Defaults.Exposed › September 2026 census › v10 registry
Methodology v10: the 33-check registry
Methodology v10 · 33 checks (24 scored + 9 informational) · census as of September 5, 2026
This is the versioned, citable registry of every check in the Defaults.Exposed grading methodology.
Each check has a permanent canonical ID and a stable URL, cite /methodology/<check-id>
and it will keep meaning the same thing. Prevalence figures are computed from the census of
316,600,902 graded domains in the September 2026 edition and are
pinned to it; the check definitions are frozen for v10.
A note on version numbers: v10 is the label of this census
edition. The scan engine itself reports its methodology version as v9, because
the checks, thresholds and grade bands have not changed since the v9 edition: the same 33 checks and
the same rubric. So a live scan and this edition grade against an identical ruleset; only the census the
prevalence figures are drawn from has moved on. A change to any definition would ship as a new engine
version first.
Machine-readable: /methodology/checks.json ·
Headline statistics: census data and downloads ·
Every acronym spelled out: the domain security glossary ·
Licence: open data ·
The edition these figures come from: September 2026 census →
How checks become a grade
24 of the 33 checks carry points; 9 are informational and never move the grade. Every check returns pass, fail, or N/A. Under the no-data rule, when a check couldn't be determined (timeout, SERVFAIL, redacted source) it is excluded from that domain's scoring denominator rather than counted as a failure. "Determined absent" (no DMARC record, no HTTPS) is a real fail. Grade bands are locked for comparability: A+ ≥ 95% · A ≥ 90% · B ≥ 80% · C ≥ 70% · D ≥ 60% · F below 60%.
Email Security
| Canonical ID | Check | Grade impact | Census prevalence | Fix guide |
|---|---|---|---|---|
spf-exists | SPF (Sender Policy Framework) record | Scored | 46.4% of graded domains publish an SPF record that ends in an all mechanism (-all, ~all, ?all or +all) | How to fix SPF |
spf-policy-strength | SPF policy strength | Scored | 18.2% of graded domains publish SPF with a hardfail (-all) policy | How to fix SPF |
dmarc-policy | DMARC (Domain-based Message Authentication, Reporting and Conformance) policy | Scored | 11.6% of graded domains publish an enforcing DMARC policy (p=quarantine or p=reject) | How to fix DMARC |
dmarc-reporting | DMARC reporting | Scored | 9.80% of graded domains publish a DMARC record with an aggregate-reporting (rua) address | How to fix DMARC |
dkim-exists | DKIM (DomainKeys Identified Mail) | Scored | 50.1% of domains where a DKIM selector could be determined publish one | How to fix DKIM |
mx-record | MX (Mail Exchange) records | Scored | 54.7% of graded domains publish at least one MX record | How to fix MX records |
reverse-dns | Reverse DNS (Domain Name System, PTR, Pointer) | Scored | 77.8% of domains with a mail-relevant address have a PTR (reverse DNS) record | How to fix Reverse DNS |
TLS & Certificates
| Canonical ID | Check | Grade impact | Census prevalence | Fix guide |
|---|---|---|---|---|
https-available | HTTPS (Hypertext Transfer Protocol Secure) available | Scored | 67.0% of graded domains serve over HTTPS | How to fix HTTPS & forced-secure redirect |
cert-valid | Certificate valid | Scored | 89.1% of HTTPS-serving domains present a valid, trusted certificate | How to fix TLS certificate health |
cert-expiry-warning | Certificate expiry | Scored | 95.4% of domains whose certificate expiry date could be read present a certificate that is neither expired nor about to expire | How to fix TLS certificate health |
cert-signature-algorithm | Signature algorithm | Scored | 99.7% of domains whose certificate signature algorithm could be read are signed with a modern algorithm (SHA-256 family or better) | How to fix TLS certificate health |
cert-key-strength | Key strength | Scored | 99.9% of domains whose certificate key could be read meet the modern key-strength baseline | How to fix TLS certificate health |
tls-version | TLS (Transport Layer Security) version | Scored | 100.0% of HTTPS-serving domains negotiate TLS 1.2 or 1.3 | How to fix Modern encryption |
cipher-strength | Cipher strength | Scored | not published per-check in the census rollup | How to fix Modern encryption |
tls-compression | TLS compression | Informational | not measured by the census; defined here and in checks.json only | How to fix Modern encryption |
