July 2026 Domain Security Census: 296.7 Million Domains Graded
Publisert · oppdatert
Figures as of 2026-07-29 · methodology v8. Aggregate census data; we never publish an individual domain’s status or grade. See how we grade.
We graded 296,674,837 domains this edition, and 73.8% of them earned an F. That is not a sample or an estimate. We probed 297 million individual domains, ran the same checks on each one, and scored every result under the same rulebook.
This is the monthly census recap. Every edition measures the same directly observed facts across the internet’s domain population: which security records exist, what policies they carry, and which version of TLS — the encryption behind https — each server agrees to use. The rulebook that turns those facts into grades is versioned, and this edition runs v8. Here is the July photograph: what moved, what stayed put, and what we deliberately decline to compare.
Where did 297 million domains land?
| Grade | Share of graded domains | Domains |
|---|---|---|
| A+ | 0.0% | 65,257 |
| A | 0.1% | 432,668 |
| B | 1.9% | 5,525,038 |
| C | 7.5% | 22,174,789 |
| D | 16.7% | 49,493,128 |
| F | 73.8% | 218,983,957 |
The story of this table is the bottom row. 218,983,957 domains sit at F this edition — 73.8% of everything we could grade. On today’s internet, a failing security posture is not the exception. It is the default. That default is not spread evenly, either. Newer domain endings such as .ai enforce DMARC, the email anti-spoofing standard, at nearly three times the rate of .com; see .com vs .ai domain security. Everything above the F line is competing for what remains.
Where does your own domain sit in this table? Run the free check — it takes seconds, and we never publish individual results.
One caution before you read this table as a trend: it is a photograph, not a film.
What do we compare month over month — and what do we not?
A grade is made by two things: the internet and our rulebook. The rulebook changes on purpose, version by version. When it changes, grade shares can move without a single DNS record changing anywhere in the world. That is not a hypothetical caution this month: The rulebook version can change between editions. So we never claim that the internet’s grades improved or declined between editions. The F rate above is true of this edition, under methodology v8, and that is all it claims.
What we do compare are the facts that stay stable across rulebooks: whether a DMARC record exists and what policy it carries, which TLS version a server negotiates, whether a DNS zone is signed and validating. Those are properties of the internet itself, measured the same way every month. When we say a number moved, it is always one of those.
Why is DMARC enforcement the number to watch?
DMARC enforcement climbed from 10.6% to 11.83% of the domains we could evaluate for DMARC. That is a rise of 1.2 percentage points in a single month. The full enforcement tracker breaks the move down. In net terms it works out at roughly 5.0 million domains.
Enforcement means a policy of quarantine or reject. A domain with one of those policies does not just publish a DMARC record; it tells the world’s mailboxes to junk or refuse mail that fails authentication. A p=none record is the weaker kind. At best it can watch spoofing happen, and only when its reporting addresses are set up. An enforcing record tells receiving mailboxes to act. It is the difference between a camera and a lock.
At this scale, every percentage point of enforcement stands for millions of domains whose owners now tell the world’s mailboxes to refuse impersonation attempts. The pressure behind the move is structural. Major mailbox providers now demand authentication from bulk senders, which makes DMARC a condition of getting mail delivered, not just a security control. Insurers and procurement teams have put DMARC on their questionnaires too. That is why we expect this line to keep creeping rather than spiking.
Most domain owners do not know which side of the camera-or-lock line they are on. The free check reads your DMARC record and tells you in seconds. The DMARC fix guide then maps the path to enforcement.
Dead domains: can the internet improve and rot at the same time?
It can, and it does. Both things show up in the same dataset, in the same month.
While enforcement climbs, 21 million domains in our 360 million-domain inventory are dead. These are registered names that no longer resolve to a usable address. They still sit on a registry’s books, paid for or quietly lapsing, but there is nothing behind them left to reach. The internet-rot report separates the dead from the unreachable and the zombies in full.
The rising line and the rotting pool describe different internets. The enforcement curve belongs to the actively managed web: domains whose owners read their mail, take audits and respond to mandates. The dead pool is everything nobody looks at any more. If you still own domains you no longer use, they belong in this picture too. A parked name without a reject policy is an open invitation to spoofers, so check those names alongside your main domain. A census that reported only the flattering half would be marketing. Reporting both is the job.
