Defaults.Exposed › Reports
Reports & insights
What we're finding as we measure domain security across the internet — aggregate data, dated, free to cite.
- The Last Mile of HTTPS: Why 27 Million Domains Respond to HTTP but Never Redirect —
~27 million domains have valid TLS certificates but still serve unencrypted HTTP with no redirect and no HSTS — every visitor who types the domain without 'https://' is exposed to SSL stripping. - The Locked Vault: Only 10.9 Million Domains Close Every Attack Surface Simultaneously —
Only 10.9M of 376.9M graded domains (2.9%) pass all five core controls at once. 1.2M (0.33%) fail every single one. The gap is not technical — it is operational. - The Top 1% of the Internet Starts at a B —
376.9M domains scored: entry to the top 1% is 82/100 — a B grade. Only 0.15% earn an A. The median domain scores 45 — a failing F. The web has no security middle class. - The Security Correlation: Which Controls Cluster Together, and Which Sit Alone —
56.8% of 376.9M graded domains have neither SPF nor DMARC. Only 2.9% have all five core controls. Security controls cluster because operator maturity — not cost — is the real variable. - The Phantom TLD Problem: The Domains That Don't Exist —
8 of 1,386 TLDs answer for every name you can invent — inflating .ph's domain count 250× to 14.6 million when the true registration base is about 57,874. Two TLDs were still broadcasting ICANN's name-collision hazard beacon in August 2026. - The Flaky Internet: 20 Million Domains That Only Sometimes Answer —
19,814,020 domains — 4.6% of 432 million scanned — produced inconsistent results across three independent scan attempts. 14.64% of domains that failed their first scan recovered on retry. Here is what that means for internet security measurement. - Who Guards the Web: Cloudflare, WAFs, and the CDN-vs-Origin Measurement Problem —
43,008,476 domains return 'Server: cloudflare' in the August 2026 census — but that number conflates CDN edge-termination with security protection. WAF rules, end-to-end encryption, and origin hardening are invisible in a server header. - The Web Server Census 2026: nginx, Apache, Cloudflare and the Invisible Half —
45.6% of 376 million measured domains suppress their Server header entirely — nearly half the web declines to say what it runs. Of those that declare, Cloudflare leads with 43 million entries. - The Google-and-Yahoo Deadline, Two Years On: Where Email Authentication Stands in August 2026 —
Two and a half years after Google and Yahoo made DMARC a hard requirement, only 9.3% of 376 million graded domains enforce it. 56.8% — 214 million domains — still publish neither SPF nor DMARC at all. - DMARC Without SPF: 16 Million Domains With Half an Email Authentication Stack —
16,238,679 domains publish DMARC but have no SPF record at all — leaving every sending path that lacks DKIM signing with no authentication fallback. August 2026 census data across 376 million domains graded. - Nine Million Domains Where A-Grades Round to Zero —
Across 9,338,016 GoDaddy-default domains, exactly 198 earn an A — an A-rate that rounds to 0.00%. We graded 164.7 million domains by email provider to find out what your MX record says about your security. - SPF Hard Fail vs Soft Fail: Why 82 Million Domains Are Using the Weaker Setting —
82,539,695 domains — 56.4% of all SPF publishers — end their record with ~all (soft fail), providing little real protection. August 2026 census data across 146 million SPF records shows why soft fail became the default and what it costs. - Who Reads the World's DMARC Reports? —
One company receives DMARC spoofing-attack telemetry for 46.8% — 13.9 million — of every report-collecting domain in our 432M-domain census. In most cases nobody chose it. - The Silent Domain: 56.8% of the Internet Has No Email Authentication —
214 million domains — 56.8% of the graded web — publish neither SPF nor DMARC, making the majority of the internet trivially spoofable. August 2026 census of 376.9M domains. - The DNS Landlords: How GoDaddy and Cloudflare Control Nameservers for 94 Million Domains —
