<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Defaults.Exposed — Articles</title>
    <link>https://defaults.exposed/en/articles</link>
    <atom:link href="https://defaults.exposed/rss.xml" rel="self" type="application/rss+xml" />
    <description>Independent domain-security research: aggregate SPF, DKIM, DMARC, DNSSEC and TLS posture across the internet, with as-of dates and free remediation guides.</description>
    <language>en</language>
    <lastBuildDate>Sat, 25 Jul 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>Email Authentication: The Complete Guide (SPF, DKIM, DMARC and BIMI)</title>
      <link>https://defaults.exposed/en/articles/email-authentication-guide</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/email-authentication-guide</guid>
      <description>SPF, DKIM and DMARC are one system, not three projects. 53.21% of 261 million graded domains publish SPF, but only 10.59% enforce DMARC — the step that actually stops impersonation. The full stack, in order, with a verification gate at each stage. Data as of 2026-06-29.</description>
      <pubDate>Sat, 25 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>DMARC vs SPF: What's the Difference, and Which Do You Need? (2026)</title>
      <link>https://defaults.exposed/en/articles/dmarc-vs-spf</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/dmarc-vs-spf</guid>
      <description>SPF lists which servers may send email for your domain. DMARC decides what happens when a message fails — and it's the only one that protects the 'From' address people actually see. 53.21% of domains publish SPF; just 10.59% enforce DMARC. What each does, why you need both, and in which order. Data as of 2026-06-29.</description>
      <pubDate>Sat, 25 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>DMARC p=reject vs p=quarantine: Which Policy Should You Choose?</title>
      <link>https://defaults.exposed/en/articles/dmarc-reject-vs-quarantine</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/dmarc-reject-vs-quarantine</guid>
      <description>reject refuses forged mail outright; quarantine sends it to spam. Of the 10.59% of domains that enforce DMARC, the split is almost even — 5.28% quarantine, 5.31% reject. How to choose, the staged path up, and how to roll back safely. As of 2026-06-29.</description>
      <pubDate>Sat, 25 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Why Is My SPF Failing? The SaaS 10-Lookup Problem for UK and EU Senders (2026)</title>
      <link>https://defaults.exposed/en/articles/spf-failing-saas-senders-europe</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/spf-failing-saas-senders-europe</guid>
      <description>SPF breaks silently the moment your include: chain exceeds 10 DNS lookups — a threshold that SaaS-heavy European businesses routinely hit. At least 797,263 domains are already past it. Data as of 2026-06-29.</description>
      <pubDate>Thu, 09 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Is BIMI? How Email Brand Logos Work — And Who Qualifies (2026)</title>
      <link>https://defaults.exposed/en/articles/what-is-bimi-email-brand-logo</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/what-is-bimi-email-brand-logo</guid>
      <description>BIMI shows your brand logo in email clients like Gmail and Apple Mail. It requires DMARC enforcement first — and only 10.59% of domains we've graded have reached that bar. Data as of 2026-06-29.</description>
      <pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Which Email Provider Gives Its Customers the Strongest SPF Defaults? (2026)</title>
      <link>https://defaults.exposed/en/articles/which-email-provider-strongest-spf</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/which-email-provider-strongest-spf</guid>
      <description>85.0% of Microsoft 365 domains end SPF with strict -all; 8.0% of Google Workspace domains do — and no major mailbox provider's customers get past 30% enforced. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Can a Domain Have Two SPF Records? No — a Million Domains Just Voided Their Own (2026)</title>
      <link>https://defaults.exposed/en/articles/two-spf-records-equals-none</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/two-spf-records-equals-none</guid>
      <description>Two SPF records void both: 1,013,416 domains publish multiple v=spf1 records, which the standard treats as a permanent error. The copy-paste mistake that switches SPF off, measured across 261 million domains. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Is the SPF ptr Mechanism — and Why Is It Still in 950,631 Records? (2026)</title>
      <link>https://defaults.exposed/en/articles/the-spf-ptr-trap</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-spf-ptr-trap</guid>
      <description>The SPF ptr mechanism was deprecated in 2014 — slow, unreliable, and a drain on the 10-lookup budget. 12 years later, 950,631 domains still publish it. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The SPF PermError Report: 100× More Domains Break the 10-Lookup Limit Than Surface Counts Show (2026)</title>
      <link>https://defaults.exposed/en/articles/the-spf-permerror-report</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-spf-permerror-report</guid>
      <description>SPF voids itself past 10 DNS lookups — and the breakage hides inside include: chains. At least 797,263 domains are over the limit. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The SPF Adoption Maturity Model (SPFAMM): The 6 Stages of SPF (2026)</title>
