A DMARC pct of 100 was never the protection it looked like
Answer A DMARC record that says pct=100 is not a strict policy. RFC 9989 retired that tag. Unspam, on September 21, 2026, checked 173 live records from August 15 and found 66 of them still advertising pct=100, which did nothing before the change and does nothing now. Ask what p= is set to. Ignore the decoration.
The note that started this: RFC 9989: DMARC Deleted Three Tags and 46 Percent Still Publish One, Andrian Valeanu, Unspam, September 21, 2026.
Sellers paste a DMARC record into a sales thread the way people paste a password policy: to end the question. The record often includes a pct tag because a generator put it there years ago. The buyer sees 100 and hears fully protected. The tag never meant the mail was protected. In the old sampling design it meant apply the policy to this percentage of failing messages. One hundred percent was the default of doing what the p= tag already said. It was not a second lock.
Andrian Valeanu's September 21, 2026 note is what started this. RFC 9989, published in May 2026, made DMARC a real internet standard and marked three tags historic: pct, ri, and rf. Historic, in the terms he quotes from the RFC, means the tag is deprecated and not expected to be in use. Receivers that follow the new document ignore unknown tags rather than throwing the whole record away. A leftover pct does not break DMARC. It also does not do any work. His count, from 173 live records resolved on August 15, 2026, is the scale. Seventy-nine records, 46 percent, still published at least one of the three historic tags. The pct tag was on 68 records, 39 percent. Pct set to 100 was on 66, 38 percent. Pct set below 100 was on 2 records, about 1 percent. The ri tag was on 16, 9 percent. The rf tag was on 11, 6 percent.
What did RFC 9989 do to the pct tag?
RFC 9989 made DMARC a standards-track document and registered pct, ri, and rf as historic. A receiver following the RFC ignores those tags.
The policy that still matters is p=. None means monitor. Quarantine and reject are enforcement. A record can say p=none and pct=100 and look busy while it enforces nothing. Publishing is not the same as every receiver obeying. It is you having a policy a careful receiver can see.
Below 100 was the leftover that could surprise an operator, and Valeanu found it on two records in that set. Under the old rule, pct below 100 meant enforce on a sample. Under the new rule the tag is ignored, so a domain that thought it was sampling may now be read as enforcing p= on the mail that fails. If you operate the domain, know whether you are that case. If you only rent a send, ask for p= anyway.
What did Unspam find in live DMARC records?
Of 173 live records resolved on August 15, 2026, 79 still published at least one of pct, ri, or rf. The pct tag was on 68, and 66 of those were set to 100.
One hundred seventy-three is not every domain. It is the set he resolved from real sending domains that day. A near-majority of that set still carries a tag the standard just retired, and almost all of those pct values were the no-op value. Records rot. Generators copy. Nobody deletes a tag that does not seem to hurt.
For a solo ad, a rotting record is a tell. A seller who has not looked at DMARC since the generator ran will also not have looked at the complaint export. Safe solo ads sellers can say the p= value without a speech.
What should a solo ad buyer ask about DMARC?
Ask whether the sending domain publishes DMARC, what the p= value is, and whether anyone reads the reports. A pct=100 tag is not the answer.
Three questions. Published or not. p=none, quarantine, or reject. Is a human reading the aggregate reports. You are not demanding they jump to reject tonight. A monitored p=none is an honest stage. An unmonitored record with a decorative pct is a screensaver.
Put the p= value next to the from-name when they have one. If they have none, the domain has not published a policy, and the seller has skipped a basic step. Buy solo ads with that fact in view. The tag that said 100 was never the protection. The policy, and the person who reads the reports, are the protection.