GoDaddy and Cloudflare together hold authoritative DNS for 94.7 million domains — 25.1% of the entire graded web — per our August 2026 census of 376.9 million domains. - The Isolation Headers: Why COOP, COEP, and CORP Cover Less Than 1% of the Web —
COOP appears on 0.78%, COEP on 0.48%, and CORP on 0.65% of 376.9 million domains — four years after Spectre made cross-origin isolation essential, fewer than 1 in 100 sites have deployed any of the three required headers. - The HTTP-Only Problem: 44 Million Domains Serving Unencrypted Web in 2026 —
44,443,652 domains — 11.8% of 376.9 million graded — serve HTTP with no TLS, no redirect, and no HSTS, despite free certificates being universally available for over a decade. - CAA Records: 98.9% of Domains Never Restrict Their CA —
98.9% of 376,928,781 domains measured in the defaults.exposed August 2026 Domain Security Census publish no CAA record — leaving them open to certificate issuance by any of approximately 300 publicly trusted certificate authorities. - One CA to Rule Them All: The Certificate Monoculture Report —
Let's Encrypt now secures 50.2% of all 231.5 million certificate-presenting domains measured in the defaults.exposed August 2026 Domain Security Census — and in 23 country-code zones, a single CA holds 80% or more of everything. - The B Ceiling: Where the Climb to an A Grade Stalls —
5.82 million domains score 80–89 but only 549,635 reach 90+. The biggest B-to-A gap is DMARC reporting: 34.4% of B-band domains fail it versus roughly 7% of A-band domains. - DMARC Gap: 87 Million Domains One Record From Safety —
86.9 million domains — 23.1% of 376.9M graded — have SPF but no DMARC record: one free DNS TXT entry away from an anti-spoofing policy. The internet's largest cheap-to-close security deficit. - Cheap Domains, Cheap Security? Budget TLDs vs the Rest —
88.8% of 19.2M graded budget-TLD domains score F — versus 72.4% on .com and 33.7% on .ch. On .top, 96.1% fail and 51.5% of scanned names were dead at scan time. - Do Registry Rules Work? .bank 3.1% F vs .com 72.4% —
3.1% of .bank domains grade F versus 72.4% on .com — a 23× gap. Registry mandates move exactly what they name: vetted-only .pharmacy grades 84.5% F, worse than the open market. - New gTLD Ghost Towns: Where a Third of Domains Are Dead —
36% of 63.8 million new-gTLD domains are dead or unreachable — 2.6 times the legacy-gTLD rate. In .bond, 87.3% of the namespace is gone. Only 58.4% of new-gTLD domains were alive enough to receive a security grade. - Domain Dark Matter: 64 Million Delegated, Empty Domains —
63,840,407 domains — 14.8% of 432 million scanned — have working DNS delegation but no website and no mail route. More than one in three registered domains never produced a gradable scan at all. - IPv6-Only Domains: 80,737 Sites Living Without IPv4 —
Just 80,737 of 376.9 million graded domains publish only an IPv6 address — 0.021%, one in 4,668. Even among the 67.4 million domains that already have IPv6, only one in 834 has dropped IPv4. - Parked Domains: 91% Grade F Across 2.1 Million Measured —
91.3% of 2,147,113 parked domains grade F — compared to 78.3% across the general web. Exactly one parked domain out of 2.1 million earns an A. Parking provider defaults, not owner choices, set the grade. - The Hosting League Table: Domain Security by DNS Provider —
GoDaddy carries 52.4 million domains at 82.9% grade F, and 52% of every A-grade domain on the internet sits behind Cloudflare alone. We attributed 376.9 million graded domains to their DNS provider. - Does Cloudflare Make You Safer? 41.9M Domains Graded —
67.7% of the 41.9 million Cloudflare-fronted domains still score an F — virtually identical to the rest of the web — yet Cloudflare holds 48.7% of all A+ grades. August 2026 census data across 205 million HTTP responses. - DMARC Subdomain Policy: 1.3 Million sp= Back Doors —
1,313,312 domains enforce DMARC at the apex then explicitly exempt their entire subdomain namespace — including 459,577 that reached p=reject and then set sp=none. We parsed 75.5 million records to find the back doors. - DMARC pct Tag: 476,000 Domains Water Down Enforcement —