ocsp-stapling | OCSP (Online Certificate Status Protocol) stapling | Informational | not measured by the census; defined here and in checks.json only | How to fix Modern encryption |
secure-renegotiation | Secure renegotiation | Informational | not measured by the census; defined here and in checks.json only | How to fix Modern encryption |
Web Security
| Canonical ID | Check | Grade impact | Census prevalence | Fix guide |
|---|---|---|---|---|
hsts-header | HSTS (HTTP Strict Transport Security) | Scored | 21.1% of HTTPS-serving domains send an HSTS header | How to fix HSTS |
http-to-https-redirect | HTTP (Hypertext Transfer Protocol)→HTTPS redirect | Scored | 51.2% of domains whose HTTP redirect behaviour could be observed redirect plain-HTTP requests to HTTPS | How to fix HTTPS & forced-secure redirect |
csp-header | Content-Security-Policy | Scored | 2.49% of domains that sent a Server, Content-Security-Policy or X-Powered-By header carry a Content-Security-Policy that constrains script (a default-src or script-src directive) | How to fix Content-Security-Policy |
x-frame-options | Clickjacking protection | Scored | 15.3% of domains whose page returned a 2xx response send clickjacking protection (X-Frame-Options or CSP frame-ancestors) | How to fix Clickjacking protection |
x-content-type-options | MIME-sniffing protection | Scored | 17.8% of domains whose page returned a 2xx response send X-Content-Type-Options: nosniff | How to fix MIME-sniffing protection |
referrer-policy | Referrer-Policy | Scored | 7.91% of domains whose page returned a 2xx response send a Referrer-Policy header | How to fix Referrer-Policy |
coop-header | COOP (Cross-Origin-Opener-Policy) | Informational | not measured by the census; defined here and in checks.json only | How to fix Cross-origin isolation headers |
corp-header | CORP (Cross-Origin-Resource-Policy) | Informational | not measured by the census; defined here and in checks.json only | How to fix Cross-origin isolation headers |
coep-header | COEP (Cross-Origin-Embedder-Policy) | Informational | not measured by the census; defined here and in checks.json only | How to fix Cross-origin isolation headers |
DNS Security
| Canonical ID | Check | Grade impact | Census prevalence | Fix guide |
|---|---|---|---|---|
caa-record | CAA (Certification Authority Authorization) records | Scored | 1.38% of domains where the CAA lookup returned a determinate answer publish a CAA record | How to fix CAA records |
dnssec | DNSSEC (Domain Name System Security Extensions) | Scored | 6.86% of graded domains have a valid, fully validating DNSSEC chain | How to fix DNSSEC |
nameserver-diversity | Nameserver diversity | Scored | 99.0% of domains whose nameserver delegation could be enumerated delegate to two or more nameservers | How to fix Nameserver setup |
soa-configuration | SOA (Start of Authority) configuration | Scored | 99.0% of domains whose SOA record could be read publish a sane SOA record | How to fix Nameserver setup |
Infrastructure
| Canonical ID | Check | Grade impact | Census prevalence | Fix guide |
|---|---|---|---|---|
ipv6-support | IPv6 support | Informational | 21.8% of graded domains publish an AAAA (IPv6 address, IPv6) record | How to fix IPv6 support |
cdn-waf-detection | CDN (Content Delivery Network) / WAF (Web Application Firewall) detection | Informational | not measured by the census; defined here and in checks.json only | How to fix CDN / WAF & hosting |
hosting-provider | Hosting provider | Informational | not measured by the census; defined here and in checks.json only | How to fix CDN / WAF & hosting |
Cite this registry
Check definitions are stable for methodology v10 and the prevalence figures are pinned to the September 2026 census. Please cite Defaults.Exposed and link the check's stable URL.
Defaults.Exposed, "Grading Methodology v10" (census as of September 5, 2026). https://defaults.exposed/methodology
Permalink: https://defaults.exposed/methodology ·
Machine-readable: /methodology/checks.json ·
Per-check anchors: https://defaults.exposed/methodology/<check-id>
Prevalence numbers are aggregates across the whole census, never a named third party's result. These are the September 2026 figures; the next census replaces them on this same page.
Headline statistics: cite the dataset DOI, not this page; see how to cite the census or the census data page. This page defines HOW a check is scored; it is not the citable source for a prevalence figure.