Defaults.Exposed › Stats › Census & population
Census & population
1 statistics · figures as of September 5, 2026 · census snapshot 2026-09-05 · September 2026 edition
How many domains exist, how many can be measured, and why the two numbers are so far apart.
| Measure | As of September 5, 2026 |
|---|---|
| Registered domains in the census | 347,691,016 |
| Domains graded | 316,600,902 |
| TLDs parsed | 1,433 |
| Dead & unreachable domains | 1,389,076 |
A domain-security statistic is only as good as the population behind it, and most published figures never say what theirs is. The census starts from the registry inventory rather than from a crawl of popular sites: 347,691,016 registered domains across 1,433 top-level domains, reconciled from every zone file and registry source obtainable. That inventory is the honest denominator. It includes the domain registered yesterday and parked, the one that has answered nothing since 2019, and the one carrying a company’s entire mail flow.
Of that inventory, 317M resolved and answered enough to be graded. The gap is not measurement failure, it is the internet’s actual condition: 0.4% of registered domains are dead, and a further 4.4% were unreachable at the time of the pass. Roughly a third of the registered internet is, in any practical sense, not there.
That matters for every other number on this site. Quote a security statistic against all registered domains and you flatter the internet, because dead domains publish nothing and fail everything. Quote it against a top-million list and you flatter it far more, because the top million are run by people with security teams. The census grades what is alive and reachable, which is neither the best nor the worst slice, and it states the denominator on every page so anyone can check the arithmetic.
The other reason to start here is comparability. A figure computed against a different population is not a better or worse version of ours, it is a different measurement. When a vendor reports DMARC adoption at fifty-something percent and the census reports a much lower number, both can be correct: theirs is usually a panel of customers or a list of large organisations, ours is the registered internet minus what is dead. The interesting question is never which number is higher, it is which population you belong to.
What the census does not cover is worth stating plainly, because every dataset has an edge and most never name theirs. It measures registered domains at the second level, not subdomains, so a company with one registered name and four hundred hostnames appears once. It measures what is published in public DNS and answered over the public internet, so anything behind a private resolver or an internal zone is invisible to it. And it measures configuration rather than behaviour: whether a protective record exists, not whether anyone has yet tried to abuse its absence.
The edition cadence matters for the same reason. Each edition is a snapshot taken over a defined window rather than a rolling average, and every figure on this site carries the snapshot date it came from. That makes editions comparable with each other and makes any single figure checkable against the published dataset. It also means a number here can lag a change you made last week, which is the honest cost of measuring the whole internet instead of polling a sample of it.
Your own domain sits somewhere in that population. The scan tells you where, in about thirty seconds, without an account.
Every statistic in this section
Each has its own citable permalink and a machine-readable twin at
/stats/s/<id>.json, resolved from the same census files as the figures above.