476,465 domains publish DMARC quarantine or reject — then weaken it with a pct value below 100. We parsed 75.5 million DMARC records to find out where the dials are set. - Zombie MX Records: Mail Routed to Dead Domains —
At least 43,723 dead or unreachable domains still publish mail-routing MX records — a floor figure, not an estimate. The mail is a potential account-takeover risk. August 2026 census. - Null MX Adoption 2026: 14.5 Million Domains Opt Out —
14,455,076 domains publish a null MX record — only 7.0% of the 207 million no-mail domains we graded. RFC 7505 adoption, measured across 376.9M domains. - Broken DNSSEC: 157,064 Domains Are Invisibly Down —
157,064 domains have broken DNSSEC chains — a hard SERVFAIL for every validating resolver. That's 1 in 709 signed domains, and owners can't see the failure. August 2026 census. - Single-Nameserver Domains: One Record from Oblivion —
290,673 domains run on a single nameserver — a complete single point of failure for website, email, and every DNS-dependent service. August 2026 census of 376.9M domains. - SOA Records: The Internet's Most Neglected Setting —
50.5% of 275 million measured domains carry an SOA retry or expire timer outside recommended ranges — the DNS record nobody has ever reviewed. - End-of-Life Software Census: 6.6 Million Servers Admit It —
6,635,647 end-of-life software banners counted across 376.9 million domains — including 2.36 million still running PHP 7.4, nearly four years after its last security patch. - Secure by Default: the Server Software Security Showdown —
Netlify sends HSTS on 95.9% of its sites; Apache on 7.0% — a 13.7× gap across 191.7 million responses showing how your hosting choice, not your security team, determines what protection your users receive. - Referrer-Policy: the Privacy Header 91% of the Web Forgot —
91.4% of 231.9 million HTTP responses carry no Referrer-Policy — leaving browser defaults to decide whether full URLs, search terms, and path-embedded tokens are shared with every third-party server a page contacts. - HSTS Adoption 2026: The Half-Locked Door —
56.2% of 329.9 million HTTPS domains send no HSTS header — and only 4.1% of those that do publish a preload-ready policy — leaving most of the encrypted web unprotected against SSL-stripping attacks. - Content Security Policy Adoption in 2026: the 8.0% Web —
Only 8.0% of 257.6 million measurable domains serve an effective Content-Security-Policy — and 48.3% of those who do land on just two identical scores, revealing platform defaults rather than deliberate security choices. - TLS 1.3 by Country: Which TLDs Win on Defaults (2026) —
94.9% of 231.5 million TLS-completing domains negotiate TLS 1.3 — but South Korea's .kr lags at 73.3% and the US .gov TLD at 77.0%, revealing how infrastructure age, not national wealth, determines encryption quality. - Cipher Suites in 2026: What Strong Encryption Really Means —
Two cipher suites carried 94.33% of 212 million measured TLS handshakes in the defaults.exposed August 2026 Domain Security Census — and RC4, 3DES, and export-grade ciphers appeared zero times. - Wildcard Certificates: 28.5% of the TLS Web on One Key —
28.5% of the TLS web — 66,011,927 of 231.5 million domains measured in the defaults.exposed August 2026 Domain Security Census — runs on wildcard certificates, sharing one private key across every subdomain. - Self-Signed Certificates: The 3.3 Million-Domain Census —
3,306,642 of 231.5 million TLS certificates observed in the defaults.exposed August 2026 Domain Security Census are self-signed — including 375,842 still carrying the 'Internet Widgits Pty Ltd' OpenSSL example default. - Expired SSL Certificates: 5.2 Million Sites Still Serving —
5,157,928 live websites were serving an expired TLS certificate at the moment of the defaults.exposed August 2026 Domain Security Census sweep — 47.8% of those certificates had been expired for over a year. - RSA vs ECDSA in 2026: Measuring the Web's Key Migration —
