Defaults.Exposed › Research
Research
Original data on how the world's businesses protect their domains — from our ongoing census of 297 million+ graded domains. Free to read and cite. Data as of 2026-07-29.
Across every dataset below, 73.8% of domains score grade F — effectively unprotected against email spoofing. Only 2% reach a secure A–B grade.
- Domain Security by Country
We graded the business domains behind 111 countries' national domain endings. Here is how exposed each country is — to email spoofing and insecure websites — ranked from least to most exposed. - Domain Security by Industry
Using industry-specific domain endings as a proxy for sector, we ranked 15 industries by how exposed their domains are. The pattern holds across all of them. - The Most & Least Secure Domain Endings (TLDs)
Of the larger domain endings we grade, which protect their businesses best — and which leave them most exposed? Here are the extremes, from the 118 TLDs with enough graded domains to compare fairly. - Email Authentication: The Complete Guide (SPF, DKIM, DMARC and BIMI)
SPF, DKIM and DMARC are one system, not three projects. 51.25% of 276 million graded domains publish SPF, but only 11.84% enforce DMARC — the step that actually stops impersonation. The full stack, in order, with a verification gate at each stage. Data as of 2026-07-28. - DMARC vs SPF: What's the Difference, and Which Do You Need? (2026)
SPF lists which servers may send email for your domain. DMARC decides what happens when a message fails — and it's the only one that protects the 'From' address people actually see. 51.25% of domains publish SPF; just 11.84% enforce DMARC. What each does, why you need both, and in which order. Data as of 2026-07-28. - DMARC p=reject vs p=quarantine: Which Policy Should You Choose?
reject refuses forged mail outright; quarantine sends it to spam. Of the 11.84% of domains that enforce DMARC, the split is almost even — 6.43% quarantine, 5.41% reject. How to choose, the staged path up, and how to roll back safely. As of 2026-07-28. - SPF Failing With SaaS Tools in the UK or EU? The 10-Lookup Limit Explained (2026)
SPF fails silently when SaaS include: chains exceed 10 DNS lookups — a limit millions of UK and EU businesses have already crossed. 828,317 domains confirmed affected. Check yours free. - What Is BIMI? How Email Brand Logos Work — And Who Qualifies (2026)
BIMI shows your brand logo in email clients like Gmail and Apple Mail. It requires DMARC enforcement first — and only 11.84% of domains we've graded have reached that bar. Data as of 2026-07-28. - Which Email Provider Gives Its Customers the Strongest SPF Defaults? (2026)
84.9% of Microsoft 365 domains end SPF with strict -all; 7.6% of Google Workspace domains do — and no major mailbox provider's customers get past 30% enforced. Data as of 2026-07-28. - Can a Domain Have Two SPF Records? No — a Million Domains Just Voided Their Own (2026)
Two SPF records void both: 1,019,482 domains publish multiple v=spf1 records, which the standard treats as a permanent error. The copy-paste mistake that switches SPF off, measured across 276 million domains. Data as of 2026-07-28. - What Is the SPF ptr Mechanism — and Why Is It Still in 946,056 Records? (2026)
The SPF ptr mechanism was deprecated in 2014 — slow, unreliable, and a drain on the 10-lookup budget. 12 years later, 946,056 domains still publish it. Data as of 2026-07-28. - The SPF PermError Report: 133× More Domains Break the 10-Lookup Limit Than Surface Counts Show (2026)
SPF voids itself past 10 DNS lookups — and the breakage hides inside include: chains. At least 828,317 domains are over the limit. Data as of 2026-07-28. - The SPF Adoption Maturity Model (SPFAMM): The 6 Stages of SPF (2026)
The average domain sits at SPF stage 2.4 of 6. SPFAMM: the six-stage SPF maturity model — find your stage and the one move up. Data as of 2026-07-28. - SPF +all: The Domains That Let the Whole Internet Send As Them (2026)
36,262 domains end their SPF record with +all — explicit permission for anyone on Earth to send email as them. Where the welcome mats cluster, how they got there, and the one-character fix. Data as of 2026-07-28. - The Fully-Protected Few: the 2.79% Who Finished
Only 2.79% of domains — 7,678,989 — run the full enforced email stack: SPF, DKIM, DMARC at quarantine/reject. Just 0.30% hold all five protections. - The Email Spoofability Index: How Many Domains Can Anyone Forge? (2026)
9 in 10 domains can be forged: 88.2% of the internet publishes no policy telling receivers to reject or junk failed mail. The spoofability index, from a census of 276 million domains. Data as of 2026-07-28. - The 6 Stages of DMARC Maturity
