44,548 .gov domains, eight years after BOD 18-01
The September 2026 census holds 44,548 names under .gov, and 27,928 of them are dead. When the scan asked for their name servers, the answer was a definitive empty one. 27,912 of those dead names are missing from the list of registered .gov domains that CISA publishes. The census’s source lists still carry them, and the registry doesn’t. The live side matches the registry closely. On 4 September 2026, the day of the scan, the registry listed 16,637 .gov domains, and 16,079 of them are among the census’s 16,089 live, graded .gov domains.
That is why this page leads with live domains. On the census’s standard base, graded plus dead, 74.8% of .gov scores an F, and dead names make up 84.8% of those Fs. Among the 16,089 live, graded .gov domains the F share is 31.1%.
Figure 1. The census holds far more .gov names than the registry lists, and the dead names make up the difference. The live, graded names and the registry are almost the same set of domains.
CISA’s Binding Operational Directive 18-01 binds one group of .gov holders: federal executive branch agencies. It gave them until 16 October 2018, almost eight years before this census, to publish a DMARC (Domain-based Message Authentication, Reporting and Conformance) policy of p=reject on every second-level domain. In September 2026, 89.2% of the 1,109 live federal executive .gov domains publish p=reject. Among the 1,289 live state and territory domains, which the directive does not cover, 14.0% do.
Figure 2. DMARC p=reject by domain type in CISA’s registry list, with the number of live, graded domains in each group in brackets.
What the directives asked for
Four federal instructions set the controls this page measures. Each is addressed to federal executive departments and agencies or their chief information officers.
- BOD 18-01, dated 16 October 2017. Within 90 days, valid SPF (Sender Policy Framework) and DMARC records on all second-level domains. Within 120 days, HTTPS-only with HSTS (HTTP Strict Transport Security) on publicly accessible websites. Within one year, by 16 October 2018, a DMARC policy of p=reject on all second-level domains and mail-sending hosts. It also required agencies to name
reports@dmarc.cyber.dhs.govas a recipient of DMARC aggregate reports. - OMB M-15-13, dated 8 June 2015. HTTPS-only with HSTS on all existing federal websites and web services by 31 December 2016, with an HSTS max-age of at least one year.
- OMB M-08-23, dated 22 August 2008. Every agency .gov domain signed with DNSSEC (Domain Name System Security Extensions) by December 2009.
- OMB M-21-07, dated 19 November 2020. At least 20%, 50% and 80% of IP-enabled assets on federal networks running IPv6-only by the end of fiscal years 2023, 2024 and 2025. It notes that a 2010 memorandum required public-facing web, email and DNS (Domain Name System) services to use native IPv6 by the end of fiscal year 2012.
State, county, city and tribal governments hold most registered .gov domains, and none of the four applies to them.
.gov beside .edu and .us
Two neighbours give a reference point. .edu has no federal mandate of this kind, and .us is the United States country-code domain. The first table shows what the census holds in each, and why .gov needs a different base from the other two.
| .gov | .edu | .us | |
|---|---|---|---|
| Names in the census | 44,548 | 6,891 | 1,314,805 |
| Dead (no name servers) | 27,928 | 0 | 1,329 |
| Alive | 16,620 | 6,891 | 1,313,476 |
| Live and graded | 16,089 | 6,685 | 1,255,826 |
| Graded plus dead, the census’s standard base | 44,017 | 6,685 | 1,257,155 |
An alive domain that isn’t graded answered the scan without giving the checks enough to grade, or never answered at all. How the domains were counted explains each state.
The second table uses one base in every column: the live, graded domains of that TLD (Top-Level Domain).
| Share of live, graded domains | .gov | .edu | .us |
|---|---|---|---|
| Domains in the base | 16,089 | 6,685 | 1,255,826 |
| Publish a DMARC record | 58.4% | 74.9% | 20.8% |
| DMARC p=reject | 18.8% | 15.9% | 4.2% |
| Publish an SPF record | 81.1% | 85.0% | 46.9% |
| Serve HTTPS (Hypertext Transfer Protocol Secure) | 78.7% | 90.2% | 64.7% |
| HSTS header, or on the preload list | 40.5% | 23.9% | 11.4% |
| DNSSEC signed | 12.7% | 4.8% | 2.8% |
| IPv6 address on the apex | 18.7% | 20.8% | 13.8% |
| Grade F | 31.1% | 22.9% | 81.0% |
Figure 3. The seven controls in the table above, each as a share of that TLD’s live, graded domains.
Taken as a whole, live .gov sits closer to .edu than to .us. .edu is ahead on publishing a DMARC record, SPF, HTTPS and IPv6. .gov is ahead on p=reject, HSTS and DNSSEC. .us trails both on every row. The zone-wide .gov figures also blend the one group the directives bind with the much larger groups they don’t, and the registry’s domain types pull them apart.