425,004 live TLS certificates are still signed with MD5, and RSA still holds 59.3% of 231.5 million keys measured in the defaults.exposed August 2026 Domain Security Census — the key migration is real but moving at the speed of defaults, not advice. - The 90-Day Web: Certificate Lifetimes in 2026 —
67.7% of 231.5 million TLS certificates observed in the defaults.exposed August 2026 Domain Security Census were issued for exactly 90 days — the annual certificate is collapsing, and the 47-day era is next. - Who Hosts the Internet's Email? Mostly Not Google or Microsoft (July 2026) —
Census of 297M domains: 52.8% of those with mail servers run self-hosted or on smaller email providers. The cloud giants have not won the domain count. Data as of 2026-07-29. - TLS 1.3 Adoption in 2026: 94.8% of TLS-Reachable Domains —
How TLS 1.3 reached near-universal adoption — our census of 297 million TLS-reachable domains. Data as of 2026-07-29. - July 2026 Domain Security Census: 296.7 Million Domains Graded —
The July 2026 census graded 296,674,837 domains. 73.8% scored an F, while DMARC enforcement climbed to 11.84%. Data as of 2026-07-29. - Internet Rot 2026: 21M Dead Domains, 43,723 Zombie MX —
Dead domains, zombie MX records, and unreachable hosts in our 360-million-domain internet census — the full breakdown. Data as of 2026-07-29. - Fully Protected Domains: 1 in 39 — Two Definitions (2026) —
What is a 'fully protected' domain? 2.79% run SPF, DKIM + enforcing DMARC; 1 in 330 hold all five controls. 297M-domain census, 2026-07-29. - DNSSEC in 2026: Only 6.28% of Domains Validly Signed —
Only 6.28% of the domains we could evaluate publish a valid DNSSEC chain. Another 240,016 zones are signed but broken, which risks taking them offline for users behind validating resolvers. Data as of 2026-07-29. - DNS Concentration: Two Providers Control a Third of the Internet (2026) —
GoDaddy and Cloudflare answer DNS for roughly a third of 297 million domains. The concentration risk, explained. Data as of 2026-07-29. - DMARC Enforcement: 11.84% Now Block Spoofing (July 2026) —
How many domains enforce DMARC against email spoofing — our monthly tracker across 297 million domains, updated each census. Data as of 2026-07-29. - .com vs .ai DMARC Enforcement (2026): .ai Is 3× Ahead —
.ai domains enforce DMARC email protection nearly three times as often as .com — we measured both in our 297-million-domain census. - Certificate Authority Race 2026: GoDaddy vs Google for Second Place —
Free certificates won: Let's Encrypt signs 52.6% of 212M certificate observations in our census. The SSL platform race: GoDaddy 18.6% vs Google Trust Services 17.3%. Data as of 2026-07-29. - BIMI Qualification Report: Who Can Show Their Logo in the Inbox? (2026) —
BIMI puts your logo beside your email, but only domains that enforce DMARC qualify. Just 11.84% of graded domains clear that bar. Data as of 2026-07-29. - Email Authentication: The Complete Guide (SPF, DKIM, DMARC and BIMI) —
SPF, DKIM and DMARC are one system, not three projects. 51.25% of 276 million graded domains publish SPF, but only 11.84% enforce DMARC — the step that actually stops impersonation. The full stack, in order, with a verification gate at each stage. Data as of 2026-07-28. - DMARC vs SPF: What's the Difference, and Which Do You Need? (2026) —
SPF lists which servers may send email for your domain. DMARC decides what happens when a message fails — and it's the only one that protects the 'From' address people actually see. 51.25% of domains publish SPF; just 11.84% enforce DMARC. What each does, why you need both, and in which order. Data as of 2026-07-28. - DMARC p=reject vs p=quarantine: Which Policy Should You Choose? —
reject refuses forged mail outright; quarantine sends it to spam. Of the 11.84% of domains that enforce DMARC, the split is almost even — 6.43% quarantine, 5.41% reject. How to choose, the staged path up, and how to roll back safely. As of 2026-07-28. - SPF Failing With SaaS Tools in the UK or EU? The 10-Lookup Limit Explained (2026) —
SPF fails silently when SaaS include: chains exceed 10 DNS lookups — a limit millions of UK and EU businesses have already crossed. 828,317 domains confirmed affected. Check yours free. - What Is BIMI? How Email Brand Logos Work — And Who Qualifies (2026) —
