Defaults.Exposed

Defaults.ExposedBy TLD › .ninja

Is .ninja safe? The state of .ninja domain security

.ninja is riskier than the internet average. Across 20,135 graded .ninja domains, 78.3% score an F — worse than the 73.8% global average — heavier on exposed domains than the web as a whole. 2.7% earn a B or better. Most .ninja domains can still be impersonated in email, but the ending shifts the odds, not your own domain's grade. As of 2026-07-29.

How do .ninja domains score?

Aggregate grade distribution across all graded .ninja domains — we never publish an individual business's grade. As of 2026-07-29.

GradeDomainsShare
A+220.1%
A940.5%
B4232.1%
C1,2786.3%
D2,55212.7%
F15,76678.3%

Does .ninja make a domain secure?

No — and that's the most important thing to know. A domain's grade is decided by how it is configured (SPF, DMARC, HTTPS, DNS), not by its ending. Choosing .ninja doesn't protect you, and a high-F-share ending doesn't doom you: a correctly configured .ninja domain earns an A while the crowd around it sits at F.

Want to know where your .ninja domain ranks? Check it privately and free — we only ever show an individual domain's grade to its verified owner. Run the free check →

Frequently asked questions

Is .ninja safe?

On average, .ninja is riskier than the internet average: 78.3% of its 20,135 graded domains score an F as of 2026-07-29, against a 73.8% global average. Most domains on every ending are exposed — the ending shifts the odds, not your own domain's grade.

How secure are .ninja domains?

21.7% of .ninja domains score above an F and 2.7% earn a B or better. The rest fail the basic externally observable protections, most importantly enforced SPF and DMARC, so they can be impersonated in email.

Does choosing .ninja make my domain secure?

No. A domain's grade comes from how it is configured — SPF, DMARC, HTTPS, DNS — not from its ending. A well-configured domain earns an A on any ending; an unconfigured one sits at F on .ninja too.

What does "grade F" mean for a .ninja domain?

It fails the basic protections we can observe from outside — above all, it has no enforced SPF and DMARC, so its email can be forged and its customers targeted with convincing fakes.

By TLD: .bot · .trade · .day · .paris · .zip · .wine · Rankings

Most & least secure TLDs → · Check your domain → · How we grade →