We measured the internet's domain security. Most of it is exposed by default.
Enter a domain: you get its grade, every check behind that grade, and the fix for each one that failed.
Independent · 317M domains graded · 33 checks · our servers in the EU · aggregate data in public; any domain's grade on request
Start where your problem is
Seven pages, one per record or surface. Each opens with what the thing is, then routes by the error you are actually looking at.
SPF An SPF record is a DNS TXT line naming the servers allowed to send as your domain. Read yours, match the error in your headers, fix it in minutes. DMARC A DMARC record only changes anything when p= says quarantine or reject. p=none tells every receiver to deliver forged mail as normal and send you a report. DKIM A dkim=fail line names its own cause: the body changed in transit, a signed header changed, or no key answers at the selector. Each is fixed at the sender or in DNS. TLS Match the exact browser error code to its cause (expired, wrong name, untrusted issuer, dead handshake) and fix each one with the command shown. DNS DNSSEC signs your DNS answers so resolvers can reject forged ones. A broken chain makes the domain vanish; 6.9% of domains checked have a valid one. Headers Each HTTP security header, the attack it stops, the share of the web that sets it, and a one-line verdict on whether the audit finding is real or pedantic. Email delivery Your bounce names the reason in a code like 550 5.7.26. Match the code here, open the page that fixes it, and check your domain free before the next send.
September 2026 edition
Every domain we could resolve, graded on the same checks as the scan above. The edition page carries the headline numbers, the data page the tables and the machine-readable twin, the methodology page the rule each check applies.
The edition The data How we grade How to citeWe publish aggregate patterns only, never a list of named domains. Any single domain's grade is shown to whoever runs the free scan.