BIMI shows your brand logo in email clients like Gmail and Apple Mail. It requires DMARC enforcement first — and only 11.84% of domains we've graded have reached that bar. Data as of 2026-07-28. - Which Email Provider Gives Its Customers the Strongest SPF Defaults? (2026) —
84.9% of Microsoft 365 domains end SPF with strict -all; 7.6% of Google Workspace domains do — and no major mailbox provider's customers get past 30% enforced. Data as of 2026-07-28. - Two SPF Records Void Your SPF: a Million Domains Did It (2026) —
Two SPF records void both: 1,019,482 domains publish multiple v=spf1 records, which the standard treats as a permanent error. The copy-paste mistake that switches SPF off, measured across 276 million domains. Data as of 2026-07-28. - SPF ptr Mechanism: Why 946,056 Records Still Use It (2026) —
The SPF ptr mechanism was deprecated in 2014 — slow, unreliable, and a drain on the 10-lookup budget. 12 years later, 946,056 domains still publish it. Data as of 2026-07-28. - SPF PermError: 133× the 10-Lookup Limit (2026) —
SPF voids itself past 10 DNS lookups — and the breakage hides inside include: chains. At least 828,317 domains are over the limit. Data as of 2026-07-28. - The SPF Adoption Maturity Model (SPFAMM): The 6 Stages of SPF (2026) —
The average domain sits at SPF stage 2.4 of 6. SPFAMM: the six-stage SPF maturity model — find your stage and the one move up. Data as of 2026-07-28. - SPF +all: The Domains That Let the Whole Internet Send As Them (2026) —
36,262 domains end their SPF record with +all — explicit permission for anyone on Earth to send email as them. Where the welcome mats cluster, how they got there, and the one-character fix. Data as of 2026-07-28. - The Fully-Protected Few: the 2.79% Who Finished —
Only 2.79% of domains — 7,678,989 — run the full enforced email stack: SPF, DKIM, DMARC at quarantine/reject. Just 0.30% hold all five protections. - The Email Spoofability Index: How Many Domains Can Anyone Forge? (2026) —
9 in 10 domains can be forged: 88.2% of the internet publishes no policy telling receivers to reject or junk failed mail. The spoofability index, from a census of 276 million domains. Data as of 2026-07-28. - The 6 Stages of DMARC Maturity —
25.81% of domains publish a DMARC record — only 11.84% enforce one. A six-stage maturity model, from Unprotected to Hardened, that explains where domains stall and the one move that advances each stage. - Publishing Blind: Most DMARC Records Ask for No Reports —
Only 39.4% of the 71M domains publishing DMARC request reports (rua=). The rest are publishing blind — and one DNS edit fixes it. - SPF ~all vs -all: What 141M Records Chose (2026) —
SPF softfail vs hardfail: 55.9% of records end in ~all — and only 1 in 11 has the setting that gives softfail teeth. Data as of 2026-07-28. - SPF Is Not Enough: 121M Domains Never Enforce (2026) —
121 million domains publish SPF but never enforce DMARC — 85.4% of everyone who set SPF up. Is SPF enough? Measured across the whole internet: no. Only 2.79% of domains are fully email-protected. The exposure, counted. As of 2026-07-28. - 'Your Connection Is Not Private' — What It Means and How to Fix It (2026) —
The full-page 'your connection is not private' warning almost always means a certificate problem. Across domains serving HTTPS, 8.79% present an invalid certificate that triggers it. What the error codes mean and how to clear it. Data as of 2026-07-28. - What Is SPF — and How Do I Fix My SPF Record? (2026) —
SPF tells the world which servers may send email for your domain. 51.25% of 276 million graded domains publish one — but a record alone isn't protection. The common mistakes, and how to fix yours. Data as of 2026-07-28. - What Is DNSSEC — and Do You Actually Need It? (2026) —
DNSSEC signs your DNS so answers can't be forged in transit. Only 6.28% of 276 million graded domains have it — and a misconfigured signature can take you offline. What it protects, who needs it, and how to turn it on safely. Data as of 2026-07-28. - What Is DMARC? p=none, quarantine and reject Explained (2026) —
