Defaults.Exposed

Defaults.Exposed › September 2026 census › v10 registry

Methodology v10: the 33-check registry

Methodology v10 · 33 checks (24 scored + 9 informational) · census as of September 5, 2026

This is the versioned, citable registry of every check in the Defaults.Exposed grading methodology. Each check has a permanent canonical ID and a stable URL, cite /methodology/<check-id> and it will keep meaning the same thing. Prevalence figures are computed from the census of 316,600,902 graded domains in the September 2026 edition and are pinned to it; the check definitions are frozen for v10.

A note on version numbers: v10 is the label of this census edition. The scan engine itself reports its methodology version as v9, because the checks, thresholds and grade bands have not changed since the v9 edition: the same 33 checks and the same rubric. So a live scan and this edition grade against an identical ruleset; only the census the prevalence figures are drawn from has moved on. A change to any definition would ship as a new engine version first.

Machine-readable: /methodology/checks.json · Headline statistics: census data and downloads · Every acronym spelled out: the domain security glossary · Licence: open data · The edition these figures come from: September 2026 census →

How checks become a grade

24 of the 33 checks carry points; 9 are informational and never move the grade. Every check returns pass, fail, or N/A. Under the no-data rule, when a check couldn't be determined (timeout, SERVFAIL, redacted source) it is excluded from that domain's scoring denominator rather than counted as a failure. "Determined absent" (no DMARC record, no HTTPS) is a real fail. Grade bands are locked for comparability: A+ ≥ 95% · A ≥ 90% · B ≥ 80% · C ≥ 70% · D ≥ 60% · F below 60%.

Email Security

Canonical ID Check Grade impact Census prevalence Fix guide
spf-exists SPF (Sender Policy Framework) record Scored 46.4% of graded domains publish an SPF record that ends in an all mechanism (-all, ~all, ?all or +all) How to fix SPF
spf-policy-strength SPF policy strength Scored 18.2% of graded domains publish SPF with a hardfail (-all) policy How to fix SPF
dmarc-policy DMARC (Domain-based Message Authentication, Reporting and Conformance) policy Scored 11.6% of graded domains publish an enforcing DMARC policy (p=quarantine or p=reject) How to fix DMARC
dmarc-reporting DMARC reporting Scored 9.80% of graded domains publish a DMARC record with an aggregate-reporting (rua) address How to fix DMARC
dkim-exists DKIM (DomainKeys Identified Mail) Scored 50.1% of domains where a DKIM selector could be determined publish one How to fix DKIM
mx-record MX (Mail Exchange) records Scored 54.7% of graded domains publish at least one MX record How to fix MX records
reverse-dns Reverse DNS (Domain Name System, PTR, Pointer) Scored 77.8% of domains with a mail-relevant address have a PTR (reverse DNS) record How to fix Reverse DNS

TLS & Certificates

Canonical ID Check Grade impact Census prevalence Fix guide
https-available HTTPS (Hypertext Transfer Protocol Secure) available Scored 67.0% of graded domains serve over HTTPS How to fix HTTPS & forced-secure redirect
cert-valid Certificate valid Scored 89.1% of HTTPS-serving domains present a valid, trusted certificate How to fix TLS certificate health
cert-expiry-warning Certificate expiry Scored 95.4% of domains whose certificate expiry date could be read present a certificate that is neither expired nor about to expire How to fix TLS certificate health
cert-signature-algorithm Signature algorithm Scored 99.7% of domains whose certificate signature algorithm could be read are signed with a modern algorithm (SHA-256 family or better) How to fix TLS certificate health
cert-key-strength Key strength Scored 99.9% of domains whose certificate key could be read meet the modern key-strength baseline How to fix TLS certificate health
tls-version TLS (Transport Layer Security) version Scored 100.0% of HTTPS-serving domains negotiate TLS 1.2 or 1.3 How to fix Modern encryption
cipher-strength Cipher strength Scored not published per-check in the census rollup How to fix Modern encryption
tls-compression TLS compression Informational not measured by the census; defined here and in checks.json only How to fix Modern encryption
ocsp-stapling OCSP (Online Certificate Status Protocol) stapling Informational not measured by the census; defined here and in checks.json only How to fix Modern encryption
secure-renegotiation Secure renegotiation Informational not measured by the census; defined here and in checks.json only How to fix Modern encryption

