Defaults.Exposed

Defaults.ExposedReports

The State of Domain Security 2026

Published · updated

Figures as of 2026-07-29 · methodology v8. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade. .com is fully graded (148M domains) and included in the totals below.

The headline: most of the internet fails basic domain security

We measured 296,674,837 live domains across 34 security checks — email authentication (SPF, DKIM, DMARC), TLS and certificates, web-security headers, and DNS (including DNSSEC). The result is stark:

This isn’t a story about a few neglected sites. It’s the default state of the internet: the protections that stop your email being forged and your visitors being misled are simply not switched on for the overwhelming majority of domains.

Grade distribution (297M domains)

GradeDomainsShare
A+65,2570.0%
A432,6680.1%
B5,525,0381.9%
C22,174,7897.5%
D49,493,12816.7%
F218,983,95773.8%

It varies a lot by country and TLD

Domain security varies widely by country and by domain ending. Established national registries — especially in Europe — tend to protect their businesses best, while cheap, high-volume generic endings popular for bulk registration do worst. But “best” is relative: even the strongest endings still leave most of their domains at an F.

These rankings shift as the census grows, so we keep them live rather than freezing them here:

What’s actually switched on, signal by signal

The grade is a roll-up. Underneath it, here is how often each individual protection is correctly in place across the population — the first census-wide baseline of its kind. Per-check figures as of 2026-07-28, across 276 million graded domains.

ProtectionWhat it stopsDomains that have it
SPF (email)Unauthorised servers sending as you51.25%
DKIM (email)Tampered / unsigned mail-29.50%
DMARC — any record25.81%
DMARC — actually enforcingEmail impersonation (the one that counts)11.84%
HTTPSUnencrypted, “Not Secure” browsing76.34%
HSTS (of HTTPS sites)Downgrade to HTTP19.12%
Content-Security-PolicyCross-site scripting / injection3.78%
Clickjacking protectionYour pages being framed5.66%
All security headers (“secure by default”)The full web-header set0.43%
DNSSEC — validDNS hijacking6.28%
CAAUnauthorised certificate issuance1.55%

Five findings worth quoting:

What this means for your business

A failing grade isn’t an abstract score. In plain terms it usually means one or more of these is true of your domain:

The encouraging part: most of these are free and quick to fix — usually a few lines in your domain’s settings. The barrier is almost never cost; it’s that nobody told the owner it mattered.

How we measured it

This edition adds the signal-by-signal baseline above — the share of domains that have each individual protection correctly in place, measured across the full graded population.

See where your own domain stands

These are averages. Your domain might be one of the 0.17% that earn an A — or one of the 73.8% that don’t. You can check it privately and free, and see exactly which of the 34 checks you pass and how to fix the ones you don’t.

Check your domain →