DMARC is the record that decides whether forged email in your name gets delivered. Only 11.84% of 276 million graded domains set it to enforce — the rest either have none or a monitor-only policy that does nothing. What each policy means and how to set it. Data as of 2026-07-28. - Weak and Outdated TLS: Is Your Site Still Serving Old Encryption? (2026) —
Good news: 94.84% of HTTPS sites now negotiate TLS 1.3. But 'weak TLS' hasn't vanished — it hides in servers that still accept old versions, weak ciphers, and broken certificates (8.79% invalid across 276 million graded domains). How to check you're not the exception. Data as of 2026-07-28. - My SSL Certificate Expired — Why It Happens and How to Fix It (2026) —
An expired or invalid certificate throws a full-page browser warning that stops visitors cold. Across domains serving HTTPS, 8.79% present an invalid certificate. Why certificates fail and how to fix — and prevent — it. Data as of 2026-07-28. - Domain Hijacking: How Domains Get Stolen and How to Stop It (2026) —
Hijacking redirects your visitors and email without touching your servers. The two DNS controls that stop it are barely used: 6.28% of 276 million graded domains have valid DNSSEC and 1.55% publish CAA. How domains are stolen and how to lock yours. Data as of 2026-07-28. - What Cyber-Insurance Checks on Your Domain (2026) —
Insurers and enterprise buyers now ask whether you enforce DMARC, serve modern TLS, and lock down DNS. Across 276 million graded domains, only 2.79% are fully email-protected — so most can't honestly tick the boxes. What's asked and how the internet actually scores. Data as of 2026-07-28. - Why Does My Website Say 'Not Secure'? What the Warning Means for Trust (2026) —
The 'Not Secure' label appears when a site isn't on valid HTTPS. Across 276 million domains, 23.66% serve no HTTPS at all, and 8.79% of those that do have an invalid certificate — so visitors see a browser warning. What it costs and how to fix it. Data as of 2026-07-28. - Why Are My Emails Going to Spam? The Authentication Gap, in Data (2026) —
Most business email lands in spam for one fixable reason: missing authentication. Across 276 million domains, only 51.25% publish SPF, -29.50% use DKIM and 25.81% have any DMARC — the exact signals Gmail and Yahoo now require. Data as of 2026-07-28. - What Your Server Headers Tell Attackers: The Stack-Disclosure Report (2026) —
69.0% of sites announce their web server in the response headers, and 8.3% reveal their app stack and version via X-Powered-By — including end-of-life software. What the web tells attackers for free, in census data. As of 2026-07-28. - The DNSSEC Paradox: More Domains Break It Than Get It Right (2026) —
DNSSEC is meant to stop DNS hijacking — but across 276 million domains, more have it misconfigured and broken (0.09%) than working correctly (6.28%). The rest (93.63%) don't try at all. Why DNS is the internet's most-neglected security layer. Data as of 2026-07-28. - The State of IPv6 in 2026: Still Only 23.15% of Domains —
A decade after 'IPv6 launch', just 23.15% of domains publish an AAAA record — the other 76.85% are IPv4-only. Adoption by country, from a 276-million-domain census. As of 2026-07-28. - Publishing SPF Isn't Enough: The False Sense of Email Security (2026) —
30.9% of domains publish SPF but have no DMARC at all, and 43.8% have SPF without enforcement — they look protected and aren't. Only 2.79% are fully email-protected. The false-security gap, in census data. As of 2026-07-28. - The SPF Misconfiguration Report: Most SPF Records Are Set Too Weak (2026) —
141 million domains publish SPF — but 55.9% use the weak '~all' softfail setting and only 39.2% use strict '-all'. Plus 36,262 domains use '+all', which authorises the entire internet to send as them. The misconfigurations hiding inside published SPF. Data as of 2026-07-28. - Who Runs the Internet's DNS? Nameserver Concentration in 2026 —