25.81% of domains publish a DMARC record — only 11.84% enforce one. A six-stage maturity model, from Unprotected to Hardened, that explains where domains stall and the one move that advances each stage. - Publishing Blind: Most DMARC Records Ask for No Reports
Only 39.4% of the 71M domains publishing DMARC request reports (rua=). The rest are publishing blind — and one DNS edit fixes it. - SPF ~all vs -all: Softfail or Hardfail — What 141 Million Records Chose (2026)
SPF softfail vs hardfail: 55.9% of records end in ~all — and only 1 in 11 has the setting that gives softfail teeth. Data as of 2026-07-28. - SPF Is Not Enough: the 121 Million Domains That Never Enforce
121 million domains publish SPF but never enforce DMARC — 85.4% of everyone who set SPF up. Is SPF enough? Measured across the whole internet: no. Only 2.79% of domains are fully email-protected. The exposure, counted. As of 2026-07-28. - 'Your Connection Is Not Private' — What It Means and How to Fix It (2026)
The full-page 'your connection is not private' warning almost always means a certificate problem. Across domains serving HTTPS, 8.79% present an invalid certificate that triggers it. What the error codes mean and how to clear it. Data as of 2026-07-28. - What Is SPF — and How Do I Fix My SPF Record? (2026)
SPF tells the world which servers may send email for your domain. 51.25% of 276 million graded domains publish one — but a record alone isn't protection. The common mistakes, and how to fix yours. Data as of 2026-07-28. - What Is DNSSEC — and Do You Actually Need It? (2026)
DNSSEC signs your DNS so answers can't be forged in transit. Only 6.28% of 276 million graded domains have it — and a misconfigured signature can take you offline. What it protects, who needs it, and how to turn it on safely. Data as of 2026-07-28. - What Is DMARC? p=none, quarantine and reject Explained (2026)
DMARC is the record that decides whether forged email in your name gets delivered. Only 11.84% of 276 million graded domains set it to enforce — the rest either have none or a monitor-only policy that does nothing. What each policy means and how to set it. Data as of 2026-07-28. - Weak and Outdated TLS: Is Your Site Still Serving Old Encryption? (2026)
Good news: 94.84% of HTTPS sites now negotiate TLS 1.3. But 'weak TLS' hasn't vanished — it hides in servers that still accept old versions, weak ciphers, and broken certificates (8.79% invalid across 276 million graded domains). How to check you're not the exception. Data as of 2026-07-28. - My SSL Certificate Expired — Why It Happens and How to Fix It (2026)
An expired or invalid certificate throws a full-page browser warning that stops visitors cold. Across domains serving HTTPS, 8.79% present an invalid certificate. Why certificates fail and how to fix — and prevent — it. Data as of 2026-07-28. - Domain and DNS Hijacking: How Domains Get Stolen and How to Lock Yours Down (2026)
Hijacking redirects your visitors and email without touching your servers. The two DNS controls that stop it are barely used: 6.28% of 276 million graded domains have valid DNSSEC and 1.55% publish CAA. How domains are stolen and how to lock yours. Data as of 2026-07-28. - Cyber-Insurance and Vendor Security Questionnaires: What They Check on Your Domain (2026)
Insurers and enterprise buyers now ask whether you enforce DMARC, serve modern TLS, and lock down DNS. Across 276 million graded domains, only 2.79% are fully email-protected — so most can't honestly tick the boxes. What's asked and how the internet actually scores. Data as of 2026-07-28. - Why Does My Website Say 'Not Secure'? What the Warning Means for Trust (2026)
The 'Not Secure' label appears when a site isn't on valid HTTPS. Across 276 million domains, 23.66% serve no HTTPS at all, and 8.79% of those that do have an invalid certificate — so visitors see a browser warning. What it costs and how to fix it. Data as of 2026-07-28. - Why Are My Emails Going to Spam? The Authentication Gap, in Data (2026)
Most business email lands in spam for one fixable reason: missing authentication. Across 276 million domains, only 51.25% publish SPF, -29.50% use DKIM and 25.81% have any DMARC — the exact signals Gmail and Yahoo now require. Data as of 2026-07-28. - What Your Server Headers Tell Attackers: The Stack-Disclosure Report (2026)
69.0% of sites announce their web server in the response headers, and 8.3% reveal their app stack and version via X-Powered-By — including end-of-life software. What the web tells attackers for free, in census data. As of 2026-07-28. - The DNSSEC Paradox: More Domains Break It Than Get It Right (2026)
DNSSEC is meant to stop DNS hijacking — but across 276 million domains, more have it misconfigured and broken (0.09%) than working correctly (6.28%). The rest (93.63%) don't try at all. Why DNS is the internet's most-neglected security layer. Data as of 2026-07-28. - The State of IPv6 in 2026: Still Only 23.15% of Domains
