Internet Rot 2026: 21M Dead Domains, 43,723 Zombie MX
Published · updated
Figures as of 2026-07-29 · methodology v8. Aggregate census data; we never publish an individual domain’s status or grade. See how we grade.
The internet is rotting, and the rot comes in two distinct kinds. A third bucket holds the domains nobody can measure with confidence. All three keep getting mixed up. Our July 2026 census inventory holds 360 million domains this edition. Of those, 21 million are dead: still registered, but no longer resolving to a usable address. Another 27 million resolve in DNS, yet nothing answers when you knock. A further 36 million could not be conclusively assessed at all.
Those are three different numbers describing three different failures. Headlines routinely blur them into one figure. This page keeps them apart. Our June deep-dive, the internet’s dead domains, covers why domains die; this report is the current edition’s count. It also introduces the strangest population in the whole census: 43,723 domains our census classifies as dead or unreachable, yet which still publish mail (MX) routes.
What exactly counts as a “dead” domain?
Most rot statistics in circulation mix at least two of the categories below. Our census keeps them strictly separate, because each one carries a different security risk.
| Category | Precise definition | This edition |
|---|---|---|
| Dead | Registered, but no longer resolves to a usable address — nothing left to visit | 21 million (5.8% of inventory) |
| Unreachable | Resolves in DNS, but no service responds to contact | 27 million |
| Indeterminate | Could not be conclusively assessed this edition | 36 million |
Dead means the name is still on a registry’s books, but it no longer resolves to a usable address. Every name in this count appears in current registry data this edition. Someone may still be paying for it. Or it has lapsed and is sitting in the grace window a registry holds a name in before releasing it. Either way, there is nothing left to visit. In most cases there is nothing to grade beyond the failure itself.
Unreachable is a subtler decay. DNS still works: the domain resolves and records exist. But nothing responds when you try to connect. No web server, no live service. Nobody answers the door.
Indeterminate is our honesty bucket. It holds the timeouts, the flaky infrastructure and the ambiguous responses — everything we could not classify with confidence. These domains are not counted as dead. They are not counted as healthy either. Any survey that quietly folds its indeterminate cases into one side or the other is inflating a number somewhere.
Two more totals complete the picture. 339 million domains in our inventory are not classified dead — but that figure still contains the unreachable and indeterminate populations. The graded total is 297 million domains: everything except unreachable and indeterminate cases. Dead domains are graded on the failure itself.
How many dead domains are there in 2026?
As of 2026-07-29, 20,991,355 registered domains are dead. That is 5.8% of the 360,067,238 registered domains in this edition’s inventory. Our inventory is large but not total: it does not cover every country-code (ccTLD) zone. So the worldwide stock of registered-but-abandoned namespace is, if anything, larger.
Add the 27 million unreachable domains and the true shape of the problem appears. A vast belt of names that are neither gone nor genuinely in use. They sit in registries, in DNS, in old email address books and in supplier records. Half-remembered, wholly unmonitored.
That last part is the point. A dead domain is not just an accounting curiosity. It is a name that people, systems and inboxes may still trust. Is one of those names yours? Scan any domain free — it takes seconds to see whether a name still resolves and what records it still publishes.
Which TLDs have the most dead domains? .com vs .xyz vs .de
Where a domain lives says a lot about how likely it is to be abandoned. By “where”, we mean the zone its name ends in: .com, .xyz, .de. Industry experience points to two drivers. Zones with very cheap first-year pricing attract speculative bulk registrations — names that are cheap to buy and cheap to walk away from after the first year. Long-established country-code zones (ccTLDs) tend to have stricter registration rules and more actively managed registries. One honest caveat: our census measures the dead share by zone, not the causes. Those drivers are the industry’s standard explanation, not something the census itself measures.
| Zone | Dead share this edition |
|---|---|
| .com | 4.1% |
| .xyz | 1.5% |
| .top | 40.7% |
| .de | 2.3% |
| .uk | 5.3% |
| All country-code TLDs (ccTLDs) | 3.6% |
| All generic TLDs (gTLDs) | 6.5% |
The question has two honest answers. In absolute counts, .com holds the most dead names outright, because it is the largest zone on earth. By share, this edition’s table puts the budget zones .xyz and .top well above the long-established European ccTLDs. Both are known for very low first-year pricing. The full breakdown for every zone is on the TLD pages, and a deeper mortality table lives in domain decay by TLD.
These are snapshot figures for this edition. We plan to track decay by zone from edition to edition, using the disposition definitions in our versioned methodology — v8 this edition. Definitions do change. The composite grading methodology moved from v7 to v8 between the June and July editions. When a definition changes, we version it and say so, rather than compare silently. We will compare decay across editions only where the definitions are like for like. If one of your domains lives in these zones, you can see where it stands right now: scan it free.
What is a zombie MX domain? 43,723 ghosts still wired for email
A zombie MX domain is a domain our census classifies as dead or unreachable, yet which still publishes MX records. An MX record is the DNS entry that tells every mail server in the world, “deliver email for this name here.” So a zombie may still receive email. Among the dead and unreachable populations, 43,723 domains still publish MX records. It is one of the smallest numbers in this report, and the one that should worry you most. The MX record points at a mail host — often a third party’s — that resolves and answers on its own. It does not care that the domain’s own infrastructure is dead or silent. That is why the mailbox line can outlive everything else.