Five providers run 44.5% of the internet's DNS. GoDaddy alone hosts 18.5% and Cloudflare 14.7%. The systemic risk of DNS concentration, across 278 million domains. As of 2026-07-28. - The Misconfiguration Hall of Fame: The Web's Weirdest Security Records (2026) —
375,840 sites serve a TLS certificate literally named "Internet Widgits Pty Ltd" — the placeholder nobody changed. DMARC policies written in the wrong language, SPF records that invite the whole internet in, and other gems from a 276-million-domain census. As of 2026-07-28. - The HTTP Security Header Report Card: How the Web Scores in 2026 —
Security headers are free, one-line defences against clickjacking, injection and snooping — and almost nobody sets them. Across 276 million domains, just 0.43% get every header right. CSP 3.78%, HSTS 19.12%, clickjacking protection 5.66%. Data as of 2026-07-28. - Are You Ready for Google & Yahoo's Email Sender Rules? (2026) —
Google, Yahoo and Microsoft now require SPF, DKIM and DMARC to deliver bulk email. Yet only 51.25% of domains publish SPF, -29.50% DKIM, and 25.81% have any DMARC. Whether your domain meets the bar, in census data. As of 2026-07-28. - Half the PHP Web Runs End-of-Life PHP (2026) —
Of the 13 million sites that reveal their PHP version, 42.2% run an end-of-life release that no longer gets security patches — and the single most common version is 7.4.33, dead since 2022. The unpatched PHP web, in census data. As of 2026-07-28. - Who Runs the World's Email? Email Hosting Market Share in 2026 —
Among 163 million domains with an identifiable mail host, 12.7% route mail through Google Workspace and 8.6% through Microsoft 365 — but the biggest category is self-hosted. Email hosting market share, as of 2026-07-28. - The Domain Exposure Score: Most Domains Have 1 of 5 Basic Protections (2026) —
Scored across five core protections — SPF, enforced DMARC, DNSSEC, HTTPS and HSTS — the typical domain has just one or two. 8.5% have none at all; only 0.30% have all five. The exposure curve of 276 million domains, as of 2026-07-28. - Does NIS2 Require DMARC? Email Authentication and EU Cyber Hygiene (2026) —
NIS2 doesn't name DMARC, but it requires cyber-hygiene measures — and email authentication is a baseline anti-spoofing control. Yet across the EU, even the best member state has only 29.59% of domains able to stop impersonation, and most sit far lower. Where EU domains actually stand, as of 2026-07-28. - Does Mandatory DNSSEC Work? What Registry-Driven Adoption Reveals (2026) —
Where registries push DNSSEC, valid adoption runs ~7× higher — 35.8% on registry-driven endings vs 4.7% elsewhere (.se 65.25% vs .com 4.59%). But even the leaders break it more than they get it right. The data, as of 2026-07-28. - "quarentine", "ninguno", "non": The Internet's Most Common DMARC Typos (2026) —
38,650 domains published a DMARC record with a misspelled or invalid policy — "quarentine", "ninguno", "non", or no policy at all — and get zero protection as a result. The typos that quietly break email security, from 71 million DMARC records. Data as of 2026-07-28. - You Set DMARC to p=none — Here's Why You're Still Exposed (2026) —
A DMARC policy of p=none monitors but doesn't protect — your domain can still be impersonated. 13.96% of domains sit at p=none, more than the 11.84% that actually enforce. The false-security trap, in census data. As of 2026-07-28. - Expired, Self-Signed, Invalid: The Certificate Error Report (2026) —
8.77% of the web's TLS certificates fail validation — 18,602,449 domains that present a certificate browsers won't trust. 3,306,642 are self-signed. The certificate errors that show visitors a warning, in census data. As of 2026-07-28. - Who Issues the Web's TLS Certificates? The Top Two CAs Now Own 71% (2026) —
Across 212 million certificates, Let's Encrypt issues 52.6% and GoDaddy 18.6% — together 71.2% of the encrypted web runs on just two certificate authorities. The CA market, measured. As of 2026-07-28. - Can Someone Spoof Your Business Email? For Most Domains, Yes (2026) —
Only 11.84% of 276 million graded domains enforce DMARC — the one control that actually stops email impersonation. The other 88.16% can be spoofed. What that means for invoice fraud, and how to tell if you're protected. Data as of 2026-07-28. - Let's Dig Into WHOIS: The Best-Performing TLDs for Domain Security (2026) —