      <link>https://defaults.exposed/en/articles/the-spf-adoption-maturity-model</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-spf-adoption-maturity-model</guid>
      <description>The average domain sits at SPF stage 2.4 of 6. SPFAMM: the six-stage SPF maturity model — find your stage and the one move up. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SPF +all: The Domains That Let the Whole Internet Send As Them (2026)</title>
      <link>https://defaults.exposed/en/articles/the-plus-all-map</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-plus-all-map</guid>
      <description>36,014 domains end their SPF record with +all — explicit permission for anyone on Earth to send email as them. Where the welcome mats cluster, how they got there, and the one-character fix. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Fully-Protected Few: the 3.87% Who Finished</title>
      <link>https://defaults.exposed/en/articles/the-fully-protected-few</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-fully-protected-few</guid>
      <description>Only 3.87% of domains — 10,092,481 — run the full enforced email stack: SPF, DKIM, DMARC at quarantine/reject. Just 0.09% hold all five protections.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Email Spoofability Index: How Many Domains Can Anyone Forge? (2026)</title>
      <link>https://defaults.exposed/en/articles/the-email-spoofability-index</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-email-spoofability-index</guid>
      <description>9 in 10 domains can be forged: 89.4% of the internet publishes no policy telling receivers to reject or junk failed mail. The spoofability index, from a census of 261 million domains. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The 6 Stages of DMARC Maturity</title>
      <link>https://defaults.exposed/en/articles/the-6-stages-of-dmarc-maturity</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-6-stages-of-dmarc-maturity</guid>
      <description>24.89% of domains publish a DMARC record — only 10.59% enforce one. A six-stage maturity model, from Unprotected to Hardened, that explains where domains stall and the one move that advances each stage.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Publishing Blind: Most DMARC Records Ask for No Reports</title>
      <link>https://defaults.exposed/en/articles/dmarc-publishing-blind</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/dmarc-publishing-blind</guid>
      <description>Only 35.7% of the 65M domains publishing DMARC request reports (rua=). The rest are publishing blind — and one DNS edit fixes it.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SPF ~all vs -all: Softfail or Hardfail — What 139 Million Records Chose (2026)</title>
      <link>https://defaults.exposed/en/articles/all-qualifier-softfail-vs-hardfail</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/all-qualifier-softfail-vs-hardfail</guid>
      <description>SPF softfail vs hardfail: 55.8% of records end in ~all — and only 1 in 11 has the setting that gives softfail teeth. Data as of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SPF Is Not Enough: the 119 Million Domains That Never Enforce</title>
      <link>https://defaults.exposed/en/articles/119-million-domains-spf-no-enforcement</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/119-million-domains-spf-no-enforcement</guid>
      <description>119 million domains publish SPF but never enforce DMARC — 85.8% of everyone who set SPF up. Is SPF enough? Measured across the whole internet: no. Only 3.87% of domains are fully email-protected. The exposure, counted. As of 2026-06-29.</description>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>'Your Connection Is Not Private' — What It Means and How to Fix It (2026)</title>
      <link>https://defaults.exposed/en/articles/your-connection-is-not-private</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/your-connection-is-not-private</guid>
      <description>The full-page 'your connection is not private' warning almost always means a certificate problem. Across domains serving HTTPS, 8.21% present an invalid certificate that triggers it. What the error codes mean and how to clear it. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Is SPF — and How Do I Fix My SPF Record? (2026)</title>
      <link>https://defaults.exposed/en/articles/what-is-spf-and-how-to-fix-it</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/what-is-spf-and-how-to-fix-it</guid>
      <description>SPF tells the world which servers may send email for your domain. 53.21% of 261 million graded domains publish one — but a record alone isn't protection. The common mistakes, and how to fix yours. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Is DNSSEC — and Do You Actually Need It? (2026)</title>
      <link>https://defaults.exposed/en/articles/what-is-dnssec-and-do-i-need-it</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/what-is-dnssec-and-do-i-need-it</guid>
      <description>DNSSEC signs your DNS so answers can't be forged in transit. Only 1.99% of 261 million graded domains have it — and a misconfigured signature can take you offline. What it protects, who needs it, and how to turn it on safely. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Is DMARC? p=none, quarantine and reject Explained (2026)</title>
