enforcement from pct=25 to pct=50 in the September scan. As of September 23 it publishes a full p=reject. The pct tag used for that kind of gradual ramp is gone from the current DMARC standard; see what replaced pct.
  • igorville.gov, the test domain the .gov registry itself uses, moved from no record to p=reject.
  • dei.gov and waste.gov (White House Office) published p=reject in August and no DMARC record in September. Both still have live DNS zones with no MX or SPF record, so no policy tells receivers to reject mail that claims to come from them.
  • usdapii.gov went from p=reject to no record. The domain no longer resolves and is no longer in CISA's .gov registry list, so it looks decommissioned rather than downgraded.

Category breakdown

Category DMARC % p=reject % Change in p=reject vs. August
Top 25 US Banks 100.0% 92.0% no change
Hospital Systems 100.0% 80.0% no change
US Federal .gov 84.2% 78.6% +0.7 pts
Fortune 100 99.0% 78.0% +6.0 pts (see note)
Cybersecurity Vendors 100.0% 77.5% no change
Top 100 SaaS 100.0% 73.0% no change
Major News Outlets 96.7% 70.0% no change
Tranco Top 500 68.4% 43.6% -0.6 pts (see note)
Top 50 Universities 100.0% 34.0% no change
State Governments 88.0% 30.0% no change

The Fortune 100 change comes from August's 8 lookup timeouts resolving, not from policy changes. The Tranco dip comes from lookup errors rising from 9 to 14 and from 15 domains rotating in and out of the Tranco list.

Seven of the ten categories didn't move at all. State governments are still nearly 49 points behind federal agencies on p=reject, a gap we looked at in state vs. federal DMARC. State governments and universities remain the two least-enforced groups we track, both with most of their domains stuck at p=none or p=quarantine.

What to take from this

If you own domains that don't send mail (old product names, redirects, typo defenses, a project you shut down), give each one v=DMARC1; p=reject, an SPF record of v=spf1 -all, and no MX record. It takes a few minutes per domain, and like the Library of Congress you can do it long before your main domain is ready for enforcement.

For the domain you do send from, start at p=none with reporting and work toward enforcement once the reports show every legitimate sender passing. Check where any domain stands with the DMARC checker, or see how easy it is to spoof with the spoofability score.

The next scan runs October 1, and the research page is refreshed with each scan.