One note on method. A domain lands in this count only when this edition’s census observed MX records published in its DNS. We count published routes; we do not test delivery. (For how MX publication looks across the whole inventory, see what percent of domains have MX records.) Zombies are therefore a small share of the dead-and-unreachable belt of 21 million plus 27 million domains. But the published route is the danger. Nothing answers on the web side. The business, in many cases, is gone. Often the mailbox line was simply never formally disconnected. Email sent to these domains does not necessarily bounce with a clean “address no longer exists”. Wherever the MX target still answers, mail can be routed, accepted, and land somewhere nobody is watching.
Walk the risk chain:
- Mail keeps being sent. Password resets, invoices, supplier threads, HR correspondence, newsletters full of personal data. All of it still arrives at an unattended address — and it will not stay unattended.
- The registration eventually expires. Abandoned domains stop being renewed. When an expired domain drops, anyone can re-register it for the price of a single year.
- The new owner inherits the mail stream. Stand up a catch-all mailbox, and everything still addressed to the old organisation flows straight to the new registrant. Trigger a password reset on an account registered with an old address, and the reset link lands in the attacker’s inbox — unless a second factor stands in the way. Reply to an in-flight invoice thread, and the payment details can quietly change.
This is one route into business email compromise and invoice redirection. The FBI’s annual cybercrime reporting consistently ranks that fraud family among the largest loss categories: billions of dollars a year across all its variants, with average reported losses per incident in six figures. The domain renewal that takes this particular route off the table costs about as much as lunch.
No step in that chain needs a technical exploit. It takes a registrar account and patience. To be clear: everything from the password reset onward is criminal fraud. The point is how little skill it takes. We publish only the aggregate count, never which domains. But attackers do not need our data. This hunt runs on public DNS, and the 43,723 ghosts are findable by anyone who looks.
Wondering whether one of your own forgotten domains is sitting on somebody’s re-registration watchlist? Run the free scan. It shows whether a forgotten name still publishes mail routes.
What should you do with a domain you no longer use?
There are only two defensible endings for a domain, and “quietly stop paying for it” is neither.
Ending one: keep it, decommissioned. Keep the registration, but shut the doors properly:
- Publish a null MX record (RFC 7505) — the standard way to declare that a domain neither sends nor receives email.
- Add an SPF record that fails all senders — it tells receivers that no one may legitimately send mail as this domain.
- Finish with a DMARC policy set to reject — it instructs receivers to bin anything that tries.
Compliant mail servers will now bounce messages immediately and cleanly. For as long as you hold the registration and keep these records published, there is no inbox for anyone else to inherit. Then scan the domain free to confirm the shutters actually closed. Publishing these records is easy; publishing them correctly is not. This census counts 38,650 malformed DMARC records alone.
Ending two: release it, drained first. If you genuinely must let a domain go, do the work before it lapses. Inventory every account, service and supplier relationship ever attached to its addresses. Migrate them. Watch the inbound mail until it runs dry. Only then release the name — accepting that whoever registers it next inherits whatever you missed.
For any domain that ever handled money or logins, the honest advice is ending one, forever. The renewal fee is not a subscription to a website. It is insurance against someone else becoming you.
What this means for your business
Your attack surface includes every domain your organisation has ever registered: old brand names, campaign microsites, the domains of companies you acquired. Each one that decays into the dead-or-unreachable belt while still publishing MX records is a standing invitation.
The risk runs both ways, because your suppliers’ rot is your problem too. If a partner’s domain dies, drops and is re-registered, the next invoice from “them” may come from someone else entirely. You cannot force a supplier to renew a domain. But you can check, in seconds, whether the domain on their last invoice still resolves and what mail routes it publishes. Check the domain free before you pay the next one.
The practical programme is short. Inventory your full domain estate. Classify each name as in-use or retired. Apply null MX, fail-all SPF and reject-mode DMARC to everything retired. Never let a domain that handled email lapse unmanaged. Publishing these records is the easy half; publishing them correctly is where estates fail. Over half of all published DMARC records (54.1%) are monitoring-only p=none — a policy that watches but does not block. So after you lock a retired domain down, verify it. And scan your live domains while you are there. The same records that silence a dead domain’s mail are the ones protecting your active ones.
Not sure where one of your domains stands? Check it free at defaults.exposed. The scan shows whether a domain resolves, what mail records it publishes to the world, and the grade its current configuration earns. It takes seconds, and it is the kind of check an attacker would run first. If the grade comes back ugly, the fix path is mapped for you, record by record. And if you would rather have the whole climb sequenced for you — exact record values, click-paths and re-checks included — that is what the A-Grade Playbook is for.
Quick answers
How many dead domains are on the internet? The defaults.exposed census counts 21 million dead domains as of 2026-07-29. That is 5.8% of the 360 million registered domains in its inventory. A dead domain is still registered but no longer resolves to a usable address.
What is a zombie MX domain? A zombie MX domain is a domain classified dead or unreachable in our census that still publishes MX records, so it may still receive email. The defaults.exposed census counts 43,723 of them as of 2026-07-29.
What is the difference between a dead domain and an unreachable domain? A dead domain no longer resolves to a usable address. An unreachable domain still resolves, but no service responds to contact. As of 2026-07-29, the census counts 21 million dead domains and 27 million unreachable ones.
What happens to email sent to an expired domain? Until the registration is deleted, published MX records can keep routing mail to wherever they point. Once the expired domain is re-registered, the new owner controls those routes. They can receive everything still sent to its old addresses.
How do I check if a domain is dead or still accepts email? Enter any domain at defaults.exposed for a free scan. It shows whether the name resolves, what MX, SPF and DMARC records it publishes, and the security grade its configuration earns. The scan uses the same current methodology (v8) as this report, applied to a single domain in seconds. Results reflect the domain at scan time, not the census snapshot.