Defaults.Exposed › Methodology › v7 registry
Methodology v7 — the 34-check registry
Methodology v7 · 34 checks (25 scored + 9 informational) · census as of July 28, 2026
This is the versioned, citable registry of every check in the Defaults.Exposed grading methodology.
Each check has a permanent canonical ID and a stable URL — cite /methodology/v7/<check-id>
and it will keep meaning the same thing. Prevalence figures are computed from the census of
275,666,275 graded domains and refresh with each census; the check
definitions themselves are frozen for v7.
Machine-readable: checks.json · Human explainer: how we grade the internet · Headline statistics: /data · Licence: open data
How checks become a grade
25 of the 34 checks carry points; 9 are informational and never move the grade. Every check returns pass, fail, or N/A — the no-data rule: when a check couldn't be determined (timeout, SERVFAIL, redacted source) it is excluded from that domain's scoring denominator rather than counted as a failure. "Determined absent" (no DMARC record, no HTTPS) is a real fail. Grade bands are locked for comparability: A+ ≥ 95% · A ≥ 90% · B ≥ 80% · C ≥ 70% · D ≥ 60% · F below 60%.
Email Security
| Canonical ID | Check | Grade impact | Census prevalence (as of July 28, 2026) | Fix guide |
|---|---|---|---|---|
spf-exists | SPF record | Scored | 50.3% of graded domains publish a syntactically valid SPF record | /fix/spf |
spf-policy-strength | SPF policy strength | Scored | 20.1% of graded domains publish SPF with a hardfail (-all) policy | /fix/spf |
dmarc-policy | DMARC policy | Scored | 11.8% of graded domains publish an enforcing DMARC policy (p=quarantine or p=reject) | /fix/dmarc |
dmarc-reporting | DMARC reporting | Scored | 10.2% of graded domains publish a DMARC record with an aggregate-reporting (rua) address | /fix/dmarc |
dkim-exists | DKIM | Scored | 51.2% of graded domains have a discoverable DKIM selector | /fix/dkim |
mx-record | MX records | Scored | 99.9% of graded domains publish at least one MX record | /fix/mx |
reverse-dns | Reverse DNS (PTR) | Scored | 76.3% of graded domains have a PTR (reverse DNS) record | /fix/reverse-dns |
TLS & Certificates
| Canonical ID | Check | Grade impact | Census prevalence (as of July 28, 2026) | Fix guide |
|---|---|---|---|---|
https-available | HTTPS available | Scored | 76.3% of graded domains serve over HTTPS | /fix/https |
cert-valid | Certificate valid | Scored | 91.2% of HTTPS-serving domains present a valid, trusted certificate | /fix/certificate |
cert-expiry-warning | Certificate expiry | Scored | not published per-check in the census rollup | /fix/certificate |
cert-signature-algorithm | Signature algorithm | Scored | not published per-check in the census rollup | /fix/certificate |
cert-key-strength | Key strength | Scored | not published per-check in the census rollup | /fix/certificate |
tls-version | TLS version | Scored | 100.0% of HTTPS-serving domains negotiate TLS 1.2 or 1.3 | /fix/tls |
cipher-strength | Cipher strength | Scored | not published per-check in the census rollup | /fix/tls |
tls-compression | TLS compression | Informational | not published per-check in the census rollup | /fix/tls |
ocsp-stapling | OCSP stapling | Informational | not published per-check in the census rollup | /fix/tls |
secure-renegotiation | Secure renegotiation | Informational | not published per-check in the census rollup | /fix/tls |
Web Security
| Canonical ID | Check | Grade impact | Census prevalence (as of July 28, 2026) | Fix guide |
|---|---|---|---|---|
hsts-header | HSTS | Scored | 19.1% of HTTPS-serving domains send an HSTS header | /fix/hsts |
http-to-https-redirect | HTTP→HTTPS redirect | Scored | not published per-check in the census rollup | /fix/https |
csp-header | Content-Security-Policy | Scored | 3.78% of graded domains send an effective Content-Security-Policy header | /fix/csp |
x-frame-options | Clickjacking protection | Scored | 5.66% of graded domains send clickjacking protection (X-Frame-Options or CSP frame-ancestors) | /fix/clickjacking |
x-content-type-options | MIME-sniffing protection | Scored | 7.28% of graded domains send X-Content-Type-Options: nosniff | /fix/mime-sniffing |
referrer-policy | Referrer-Policy | Scored | 2.99% of graded domains send a Referrer-Policy header | /fix/referrer-policy |
coop-header | COOP (Cross-Origin-Opener-Policy) | Informational | 1.05% of graded domains send a Cross-Origin-Opener-Policy header | /fix/cross-origin-headers |
corp-header | CORP (Cross-Origin-Resource-Policy) | Informational | 0.89% of graded domains send a Cross-Origin-Resource-Policy header | /fix/cross-origin-headers |
coep-header | COEP (Cross-Origin-Embedder-Policy) | Informational | 0.68% of graded domains send a Cross-Origin-Embedder-Policy header | /fix/cross-origin-headers |
DNS Security
| Canonical ID | Check | Grade impact | Census prevalence (as of July 28, 2026) | Fix guide |
|---|---|---|---|---|
caa-record | CAA records | Scored | 1.54% of graded domains publish a CAA record | /fix/caa |
dnssec-ds | DNSSEC (DS) | Scored | 6.28% of graded domains have a valid, fully validating DNSSEC chain | /fix/dnssec |
dnssec-dnskey | DNSSEC (DNSKEY) | Scored | 6.28% of graded domains have a valid, fully validating DNSSEC chain | /fix/dnssec |
nameserver-diversity | Nameserver diversity | Scored | not published per-check in the census rollup | /fix/nameservers |
soa-configuration | SOA configuration | Scored | not published per-check in the census rollup | /fix/nameservers |
ipv6-support | IPv6 support | Informational | 23.1% of graded domains publish an AAAA (IPv6) record | /fix/ipv6 |
Infrastructure
| Canonical ID | Check | Grade impact | Census prevalence (as of July 28, 2026) | Fix guide |
|---|---|---|---|---|
cdn-waf-detection | CDN / WAF detection | Informational | not published per-check in the census rollup | /fix/infrastructure |
hosting-provider | Hosting provider | Informational | not published per-check in the census rollup | /fix/infrastructure |
Cite this registry
Check definitions are stable for methodology v7; prevalence figures are dated per census. Please cite Defaults.Exposed and link the check's stable URL.
Defaults.Exposed, "Grading Methodology v7" (census as of July 28, 2026). https://defaults.exposed/methodology/v7
Permalink: https://defaults.exposed/methodology/v7 ·
Machine-readable: checks.json ·
Per-check anchors: https://defaults.exposed/methodology/v7/<check-id>
Prevalence numbers are aggregates across the whole census — never a named third party's result. Updated with each census run.