      <link>https://defaults.exposed/en/articles/what-is-dmarc-none-quarantine-reject</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/what-is-dmarc-none-quarantine-reject</guid>
      <description>DMARC is the record that decides whether forged email in your name gets delivered. Only 10.59% of 261 million graded domains set it to enforce — the rest either have none or a monitor-only policy that does nothing. What each policy means and how to set it. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Weak and Outdated TLS: Is Your Site Still Serving Old Encryption? (2026)</title>
      <link>https://defaults.exposed/en/articles/weak-and-outdated-tls</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/weak-and-outdated-tls</guid>
      <description>Good news: 90.51% of HTTPS sites now negotiate TLS 1.3. But 'weak TLS' hasn't vanished — it hides in servers that still accept old versions, weak ciphers, and broken certificates (8.21% invalid across 261 million graded domains). How to check you're not the exception. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>My SSL Certificate Expired — Why It Happens and How to Fix It (2026)</title>
      <link>https://defaults.exposed/en/articles/ssl-certificate-expired-how-to-fix</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/ssl-certificate-expired-how-to-fix</guid>
      <description>An expired or invalid certificate throws a full-page browser warning that stops visitors cold. Across domains serving HTTPS, 8.21% present an invalid certificate. Why certificates fail and how to fix — and prevent — it. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Domain and DNS Hijacking: How Domains Get Stolen and How to Lock Yours Down (2026)</title>
      <link>https://defaults.exposed/en/articles/domain-and-dns-hijacking</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/domain-and-dns-hijacking</guid>
      <description>Hijacking redirects your visitors and email without touching your servers. The two DNS controls that stop it are barely used: 1.99% of 261 million graded domains have valid DNSSEC and 1.56% publish CAA. How domains are stolen and how to lock yours. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cyber-Insurance and Vendor Security Questionnaires: What They Check on Your Domain (2026)</title>
      <link>https://defaults.exposed/en/articles/cyber-insurance-security-questionnaire</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/cyber-insurance-security-questionnaire</guid>
      <description>Insurers and enterprise buyers now ask whether you enforce DMARC, serve modern TLS, and lock down DNS. Across 261 million graded domains, only 3.87% are fully email-protected — so most can't honestly tick the boxes. What's asked and how the internet actually scores. Data as of 2026-06-29.</description>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Why Does My Website Say 'Not Secure'? What the Warning Means for Trust (2026)</title>
      <link>https://defaults.exposed/en/articles/why-does-my-website-say-not-secure</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/why-does-my-website-say-not-secure</guid>
      <description>The 'Not Secure' label appears when a site isn't on valid HTTPS. Across 261 million domains, 21.98% serve no HTTPS at all, and 8.21% of those that do have an invalid certificate — so visitors see a browser warning. What it costs and how to fix it. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Why Are My Emails Going to Spam? The Authentication Gap, in Data (2026)</title>
      <link>https://defaults.exposed/en/articles/why-are-my-emails-going-to-spam</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/why-are-my-emails-going-to-spam</guid>
      <description>Most business email lands in spam for one fixable reason: missing authentication. Across 261 million domains, only 53.21% publish SPF, 51.84% use DKIM and 24.89% have any DMARC — the exact signals Gmail and Yahoo now require. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Your Server Headers Tell Attackers: The Stack-Disclosure Report (2026)</title>
      <link>https://defaults.exposed/en/articles/what-your-server-headers-leak</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/what-your-server-headers-leak</guid>
      <description>71.4% of sites announce their web server in the response headers, and 8.1% reveal their app stack and version via X-Powered-By — including end-of-life software. What the web tells attackers for free, in census data. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The DNSSEC Paradox: More Domains Break It Than Get It Right (2026)</title>
      <link>https://defaults.exposed/en/articles/the-dnssec-paradox</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-dnssec-paradox</guid>
      <description>DNSSEC is meant to stop DNS hijacking — but across 261 million domains, more have it misconfigured and broken (3.02%) than working correctly (1.99%). The rest (94.99%) don't try at all. Why DNS is the internet's most-neglected security layer. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The State of IPv6 in 2026: Still Only 23.76% of Domains</title>
      <link>https://defaults.exposed/en/articles/state-of-ipv6-2026</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/state-of-ipv6-2026</guid>
