The State of Domain Security 2026
Published · updated
Figures as of 2026-07-29 · methodology v8. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade.
.comis fully graded (148M domains) and included in the totals below.
The headline: most of the internet fails basic domain security
We measured 296,674,837 live domains across 34 security checks — email authentication (SPF, DKIM, DMARC), TLS and certificates, web-security headers, and DNS (including DNSSEC). The result is stark:
- 73.8% score an F — the lowest grade.
- Fewer than 0.17% earn an A or A+ — roughly 1 in 600 domains.
- Only about 1 in 11 reach a C or better.
This isn’t a story about a few neglected sites. It’s the default state of the internet: the protections that stop your email being forged and your visitors being misled are simply not switched on for the overwhelming majority of domains.
Grade distribution (297M domains)
| Grade | Domains | Share |
|---|---|---|
| A+ | 65,257 | 0.0% |
| A | 432,668 | 0.1% |
| B | 5,525,038 | 1.9% |
| C | 22,174,789 | 7.5% |
| D | 49,493,128 | 16.7% |
| F | 218,983,957 | 73.8% |
It varies a lot by country and TLD
Domain security varies widely by country and by domain ending. Established national registries — especially in Europe — tend to protect their businesses best, while cheap, high-volume generic endings popular for bulk registration do worst. But “best” is relative: even the strongest endings still leave most of their domains at an F.
These rankings shift as the census grows, so we keep them live rather than freezing them here:
What’s actually switched on, signal by signal
The grade is a roll-up. Underneath it, here is how often each individual protection is correctly in place across the population — the first census-wide baseline of its kind. Per-check figures as of 2026-07-28, across 276 million graded domains.
| Protection | What it stops | Domains that have it |
|---|---|---|
| SPF (email) | Unauthorised servers sending as you | 51.25% |
| DKIM (email) | Tampered / unsigned mail | -29.50% |
| DMARC — any record | — | 25.81% |
| DMARC — actually enforcing | Email impersonation (the one that counts) | 11.84% |
| HTTPS | Unencrypted, “Not Secure” browsing | 76.34% |
| HSTS (of HTTPS sites) | Downgrade to HTTP | 19.12% |
| Content-Security-Policy | Cross-site scripting / injection | 3.78% |
| Clickjacking protection | Your pages being framed | 5.66% |
| All security headers (“secure by default”) | The full web-header set | 0.43% |
| DNSSEC — valid | DNS hijacking | 6.28% |
| CAA | Unauthorised certificate issuance | 1.55% |
Five findings worth quoting:
- Only 11.84% of domains enforce DMARC — so roughly 88.16% can be impersonated in email, even though 51.25% have published SPF and think they’re covered.
- 76.34% serve HTTPS, but only 0.43% set every security header — encryption is mainstream; everything above it is not.
- 8.79% of HTTPS sites have an invalid certificate — expired, self-signed or for the wrong name — so visitors get a warning anyway.
- More domains have broken DNSSEC (0.09%) than working DNSSEC (6.28%) — the control meant to protect DNS more often takes domains offline than secures them.
- Just 1.55% set a CAA record — DNS is the internet’s most-neglected security layer.
What this means for your business
A failing grade isn’t an abstract score. In plain terms it usually means one or more of these is true of your domain:
- Your email can be forged. Without enforced SPF and DMARC, a criminal can send email that looks exactly like it came from you — to your customers, staff and suppliers — and it lands in the inbox. That’s how fake-invoice and CEO-fraud scams work.
- Your real email is more likely to be junked. Google and Yahoo increasingly distrust unauthenticated domains, so your genuine quotes and invoices quietly land in spam.
- You’ll fail other people’s security checks. Bigger customers run a quick scan before they sign. “Domain not protected — can be spoofed” is enough to lose the deal.
- Your site can warn visitors away. A missing or broken certificate shows shoppers a red “Not secure” page.
The encouraging part: most of these are free and quick to fix — usually a few lines in your domain’s settings. The barrier is almost never cost; it’s that nobody told the owner it mattered.
How we measured it
- 34 checks, externally observable — no access to anyone’s systems required. (Full methodology.)
- Pass / fail / N/A. Where a check genuinely can’t be determined it’s marked N/A and excluded — it never counts as a failure.
- A real failure is a real failure. A domain with no SPF/DMARC scores poorly because it can genuinely be spoofed — not because of how we counted.
- Aggregate only. These are population patterns; an individual domain’s grade is shown only to its verified owner.
- Data is stored and processed within the EU.
This edition adds the signal-by-signal baseline above — the share of domains that have each individual protection correctly in place, measured across the full graded population.
See where your own domain stands
These are averages. Your domain might be one of the 0.17% that earn an A — or one of the 73.8% that don’t. You can check it privately and free, and see exactly which of the 34 checks you pass and how to fix the ones you don’t.