Only 0.168% of graded domains earn an A or A+ — yet a handful of TLDs run about 8.2× that rate. We dig into which top-level domains have proportionally the most A and A+ domains, as of 2026-07-29. - Which Country's Businesses Are Most Spoofable? (2026) —
China tops the list: 96.7% of its business domains are effectively unprotected against email spoofing. We ranked 69 countries by how forgeable their domains are. Data as of 2026-07-29. - The A-Grade Elite: What the Internet's Most Secure Domains Do Differently (2026) —
Only 2.03% of 297 million domains earn a B or better, and just 0.17% reach an A — about 1 in 600. Here is exactly what the internet's most secure domains have in common, as of 2026-07-29. - The Internet's Dead Domains: How Many Domains No Longer Resolve? (2026) —
Of 360 million domains we track, 21 million (5.8%) no longer resolve to anything. Here's what the internet's dead domains tell us — and the quiet security risk abandoned domains leave behind. Data as of 2026-07-29. - The Internet Security Grade Curve: What an Average Domain Looks Like in 2026 —
We graded 297 million domains A–F. The average domain scores a D or F — only 7.5% reach a C, and just 2.03% earn a B or better. Here is the full grade distribution of the internet, as of 2026-07-29. - New gTLDs vs Legacy Domains: Is .com Really Safer Than .xyz or .ai? (2026) —
We compared the security of legacy endings (.com, .net, .org) against new gTLDs (.ai, .io, .xyz, .top) across millions of domains. The surprise: age doesn't predict safety — price and purpose do. Data as of 2026-07-29. - National vs Generic Domains: Are ccTLDs Like .de and .uk Safer Than .com? (2026) —
We compared 111 national domain endings against 383 generic ones across 297 million domains. National (ccTLD) domains are measurably more secure: 61.5% score an F versus 77.6% on generic endings. Data as of 2026-07-29. - The National Domain Security Index 2026: How Countries Rank on Domain Security —
We graded the business domains behind 111 countries' national endings. 61.5% score an F — and even the best-ranked country leaves most of its domains exposed. The full national ranking, updated live, as of 2026-07-29. - How We Graded the Entire Internet: The A–F Domain Security Methodology (2026) —
How Defaults.Exposed grades 297 million domains from A+ to F across 34 externally observable security checks — what we measure, how the grade is calculated, and the limits of the data. Last updated 2026-07-29. - Europe vs the World: Domain Security in the GDPR Era (2026) —
European businesses protect their domains better than the rest of the world: 54.6% of European national-domain businesses score an F, versus 70.3% elsewhere. But 'better' still means most domains are exposed. The data, as of 2026-07-29. - Emerging-Market Domains: The Security Gap in Fast-Growing ccTLDs (2026) —
National domains in emerging markets score an F 70.6% of the time, against 58.0% in developed economies — an 12.5-point gap. But the spread inside the emerging group is far wider than the gap between groups. The data, as of 2026-07-29. - Domain Decay by TLD: Where Domains Go to Die (2026) —
About 5.8% of all registered domains no longer resolve — but the rate varies wildly by ending. Cheap bulk endings like .xyz decay fastest; established national registries barely at all. The internet's domain mortality map, as of 2026-07-29. - The State of Domain Security 2026 —
We graded 297 million domains across 34 security checks. 73.8% score an F — only 11.84% enforce DMARC, 76.34% use HTTPS, and 0.43% get every security header right. The signal-by-signal state of the internet. - The Domain Security World Cup: who lifts the trophy if the safest domains win? —
We took the real 2026 World Cup draw — all 12 groups, all 48 teams — and let one rule decide every match: the country whose business domains are least exposed wins. Bosnia are world champions, Germany finish bottom of their group, and the hosts go out at home.