      <description>A decade after 'IPv6 launch', just 23.76% of domains publish an AAAA record — the other 76.24% are IPv4-only. Adoption by country, from a 261-million-domain census. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Publishing SPF Isn't Enough: The False Sense of Email Security (2026)</title>
      <link>https://defaults.exposed/en/articles/spf-without-dmarc</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/spf-without-dmarc</guid>
      <description>32.4% of domains publish SPF but have no DMARC at all, and 45.7% have SPF without enforcement — they look protected and aren't. Only 3.87% are fully email-protected. The false-security gap, in census data. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The SPF Misconfiguration Report: Most SPF Records Are Set Too Weak (2026)</title>
      <link>https://defaults.exposed/en/articles/spf-misconfiguration-report</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/spf-misconfiguration-report</guid>
      <description>139 million domains publish SPF — but 55.8% use the weak '~all' softfail setting and only 39.3% use strict '-all'. Plus 36,014 domains use '+all', which authorises the entire internet to send as them. The misconfigurations hiding inside published SPF. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Who Runs the Internet's DNS? Nameserver Concentration in 2026</title>
      <link>https://defaults.exposed/en/articles/nameserver-concentration</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/nameserver-concentration</guid>
      <description>Five providers run 42.1% of the internet's DNS. Cloudflare alone hosts 15.4% and GoDaddy 14.2%. The systemic risk of DNS concentration, across 255 million domains. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Misconfiguration Hall of Fame: The Web's Weirdest Security Records (2026)</title>
      <link>https://defaults.exposed/en/articles/misconfiguration-hall-of-fame</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/misconfiguration-hall-of-fame</guid>
      <description>244,468 sites serve a TLS certificate literally named &quot;Internet Widgits Pty Ltd&quot; — the placeholder nobody changed. DMARC policies written in the wrong language, SPF records that invite the whole internet in, and other gems from a 261-million-domain census. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The HTTP Security Header Report Card: How the Web Scores in 2026</title>
      <link>https://defaults.exposed/en/articles/http-security-header-report-card</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/http-security-header-report-card</guid>
      <description>Security headers are free, one-line defences against clickjacking, injection and snooping — and almost nobody sets them. Across 261 million domains, just 4.03% get every header right. CSP 8.87%, HSTS 22.91%, clickjacking protection 14.48%. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Are You Ready for Google &amp; Yahoo's Email Sender Rules? (2026)</title>
      <link>https://defaults.exposed/en/articles/google-yahoo-sender-requirements</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/google-yahoo-sender-requirements</guid>
      <description>Google, Yahoo and Microsoft now require SPF, DKIM and DMARC to deliver bulk email. Yet only 53.21% of domains publish SPF, 51.84% DKIM, and 24.89% have any DMARC. Whether your domain meets the bar, in census data. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Half the PHP Web Runs End-of-Life PHP (2026)</title>
      <link>https://defaults.exposed/en/articles/end-of-life-php-on-the-web</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/end-of-life-php-on-the-web</guid>
      <description>Of the 12 million sites that reveal their PHP version, 50.8% run an end-of-life release that no longer gets security patches — and the single most common version is 7.4.33, dead since 2022. The unpatched PHP web, in census data. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Who Runs the World's Email? Email Hosting Market Share in 2026</title>
      <link>https://defaults.exposed/en/articles/email-hosting-market-share</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/email-hosting-market-share</guid>
      <description>Among 161 million domains with an identifiable mail host, 12.7% route mail through Google Workspace and 8.6% through Microsoft 365 — but the biggest category is self-hosted. Email hosting market share, as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Domain Exposure Score: Most Domains Have 1 of 5 Basic Protections (2026)</title>
      <link>https://defaults.exposed/en/articles/domain-exposure-score</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/domain-exposure-score</guid>
      <description>Scored across five core protections — SPF, enforced DMARC, DNSSEC, HTTPS and HSTS — the typical domain has just one or two. 8.8% have none at all; only 0.09% have all five. The exposure curve of 261 million domains, as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Does NIS2 Require DMARC? Email Authentication and EU Cyber Hygiene (2026)</title>
      <link>https://defaults.exposed/en/articles/does-nis2-require-dmarc</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/does-nis2-require-dmarc</guid>
