Defaults.Exposed

Defaults.ExposedStats › DNS & infrastructure

DNS & infrastructure

5 statistics · figures as of September 5, 2026 · census snapshot 2026-09-05 · September 2026 edition

DNSSEC, CAA, IPv6 and the handful of providers who between them answer for most of the internet.

MeasureAs of September 5, 2026
DNSSEC adoption 6.9%
CAA adoption 1.4%
IPv6 (AAAA) adoption 21.8%
DNS provider market share GoDaddy

DNS is the layer everything else depends on, and it is the least protected layer the census measures. 6.9% of graded domains have a valid DNSSEC chain. A further 0.1% are signed but broken, which is its own category of problem: a broken chain can make a domain unreachable for validating resolvers while providing none of the protection signing was meant to buy. Among all signed domains, 0.8% are in that broken state.

Certificate authority authorisation is the other control at this layer, and adoption is similarly thin at 1.4%. A CAA record is one line that names which certificate authorities may issue for your domain. Without it, any authority on earth may issue a certificate for your name, and nothing in the process would tell you it had happened. It is among the cheapest controls in the whole census and among the least used.

Concentration is the story the provider figures tell. The largest DNS provider alone serves 16.94% of domains with nameservers, and Cloudflare specifically answers for 49,278,555 domains, or 15.78% of them. That concentration cuts both ways. A default changed at one provider improves millions of domains overnight, which is most of how adoption figures move at all. It also means a small number of operators hold a great deal of the internet’s resolution in their configuration choices.

Two further measurements round out the picture. IPv6 reachability sits at 21.8%, which after two decades of transition says more about hosting defaults than about intent. And 22,163,989 domains sit on dedicated parking nameservers, registered but pointed at nothing in particular, a reminder that a large share of the registered internet exists to be resold rather than used.

DNSSEC adoption is stuck for a structural reason rather than a technical one. Signing a zone is straightforward at the DNS host, but completing the chain requires publishing a DS record at the registrar, and registrar interfaces for that range from buried to absent. The result is a control where the operator who can sign and the operator who can complete the chain are frequently different companies, with the customer in between. Where a single provider does both, adoption is markedly higher, which is the clearest evidence that friction rather than disagreement keeps the number low.

There is also a resolver side that no site-level measurement can see. A signed domain only benefits visitors whose resolver actually validates signatures, and a broken chain only harms those same visitors. That asymmetry is why signed-but-broken is worse than unsigned: an unsigned domain is merely unprotected, while a broken one can be unreachable for the most security-conscious part of its audience while offering nothing to anybody else.

DNSSEC and CAA are both single records published through your DNS host. The scan tells you whether yours are there.

Every statistic in this section

Each has its own citable permalink and a machine-readable twin at /stats/s/<id>.json, resolved from the same census files as the figures above.

← All sections · how we grade · data & downloads