.gov by who holds it
CISA’s public dotgov-data list gives a domain type for every registered .gov domain. Joined to the census on the domain name, it splits the live, graded .gov domains into the groups below. The two count columns come first. Every share after them uses the same base: the live, graded domains in that row.
| Domain type | Registered | Live and graded | p=reject | SPF | HTTPS | HSTS or preload | DNSSEC | IPv6 |
|---|---|---|---|---|---|---|---|---|
| Federal Executive | 1,175 | 1,109 | 89.2% | 91.9% | 81.6% | 77.8% | 84.8% | 49.8% |
| State or territory | 1,421 | 1,289 | 14.0% | 51.7% | 74.3% | 31.0% | 13.9% | 16.4% |
| County | 2,658 | 2,594 | 16.8% | 84.0% | 74.7% | 46.1% | 8.3% | 15.7% |
| City | 9,040 | 8,840 | 12.1% | 85.1% | 80.9% | 37.2% | 5.0% | 15.9% |
| Tribal | 287 | 274 | 18.6% | 82.8% | 67.2% | 35.4% | 2.9% | 9.9% |
| Federal Legislative and Judicial | 145 | 135 | 28.1% | 56.3% | 68.9% | 25.9% | 74.8% | 31.1% |
| All other types | 1,911 | 1,838 | 13.8% | 74.0% | 78.1% | 35.0% | 8.3% | 19.2% |
| All registered .gov | 16,637 | 16,079 | 18.8% | 81.2% | 78.8% | 40.6% | 12.7% | 18.7% |
“All other types” covers special districts, election offices, school districts, interstate bodies and two domains typed only as Federal.
Federal executive domains lead every column. Their p=reject share is 89.2%. State, county, city and tribal domains sit between 12.1% and 18.6%. DNSSEC shows the same split: 84.8% of federal executive domains are signed, against 2.9% to 13.9% for the four non-federal groups. Legislative and judicial branch domains are federal and outside BOD 18-01. On p=reject they sit between the executive branch and the non-federal groups, at 28.1%. On DNSSEC they are nearer the executive branch, at 74.8%.
Figure 4. For each control, the dot is the federal executive branch and the grey bar runs from the lowest to the highest of the state, county, city and tribal groups.
Few domains have all six controls in place. A domain passes all six here if it publishes p=reject and SPF, serves HTTPS, has HSTS by header or preload, is signed with DNSSEC and has an IPv6 address on the apex. 421 live .gov domains pass all six, and 382 of them are federal executive.
The census shows where the gap is. It can’t show why.
The federal executive branch, read against the directive
The registry lists 1,175 federal executive .gov domains, and every one of them is in the census. 1,109 are live and graded, 6 are dead and 60 were unreachable or could not be graded. The table reads the 1,109 live, graded domains against the directive’s own wording where the census can see it.
| Federal executive, live and graded | Domains | Share |
|---|---|---|
| DMARC p=reject | 989 | 89.2% |
| p=reject with no weaker sp= and pct at 100 | 981 | 88.5% |
reports@dmarc.cyber.dhs.gov in rua= | 951 | 85.8% |
| SPF record | 1,019 | 91.9% |
| Serve HTTPS | 905 | 81.6% |
| Serve HTTPS and redirect HTTP (Hypertext Transfer Protocol) to it | 703 | 63.4% |
| HSTS header with max-age of a year or more | 609 | 54.9% |
| On the HSTS preload list | 670 | 60.4% |
| Either of the two rows above | 852 | 76.8% |
| DNSSEC signed | 940 | 84.8% |
| IPv6 address on the apex | 552 | 49.8% |
The second row uses the stricter form CISA’s guidance describes for the deadline: p=reject at 100 percent, with no subdomain policy weaker than reject. It lowers the figure by less than a point.
HSTS needs two rows because the directive accepts either route. CISA’s page on the directive says preloading a domain is technical compliance with its HTTPS requirement, and that the .gov registry began preloading new federal .gov domains automatically in 2017. According to get.gov, every newly registered .gov domain is now preloaded, and the registry intends to preload the .gov top-level domain as a whole. On the Chromium list of 31 August 2026 it hadn’t yet: the list carried no entry for .gov itself, and 5,064 entries for individual .gov domains. Across all live .gov domains, 18.3% send an HSTS header, 29.2% are preloaded, and 40.5% have one or the other.
What the census can and can’t see
- The census reads the apex of each domain. The directive’s web and mail clauses cover every public website and mail-sending host, and many of those sit on subdomains the census doesn’t visit.
- The stricter DMARC row reads the p=, sp= and pct= tags on each domain’s own record. It can’t see whether a subdomain publishes a weaker DMARC record of its own, which the directive’s guidance also rules out.
- HTTPS here means a completed TLS (Transport Layer Security) handshake on the apex. A domain that runs no website counts as not serving HTTPS, though the directive’s HTTPS clause is about websites.
- IPv6 here means an AAAA record on the apex. M-21-07’s targets concern assets on federal networks, which can’t be seen from outside, so the apex figure says nothing about M-21-07 progress.
- DNSSEC signed means the domain publishes both a DS (Delegation Signer) and a DNSKEY (DNS Public Key) record. The census doesn’t validate the signatures.
- This page covers .gov only. CISA’s guidance says the directive covers agency mail and web systems whatever the domain suffix, so federal domains under other TLDs are left out. CISA’s directives also exclude national security systems and certain Defense Department and Intelligence Community systems.
- Domain types come from CISA’s registry list and preload status from the Chromium HSTS preload list, each the last version published before the scan. Neither is census data.
For the grade shares of every TLD on the census’s standard base, see the TLD statistics page. The DMARC pillar explains what p=reject does to spoofed mail, and HSTS explains the header and the preload list.
See your own
The free scan reads any domain live, .gov or otherwise, on the same checks the census uses, including DMARC, SPF, HTTPS, HSTS, DNSSEC and IPv6.
Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Domain types from CISA’s public dotgov-data list as of 4 September 2026; preload status from the Chromium HSTS preload list as of 31 August 2026. Census numbers move every month; the current values are on the data page.