Defaults.Exposed

Defaults.ExposedMethodology › v7 registry

Methodology v7 — the 34-check registry

Methodology v7 · 34 checks (25 scored + 9 informational) · census as of July 28, 2026

This is the versioned, citable registry of every check in the Defaults.Exposed grading methodology. Each check has a permanent canonical ID and a stable URL — cite /methodology/v7/<check-id> and it will keep meaning the same thing. Prevalence figures are computed from the census of 275,666,275 graded domains and refresh with each census; the check definitions themselves are frozen for v7.

Machine-readable: checks.json · Human explainer: how we grade the internet · Headline statistics: /data · Licence: open data

How checks become a grade

25 of the 34 checks carry points; 9 are informational and never move the grade. Every check returns pass, fail, or N/A — the no-data rule: when a check couldn't be determined (timeout, SERVFAIL, redacted source) it is excluded from that domain's scoring denominator rather than counted as a failure. "Determined absent" (no DMARC record, no HTTPS) is a real fail. Grade bands are locked for comparability: A+ ≥ 95% · A ≥ 90% · B ≥ 80% · C ≥ 70% · D ≥ 60% · F below 60%.

Email Security

Canonical ID Check Grade impact Census prevalence (as of July 28, 2026) Fix guide
spf-exists SPF record Scored 50.3% of graded domains publish a syntactically valid SPF record /fix/spf
spf-policy-strength SPF policy strength Scored 20.1% of graded domains publish SPF with a hardfail (-all) policy /fix/spf
dmarc-policy DMARC policy Scored 11.8% of graded domains publish an enforcing DMARC policy (p=quarantine or p=reject) /fix/dmarc
dmarc-reporting DMARC reporting Scored 10.2% of graded domains publish a DMARC record with an aggregate-reporting (rua) address /fix/dmarc
dkim-exists DKIM Scored 51.2% of graded domains have a discoverable DKIM selector /fix/dkim
mx-record MX records Scored 99.9% of graded domains publish at least one MX record /fix/mx
reverse-dns Reverse DNS (PTR) Scored 76.3% of graded domains have a PTR (reverse DNS) record /fix/reverse-dns

TLS & Certificates

Canonical ID Check Grade impact Census prevalence (as of July 28, 2026) Fix guide
https-available HTTPS available Scored 76.3% of graded domains serve over HTTPS /fix/https
cert-valid Certificate valid Scored 91.2% of HTTPS-serving domains present a valid, trusted certificate /fix/certificate
cert-expiry-warning Certificate expiry Scored not published per-check in the census rollup /fix/certificate
cert-signature-algorithm Signature algorithm Scored not published per-check in the census rollup /fix/certificate
cert-key-strength Key strength Scored not published per-check in the census rollup /fix/certificate
tls-version TLS version Scored 100.0% of HTTPS-serving domains negotiate TLS 1.2 or 1.3 /fix/tls
cipher-strength Cipher strength Scored not published per-check in the census rollup /fix/tls
tls-compression TLS compression Informational not published per-check in the census rollup /fix/tls
ocsp-stapling OCSP stapling Informational not published per-check in the census rollup /fix/tls
secure-renegotiation Secure renegotiation Informational not published per-check in the census rollup /fix/tls

Web Security

Canonical ID Check Grade impact Census prevalence (as of July 28, 2026) Fix guide
hsts-header HSTS Scored 19.1% of HTTPS-serving domains send an HSTS header /fix/hsts
http-to-https-redirect HTTP→HTTPS redirect Scored not published per-check in the census rollup /fix/https
csp-header Content-Security-Policy Scored 3.78% of graded domains send an effective Content-Security-Policy header /fix/csp
x-frame-options Clickjacking protection Scored 5.66% of graded domains send clickjacking protection (X-Frame-Options or CSP frame-ancestors) /fix/clickjacking
x-content-type-options MIME-sniffing protection Scored 7.28% of graded domains send X-Content-Type-Options: nosniff /fix/mime-sniffing
referrer-policy Referrer-Policy Scored 2.99% of graded domains send a Referrer-Policy header /fix/referrer-policy
coop-header COOP (Cross-Origin-Opener-Policy) Informational 1.05% of graded domains send a Cross-Origin-Opener-Policy header /fix/cross-origin-headers
corp-header CORP (Cross-Origin-Resource-Policy) Informational 0.89% of graded domains send a Cross-Origin-Resource-Policy header /fix/cross-origin-headers
coep-header COEP (Cross-Origin-Embedder-Policy) Informational 0.68% of graded domains send a Cross-Origin-Embedder-Policy header /fix/cross-origin-headers

DNS Security

Canonical ID Check Grade impact Census prevalence (as of July 28, 2026) Fix guide
caa-record CAA records Scored 1.54% of graded domains publish a CAA record /fix/caa
dnssec-ds DNSSEC (DS) Scored 6.28% of graded domains have a valid, fully validating DNSSEC chain /fix/dnssec
dnssec-dnskey DNSSEC (DNSKEY) Scored 6.28% of graded domains have a valid, fully validating DNSSEC chain /fix/dnssec
nameserver-diversity Nameserver diversity Scored not published per-check in the census rollup /fix/nameservers
soa-configuration SOA configuration Scored not published per-check in the census rollup /fix/nameservers
ipv6-support IPv6 support Informational 23.1% of graded domains publish an AAAA (IPv6) record /fix/ipv6

Infrastructure

Canonical ID Check Grade impact Census prevalence (as of July 28, 2026) Fix guide
cdn-waf-detection CDN / WAF detection Informational not published per-check in the census rollup /fix/infrastructure
hosting-provider Hosting provider Informational not published per-check in the census rollup /fix/infrastructure

Cite this registry

Check definitions are stable for methodology v7; prevalence figures are dated per census. Please cite Defaults.Exposed and link the check's stable URL.

Defaults.Exposed, "Grading Methodology v7" (census as of July 28, 2026). https://defaults.exposed/methodology/v7

Permalink: https://defaults.exposed/methodology/v7 · Machine-readable: checks.json · Per-check anchors: https://defaults.exposed/methodology/v7/<check-id>

Prevalence numbers are aggregates across the whole census — never a named third party's result. Updated with each census run.