      <description>NIS2 doesn't name DMARC, but it requires cyber-hygiene measures — and email authentication is a baseline anti-spoofing control. Yet across the EU, even the best member state has only 29.43% of domains able to stop impersonation, and most sit far lower. Where EU domains actually stand, as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Does Mandatory DNSSEC Work? What Registry-Driven Adoption Reveals (2026)</title>
      <link>https://defaults.exposed/en/articles/does-mandatory-dnssec-work</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/does-mandatory-dnssec-work</guid>
      <description>Where registries push DNSSEC, valid adoption runs ~7× higher — 9.1% on registry-driven endings vs 1.3% elsewhere (.se 18.38% vs .com 1.62%). But even the leaders break it more than they get it right. The data, as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>&quot;quarentine&quot;, &quot;ninguno&quot;, &quot;non&quot;: The Internet's Most Common DMARC Typos (2026)</title>
      <link>https://defaults.exposed/en/articles/dmarc-typos</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/dmarc-typos</guid>
      <description>48,648 domains published a DMARC record with a misspelled or invalid policy — &quot;quarentine&quot;, &quot;ninguno&quot;, &quot;non&quot;, or no policy at all — and get zero protection as a result. The typos that quietly break email security, from 65 million DMARC records. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>You Set DMARC to p=none — Here's Why You're Still Exposed (2026)</title>
      <link>https://defaults.exposed/en/articles/dmarc-p-none-is-not-protection</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/dmarc-p-none-is-not-protection</guid>
      <description>A DMARC policy of p=none monitors but doesn't protect — your domain can still be impersonated. 14.29% of domains sit at p=none, more than the 10.59% that actually enforce. The false-security trap, in census data. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Expired, Self-Signed, Invalid: The Certificate Error Report (2026)</title>
      <link>https://defaults.exposed/en/articles/certificate-error-report</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/certificate-error-report</guid>
      <description>8.57% of the web's TLS certificates fail validation — 16,920,535 domains that present a certificate browsers won't trust. 3,378,080 are self-signed. The certificate errors that show visitors a warning, in census data. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Who Issues the Web's TLS Certificates? Two Free CAs Now Own 75% (2026)</title>
      <link>https://defaults.exposed/en/articles/certificate-authority-market-share</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/certificate-authority-market-share</guid>
      <description>Across 197 million certificates, Let's Encrypt issues 57.2% and Google Trust Services 17.6% — together 74.7% of the encrypted web runs on two free certificate authorities. The CA market, measured. As of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Can Someone Send Email Pretending to Be Your Business? For Most Domains, Yes (2026)</title>
      <link>https://defaults.exposed/en/articles/can-someone-spoof-my-domain</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/can-someone-spoof-my-domain</guid>
      <description>Only 10.59% of 261 million graded domains enforce DMARC — the one control that actually stops email impersonation. The other 89.41% can be spoofed. What that means for invoice fraud, and how to tell if you're protected. Data as of 2026-06-29.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Let's Dig Into WHOIS: The Best-Performing TLDs for Domain Security (2026)</title>
      <link>https://defaults.exposed/en/articles/best-tlds-for-domain-security</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/best-tlds-for-domain-security</guid>
      <description>Only 0.022% of graded domains earn an A or A+ — yet a handful of TLDs run about 5.8× that rate. We dig into which top-level domains have proportionally the most A and A+ domains, as of 2026-06-28.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Which Country's Businesses Are Most Spoofable? (2026)</title>
      <link>https://defaults.exposed/en/articles/the-most-spoofable-countries</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-most-spoofable-countries</guid>
      <description>Philippines tops the list: 99.7% of its business domains are effectively unprotected against email spoofing. We ranked 69 countries by how forgeable their domains are. Data as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The A-Grade Elite: What the Internet's Most Secure Domains Do Differently (2026)</title>
      <link>https://defaults.exposed/en/articles/the-most-secure-domains-on-the-internet</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-most-secure-domains-on-the-internet</guid>
      <description>Only 0.46% of 260 million domains earn a B or better, and just 0.02% reach an A — about 1 in 4,600. Here is exactly what the internet's most secure domains have in common, as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Internet's Dead Domains: How Many Domains No Longer Resolve? (2026)</title>
      <link>https://defaults.exposed/en/articles/the-internets-dead-domains</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-internets-dead-domains</guid>
      <description>Of 333 million domains we track, 21 million (6.2%) no longer resolve to anything. Here's what the internet's dead domains tell us — and the quiet security risk abandoned domains leave behind. Data as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Internet Security Grade Curve: What an Average Domain Looks Like in 2026</title>