TLS 1.3 and DNSSEC: what refused to move?
Some of our most important numbers barely move from edition to edition. The stillness is itself the finding.
TLS 1.3 was negotiated on 94.8% of the domains where we could complete a handshake. That handshake succeeded on 210 million domains this edition. Within that group, modern transport encryption is close to a solved problem. That is not because the world’s administrators each made a good decision. It is because content-delivery networks, hosting platforms and web servers now ship it by default. When the default does the work, adoption gets close to universal. The TLS 1.3 adoption report traces how that happened.
DNSSEC sits at 6.28% signed and validating among the domains whose DNS we could evaluate. DNSSEC adds cryptographic signatures to DNS answers, so resolvers can detect tampering. Unlike TLS, nobody switches it on for you. It is an explicit opt-in, and enabling it still feels slightly scary. When the burden falls on the owner, even a decades-old standard stays a niche pursuit. The DNSSEC adoption report digs into why. The gap between the TLS figure and the DNSSEC figure is the clearest picture we have of what actually drives security adoption: defaults, not diligence.
One bar is stricter still: 7,678,989 domains hold the complete email-protection stack the census measures — roughly 1 in 39. Full marks remain rare enough to be a distinction. The fully protected club looks at who clears the bar.
What will next month’s census ask?
The same questions. That is the point. Every month we measure the same directly observed facts across that month’s domain population: record presence, policy splits, negotiated TLS versions, signed zones. The grading rulebook is versioned separately — June ran the prior methodology version, this edition runs v8 — and when it changes, we publish the change before we say anything else.
Next edition we will watch whether DMARC enforcement holds its slope, whether DNSSEC finally shows a pulse, and how the dead pool develops. One caveat on the dead pool: whether a domain counts as dead depends on our probe-and-retry policy, and we version and disclose that policy just like the grading rules. The grade distribution will be published the way it always is: as its own snapshot, under whatever rulebook that edition runs.
What this means for your business
With 73.8% of graded domains at F, simply holding a passing posture separates you from most of the internet. The bar for standing out is lower than most boards assume.
The DMARC gap is your spoofing exposure. If your domain sits in the large majority without an enforcing policy, anyone can try to send mail that claims to come from you. Your domain gives receiving mailboxes no standing instruction to junk or refuse that mail. The target could be your customers, your suppliers or your own finance team. One spoofed invoice paid in error costs more than a decade of fixing this. Business email compromise, fraud that begins with a faked email, remains among the largest reported cyber-loss categories year after year. The climb to 11.83% shows your peers are closing that door.
Passing every measured layer is a claim you can make. 7,678,989 domains pass every email-protection layer the census measures, about 1 in 39. Being one of them is an evidence-backed talking point in security questionnaires, cyber-insurance applications and enterprise procurement. The free check shows which layers your domain already passes. If you want the shortest path to full marks, the A-Grade Playbook turns your specific gaps into a step-by-step runbook.
Your risk also includes everyone you email. Your suppliers and partners come from the same population this table describes — their posture is your exposure. Run the free check on the domains that send you invoices before you pay the next one.
Every figure in this report is an aggregate, but your own domain has a specific answer. It takes seconds to get. Run the free domain security check and see exactly where you stand on the checks this census measures — before someone else looks.
Quick answers
How many domains did the latest defaults.exposed census grade? As of 2026-07-29, the census graded 296,674,837 domains. 73.8% of them received an F under methodology v8.
How much did DMARC enforcement rise in the July 2026 census? Enforcement rose from 10.6% to 11.83% of evaluated domains between the June and July 2026 editions. The DMARC enforcement tracker has the full breakdown.
How many domains are fully protected? 7,678,989 domains — about 1 in 39 — pass every layer of the email-protection stack the defaults.exposed census measures.
How do I check my own domain’s security grade? Run the free check at defaults.exposed. It grades any domain in seconds against the same v8 checks used in the census, and results are never published.