Is .com safer than .net or .org? The measured answer with the denominator stated
If you’re asking “is .com or .net safer”, the September 2026 census has a measured answer. Of the legacy three, .com carries the lowest share of grade F domains at 74.2%, .org sits at 76.9%, and .net carries the highest at 80.5%. Each share is measured against that ending’s graded plus dead domains, and the graded counts behind them are 151,114,731 for .com, 10,995,426 for .net and 11,087,980 for .org. So on this edition .com wins the comparison, and the rest of this page explains why that result shouldn’t change which ending you register.
The three numbers, with the denominator beside them
Grade F on defaults.exposed means a domain has done close to nothing. Its email authentication isn’t at enforcement and its DNS isn’t signed; the web surface, where there is one, is unprotected. The F share is the cleanest single comparable between endings, because it asks the same question of each domain and lower is better.
| Ending | Domains graded | F share (of graded plus dead) |
|---|---|---|
| .com | 151,114,731 | 74.2% |
| .org | 11,087,980 | 76.9% |
| .net | 10,995,426 | 80.5% |
The graded column is there because a percentage means little until you know how many domains stand behind it. Anyone can tell you an ending is “safer”; the census can tell you how many domains it looked at before saying so. The three shares describe three very different populations, and the gap between them is narrow next to what you’d find by picking two endings at random from the ones the census scanned.
One thing the table can’t tell you is anything about a single domain. An ending’s F share is a description of its owners in aggregate. Your domain is one row in that aggregate, and it can sit anywhere on the curve.
The ranking is a fact about buyers
The records published under a domain set its grade. The registry agreement for .com, .net or .org says nothing about which of those records you can publish; all of them are free and available on any ending. So when three endings run on identical rules and land on different F shares, the difference has to come from the people registering them.
That’s what the data shows across the wider census. Premium technical endings bought by developers and infrastructure teams grade better; those buyers tend to configure DNS and email as a matter of habit. At the other end sit the cheap, bulk-registered endings where most domains are parked or thrown away, and since almost nobody configures a domain they’ve forgotten about, those grade worst. The legacy three are a mix of everyone, from serious businesses to abandoned registrations, and they land in the middle of the range.
Which puts .net’s 80.5% in context: the owners of .net domains, taken together, have published fewer records than the owners of .com domains, and that’s the whole of what the number measures. Swap the two populations and the shares would swap with them, because the ending itself had nothing to do with either result.
Scale drags .com toward the average
Across all 316,600,902 graded plus dead domains in the census, 234,955,475 carry grade F, which is 74.2%. Read that beside .com’s own 74.2% and you can see what scale does. An ending of that size is the average. Its owners are so numerous and so varied that the ending’s curve resolves toward whatever the median owner did, and the median owner of a domain on the registered internet did nothing.
That’s also why .com can’t pull far ahead of the internet as a whole. Any push that improved its share would have to move an enormous number of individual owners, and no registry runs a lever that big. Smaller endings can move; .com is the baseline that everything else gets measured against.
How far a country ending can move
If you want to see how far an ending’s curve can move, look outside the legacy three. On the same basis, .nl has 3,748,769 graded domains and an F share of 39.8%. That’s a country ending whose registry has spent years pushing DNS signing and sensible defaults through its registrars, and the whole distribution shifted with it.
Put .nl’s 39.8% next to .net’s 80.5% and the differences inside the legacy three look like what they are: three samples from the same broad population, sold at similar prices to much the same people. The difference between a legacy ending and .nl is what a registry with a policy can do to an ending’s curve over a decade.
That’s still no argument for registering a .nl. The records that lifted .nl’s curve are available to you today on whichever ending you already hold, and publishing them is a decision you make once, at the DNS console, for the domain you have. The registry did the persuading in .nl’s case. On .com, .net or .org, you do it yourself, and it takes an afternoon.
How to read any ending comparison you’re shown
Registrars and hosting blogs will keep telling you one ending is safer than another. A claim like that needs to survive a few questions before you act on it.
The first is what “safer” means. It has to be something measurable, share of domains at grade F or share with DMARC at enforcement, and if the claim doesn’t say which, it’s telling you what someone likes.
The second is the denominator. An F share for an ending with a few thousand registrations moves when a few dozen owners change a record, which is why the graded count sits beside each figure on this page.
Then there’s the edition. Census numbers move every month as domains lapse and new owners configure them, so if there’s no date on the figure you’ve no way to check it.
Last, the mechanism. If someone says .com is safer, ask what a .com can publish that a .net can’t. The answer is nothing, so whatever the comparison is measuring, it’s the people who bought each ending.
What sets a grade on any ending
The grade for a domain is the sum of what’s published under it. The census reads the same records for a .com as for a .net, and the scanner on this site reads the same ones for yours.
- SPF, DKIM and DMARC, with DMARC at enforcement, meaning
p=quarantineorp=reject. Ap=nonerecord monitors and blocks nothing; the DMARC guide explains why that one token is the whole difference. - A valid, current certificate on a modern TLS version, with HSTS so browsers stop trying plain HTTP at all.
- DNSSEC, so a resolver can tell a forged answer from a real one, and CAA, so only the authority you chose can issue a certificate for your name. Both live in DNS, and the DNS guide shows what each record looks like when it’s right.
- The HTTP security headers: a content security policy, clickjacking protection,
X-Content-Type-Options: nosniffand a referrer policy.
Nothing on that list costs money, and none of it depends on which ending you hold. A .net with all of it published outgrades a .com with none of it, and the census holds plenty of both.
The domain you own beats the ending you’re choosing
Which ending grades better is arguable for as long as you like, because it depends on the population you pick and the edition you read. Whether your own domain can be spoofed is knowable in seconds, and the answer is specific to you. The scan reads the records under the name you type in and tells you which line to add or change to move the grade.
If you’ve been told an ending is safer and want to test the claim against something concrete, start with can someone spoof my domain: it shows what a missing enforcement policy lets an attacker do with your name, regardless of what comes after the dot. Then run the free scan on the domain you already hold. A grade A is reachable on .com, on .net and on .org, and the route to it is the same list of free records on all three.
Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Census numbers move every month; the current values are on the census data page.