Web Security

Canonical ID Check Grade impact Census prevalence Fix guide
hsts-header HSTS (HTTP Strict Transport Security) Scored 21.1% of HTTPS-serving domains send an HSTS header How to fix HSTS
http-to-https-redirect HTTP (Hypertext Transfer Protocol)→HTTPS redirect Scored 51.2% of domains whose HTTP redirect behaviour could be observed redirect plain-HTTP requests to HTTPS How to fix HTTPS & forced-secure redirect
csp-header Content-Security-Policy Scored 2.49% of domains that sent a Server, Content-Security-Policy or X-Powered-By header carry a Content-Security-Policy that constrains script (a default-src or script-src directive) How to fix Content-Security-Policy
x-frame-options Clickjacking protection Scored 15.3% of domains whose page returned a 2xx response send clickjacking protection (X-Frame-Options or CSP frame-ancestors) How to fix Clickjacking protection
x-content-type-options MIME-sniffing protection Scored 17.8% of domains whose page returned a 2xx response send X-Content-Type-Options: nosniff How to fix MIME-sniffing protection
referrer-policy Referrer-Policy Scored 7.91% of domains whose page returned a 2xx response send a Referrer-Policy header How to fix Referrer-Policy
coop-header COOP (Cross-Origin-Opener-Policy) Informational not measured by the census; defined here and in checks.json only How to fix Cross-origin isolation headers
corp-header CORP (Cross-Origin-Resource-Policy) Informational not measured by the census; defined here and in checks.json only How to fix Cross-origin isolation headers
coep-header COEP (Cross-Origin-Embedder-Policy) Informational not measured by the census; defined here and in checks.json only How to fix Cross-origin isolation headers

DNS Security

Canonical ID Check Grade impact Census prevalence Fix guide
caa-record CAA (Certification Authority Authorization) records Scored 1.38% of domains where the CAA lookup returned a determinate answer publish a CAA record How to fix CAA records
dnssec DNSSEC (Domain Name System Security Extensions) Scored 6.86% of graded domains have a valid, fully validating DNSSEC chain How to fix DNSSEC
nameserver-diversity Nameserver diversity Scored 99.0% of domains whose nameserver delegation could be enumerated delegate to two or more nameservers How to fix Nameserver setup
soa-configuration SOA (Start of Authority) configuration Scored 99.0% of domains whose SOA record could be read publish a sane SOA record How to fix Nameserver setup

Infrastructure

Canonical ID Check Grade impact Census prevalence Fix guide
ipv6-support IPv6 support Informational 21.8% of graded domains publish an AAAA (IPv6 address, IPv6) record How to fix IPv6 support
cdn-waf-detection CDN (Content Delivery Network) / WAF (Web Application Firewall) detection Informational not measured by the census; defined here and in checks.json only How to fix CDN / WAF & hosting
hosting-provider Hosting provider Informational not measured by the census; defined here and in checks.json only How to fix CDN / WAF & hosting

Cite this registry

Check definitions are stable for methodology v10 and the prevalence figures are pinned to the September 2026 census. Please cite Defaults.Exposed and link the check's stable URL.

Defaults.Exposed, "Grading Methodology v10" (census as of September 5, 2026). https://defaults.exposed/methodology

Permalink: https://defaults.exposed/methodology · Machine-readable: /methodology/checks.json · Per-check anchors: https://defaults.exposed/methodology/<check-id>

Prevalence numbers are aggregates across the whole census, never a named third party's result. These are the September 2026 figures; the next census replaces them on this same page.

Headline statistics: cite the dataset DOI, not this page; see how to cite the census or the census data page. This page defines HOW a check is scored; it is not the citable source for a prevalence figure.