Defaults.Exposed › Stats › Security grades
Security grades
3 statistics · figures as of September 5, 2026 · census snapshot 2026-09-05 · September 2026 edition
What the A-to-F distribution actually looks like across the whole measurable internet, and why the shape is so lopsided.
| Measure | As of September 5, 2026 |
|---|---|
| Domains scoring an F | 74.2% |
| Domains scoring A or A+ | 0.20% |
| A+ domains | 80,995 |
| B-or-better domains | 7,031,573 |
The grade distribution is the single most compressed summary the census produces, and it is brutal. 74.2% of the 317 million graded domains score an F: 234,955,475 domains that fail the basic, externally observable protections. At the other end, 0.20% reach an A or A+, and only 80,995 domains hold an A+ outright. Between those poles, 7,031,573 domains manage a B or better, which is 2.22% of everything graded.
A distribution this lopsided is usually a sign that the thing being measured is hard or expensive. Here it is neither. Every control in the grade is free, publishable through a registrar or DNS host in minutes, and requires no software, licence or vendor. The distribution is not a picture of who could afford security. It is a picture of defaults: what a domain looks like when nobody has deliberately configured it.
That also explains why the curve moves faster than people expect. A domain’s grade is built from independent checks, so one published DNS record can carry it across a boundary. A hosting platform that turns a header on for every customer moves a percentage point of the whole internet in a week, without a single customer deciding anything. Most of the movement between editions comes from platform defaults changing, not from individual owners acting.
The F cohort deserves one clarification, because it is the figure most often misquoted. An F does not mean a domain has been compromised or is doing anything wrong. It means the domain publishes none of the protections that would stop someone forging mail from it or intercepting traffic to it. It is a statement about what is absent, and absence is exactly what an attacker looks for when choosing which name to impersonate.
The mechanics behind a grade are deliberately unclever. Each check is decided independently, a domain either publishes what the check looks for or it does not, and the grade is the arithmetic of those results rather than a judgement applied on top. There is no weighting by industry, no adjustment for company size, and no allowance for intent. A large organisation with no SPF record scores exactly what a dormant domain with no SPF record scores, because to someone forging mail from either of them the situation is identical.
One rule does more work than any other: a check the census cannot decide is recorded as undetermined and excluded from that domain's denominator, never counted as a failure. A timeout, a refused query or a redacted source produces no data, and no data is not evidence of absence. That single decision is why the grades here sit lower than a naive scan would report but are harder to argue with, and it is the first thing to check when comparing this distribution against anyone else's.
A grade is not a verdict on a business, it is a list of records that are missing. Find out which ones are missing from yours.
Every statistic in this section
Each has its own citable permalink and a machine-readable twin at
/stats/s/<id>.json, resolved from the same census files as the figures above.