A decade after 'IPv6 launch', just 23.15% of domains publish an AAAA record — the other 76.85% are IPv4-only. Adoption by country, from a 276-million-domain census. As of 2026-07-28. - Publishing SPF Isn't Enough: The False Sense of Email Security (2026)
30.9% of domains publish SPF but have no DMARC at all, and 43.8% have SPF without enforcement — they look protected and aren't. Only 2.79% are fully email-protected. The false-security gap, in census data. As of 2026-07-28. - The SPF Misconfiguration Report: Most SPF Records Are Set Too Weak (2026)
141 million domains publish SPF — but 55.9% use the weak '~all' softfail setting and only 39.2% use strict '-all'. Plus 36,262 domains use '+all', which authorises the entire internet to send as them. The misconfigurations hiding inside published SPF. Data as of 2026-07-28. - Who Runs the Internet's DNS? Nameserver Concentration in 2026
Five providers run 44.5% of the internet's DNS. GoDaddy alone hosts 18.5% and Cloudflare 14.7%. The systemic risk of DNS concentration, across 278 million domains. As of 2026-07-28. - The Misconfiguration Hall of Fame: The Web's Weirdest Security Records (2026)
375,840 sites serve a TLS certificate literally named "Internet Widgits Pty Ltd" — the placeholder nobody changed. DMARC policies written in the wrong language, SPF records that invite the whole internet in, and other gems from a 276-million-domain census. As of 2026-07-28. - The HTTP Security Header Report Card: How the Web Scores in 2026
Security headers are free, one-line defences against clickjacking, injection and snooping — and almost nobody sets them. Across 276 million domains, just 0.43% get every header right. CSP 3.78%, HSTS 19.12%, clickjacking protection 5.66%. Data as of 2026-07-28. - Are You Ready for Google & Yahoo's Email Sender Rules? (2026)
Google, Yahoo and Microsoft now require SPF, DKIM and DMARC to deliver bulk email. Yet only 51.25% of domains publish SPF, -29.50% DKIM, and 25.81% have any DMARC. Whether your domain meets the bar, in census data. As of 2026-07-28. - Half the PHP Web Runs End-of-Life PHP (2026)
Of the 13 million sites that reveal their PHP version, 42.2% run an end-of-life release that no longer gets security patches — and the single most common version is 7.4.33, dead since 2022. The unpatched PHP web, in census data. As of 2026-07-28. - Who Runs the World's Email? Email Hosting Market Share in 2026
Among 163 million domains with an identifiable mail host, 12.7% route mail through Google Workspace and 8.6% through Microsoft 365 — but the biggest category is self-hosted. Email hosting market share, as of 2026-07-28. - The Domain Exposure Score: Most Domains Have 1 of 5 Basic Protections (2026)
Scored across five core protections — SPF, enforced DMARC, DNSSEC, HTTPS and HSTS — the typical domain has just one or two. 8.5% have none at all; only 0.30% have all five. The exposure curve of 276 million domains, as of 2026-07-28. - Does NIS2 Require DMARC? Email Authentication and EU Cyber Hygiene (2026)
NIS2 doesn't name DMARC, but it requires cyber-hygiene measures — and email authentication is a baseline anti-spoofing control. Yet across the EU, even the best member state has only 29.59% of domains able to stop impersonation, and most sit far lower. Where EU domains actually stand, as of 2026-07-28. - Does Mandatory DNSSEC Work? What Registry-Driven Adoption Reveals (2026)
Where registries push DNSSEC, valid adoption runs ~7× higher — 35.8% on registry-driven endings vs 4.7% elsewhere (.se 65.25% vs .com 4.59%). But even the leaders break it more than they get it right. The data, as of 2026-07-28. - "quarentine", "ninguno", "non": The Internet's Most Common DMARC Typos (2026)
38,650 domains published a DMARC record with a misspelled or invalid policy — "quarentine", "ninguno", "non", or no policy at all — and get zero protection as a result. The typos that quietly break email security, from 71 million DMARC records. Data as of 2026-07-28. - You Set DMARC to p=none — Here's Why You're Still Exposed (2026)
A DMARC policy of p=none monitors but doesn't protect — your domain can still be impersonated. 13.96% of domains sit at p=none, more than the 11.84% that actually enforce. The false-security trap, in census data. As of 2026-07-28. - Expired, Self-Signed, Invalid: The Certificate Error Report (2026)
8.77% of the web's TLS certificates fail validation — 18,602,449 domains that present a certificate browsers won't trust. 3,306,642 are self-signed. The certificate errors that show visitors a warning, in census data. As of 2026-07-28. - Who Issues the Web's TLS Certificates? The Top Two CAs Now Own 71% (2026)