      <link>https://defaults.exposed/en/articles/the-internet-security-grade-curve</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-internet-security-grade-curve</guid>
      <description>We graded 260 million domains A–F. The average domain scores a D or F — only 3.3% reach a C, and just 0.46% earn a B or better. Here is the full grade distribution of the internet, as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>New gTLDs vs Legacy Domains: Is .com Really Safer Than .xyz or .ai? (2026)</title>
      <link>https://defaults.exposed/en/articles/new-gtlds-vs-legacy-domains</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/new-gtlds-vs-legacy-domains</guid>
      <description>We compared the security of legacy endings (.com, .net, .org) against new gTLDs (.ai, .io, .xyz, .top) across millions of domains. The surprise: age doesn't predict safety — price and purpose do. Data as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>National vs Generic Domains: Are ccTLDs Like .de and .uk Safer Than .com? (2026)</title>
      <link>https://defaults.exposed/en/articles/national-vs-generic-domains</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/national-vs-generic-domains</guid>
      <description>We compared 111 national domain endings against 361 generic ones across 260 million domains. National (ccTLD) domains are measurably more secure: 80.2% score an F versus 88.3% on generic endings. Data as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The National Domain Security Index 2026: How Countries Rank on Domain Security</title>
      <link>https://defaults.exposed/en/articles/national-domain-security-index</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/national-domain-security-index</guid>
      <description>We graded the business domains behind 111 countries' national endings. 80.2% score an F — and even the best-ranked country leaves most of its domains exposed. The full national ranking, updated live, as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How We Graded the Entire Internet: The A–F Domain Security Methodology (2026)</title>
      <link>https://defaults.exposed/en/articles/how-we-graded-the-internet</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/how-we-graded-the-internet</guid>
      <description>How Defaults.Exposed grades 260 million domains from A+ to F across 34 externally observable security checks — what we measure, how the grade is calculated, and the limits of the data. Last updated 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Europe vs the World: Domain Security in the GDPR Era (2026)</title>
      <link>https://defaults.exposed/en/articles/europe-vs-world-domain-security</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/europe-vs-world-domain-security</guid>
      <description>European businesses protect their domains better than the rest of the world: 76.4% of European national-domain businesses score an F, versus 84.7% elsewhere. But 'better' still means most domains are exposed. The data, as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Emerging-Market Domains: The Security Gap in Fast-Growing ccTLDs (2026)</title>
      <link>https://defaults.exposed/en/articles/emerging-market-domains</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/emerging-market-domains</guid>
      <description>National domains in emerging markets score an F 85.6% of the time, against 77.4% in developed economies — an 8.3-point gap. But the spread inside the emerging group is far wider than the gap between groups. The data, as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Domain Decay by TLD: Where Domains Go to Die (2026)</title>
      <link>https://defaults.exposed/en/articles/domain-decay-by-tld</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/domain-decay-by-tld</guid>
      <description>About 6.2% of all registered domains no longer resolve — but the rate varies wildly by ending. Cheap bulk endings like .xyz decay fastest; established national registries barely at all. The internet's domain mortality map, as of 2026-06-28.</description>
      <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The State of Domain Security 2026</title>
      <link>https://defaults.exposed/en/articles/the-state-of-domain-security-2026</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/the-state-of-domain-security-2026</guid>
      <description>We graded 260 million domains across 34 security checks. 86.2% score an F — only 10.59% enforce DMARC, 78.02% use HTTPS, and 4.03% get every security header right. The signal-by-signal state of the internet.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Domain Security World Cup: who lifts the trophy if the safest domains win?</title>
      <link>https://defaults.exposed/en/articles/domain-security-world-cup</link>
      <guid isPermaLink="true">https://defaults.exposed/en/articles/domain-security-world-cup</guid>
      <description>We took the real 2026 World Cup draw — all 12 groups, all 48 teams — and let one rule decide every match: the country whose business domains are least exposed wins. Bosnia are world champions, Germany finish bottom of their group, and the hosts go out at home.</description>
      <pubDate>Sat, 27 Jun 2026 12:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