Across 212 million certificates, Let's Encrypt issues 52.6% and GoDaddy 18.6% — together 71.2% of the encrypted web runs on just two certificate authorities. The CA market, measured. As of 2026-07-28. - Can Someone Send Email Pretending to Be Your Business? For Most Domains, Yes (2026)
Only 11.84% of 276 million graded domains enforce DMARC — the one control that actually stops email impersonation. The other 88.16% can be spoofed. What that means for invoice fraud, and how to tell if you're protected. Data as of 2026-07-28. - Let's Dig Into WHOIS: The Best-Performing TLDs for Domain Security (2026)
Only 0.168% of graded domains earn an A or A+ — yet a handful of TLDs run about 8.2× that rate. We dig into which top-level domains have proportionally the most A and A+ domains, as of 2026-07-29. - Which Country's Businesses Are Most Spoofable? (2026)
China tops the list: 96.7% of its business domains are effectively unprotected against email spoofing. We ranked 69 countries by how forgeable their domains are. Data as of 2026-07-29. - The A-Grade Elite: What the Internet's Most Secure Domains Do Differently (2026)
Only 2.03% of 297 million domains earn a B or better, and just 0.17% reach an A — about 1 in 600. Here is exactly what the internet's most secure domains have in common, as of 2026-07-29. - The Internet's Dead Domains: How Many Domains No Longer Resolve? (2026)
Of 360 million domains we track, 21 million (5.8%) no longer resolve to anything. Here's what the internet's dead domains tell us — and the quiet security risk abandoned domains leave behind. Data as of 2026-07-29. - The Internet Security Grade Curve: What an Average Domain Looks Like in 2026
We graded 297 million domains A–F. The average domain scores a D or F — only 7.5% reach a C, and just 2.03% earn a B or better. Here is the full grade distribution of the internet, as of 2026-07-29. - New gTLDs vs Legacy Domains: Is .com Really Safer Than .xyz or .ai? (2026)
We compared the security of legacy endings (.com, .net, .org) against new gTLDs (.ai, .io, .xyz, .top) across millions of domains. The surprise: age doesn't predict safety — price and purpose do. Data as of 2026-07-29. - National vs Generic Domains: Are ccTLDs Like .de and .uk Safer Than .com? (2026)
We compared 111 national domain endings against 383 generic ones across 297 million domains. National (ccTLD) domains are measurably more secure: 61.5% score an F versus 77.6% on generic endings. Data as of 2026-07-29. - The National Domain Security Index 2026: How Countries Rank on Domain Security
We graded the business domains behind 111 countries' national endings. 61.5% score an F — and even the best-ranked country leaves most of its domains exposed. The full national ranking, updated live, as of 2026-07-29. - How We Graded the Entire Internet: The A–F Domain Security Methodology (2026)
How Defaults.Exposed grades 297 million domains from A+ to F across 34 externally observable security checks — what we measure, how the grade is calculated, and the limits of the data. Last updated 2026-07-29. - Europe vs the World: Domain Security in the GDPR Era (2026)
European businesses protect their domains better than the rest of the world: 54.6% of European national-domain businesses score an F, versus 70.3% elsewhere. But 'better' still means most domains are exposed. The data, as of 2026-07-29. - Emerging-Market Domains: The Security Gap in Fast-Growing ccTLDs (2026)
National domains in emerging markets score an F 70.6% of the time, against 58.0% in developed economies — an 12.5-point gap. But the spread inside the emerging group is far wider than the gap between groups. The data, as of 2026-07-29. - Domain Decay by TLD: Where Domains Go to Die (2026)
About 5.8% of all registered domains no longer resolve — but the rate varies wildly by ending. Cheap bulk endings like .xyz decay fastest; established national registries barely at all. The internet's domain mortality map, as of 2026-07-29. - The State of Domain Security 2026
We graded 297 million domains across 34 security checks. 73.8% score an F — only 11.84% enforce DMARC, 76.34% use HTTPS, and 0.43% get every security header right. The signal-by-signal state of the internet. - The Domain Security World Cup: who lifts the trophy if the safest domains win?
We took the real 2026 World Cup draw — all 12 groups, all 48 teams — and let one rule decide every match: the country whose business domains are least exposed wins. Bosnia are world champions, Germany finish bottom of their group, and the hosts go out at home.
Figures are recomputed from the census on every update; each report shows its data's as-of date and a growing edition history for trends. How we grade →