Defaults.Exposed

Defaults.Exposed › Tools

Tools

Five pages that take something you already have, a header block, a DNS record or a score, and tell you what it means. Four of them work entirely in your browser and send nothing anywhere. The fifth resolves an SPF chain here, over this server's own resolver, because that answer does not exist until somebody resolves it.

They all read from the same September 2026 census the rest of the site is built on, so a prevalence figure beside a record is measured across 316,600,902 graded domains rather than guessed at.

Read an Authentication-Results header Paste the header block from a message and get every token explained where it sits, then scan the domain it names. Count your SPF lookups Resolve the include chain and count the DNS lookups a receiver spends, against the ten that void the record. Decode a DMARC record Read your policy tag by tag and see which parts are doing something and which are being ignored. Identify a TXT record Find out what a string in your zone is, whether it is safe to remove, and how many domains carry the same token. Place your score inside your TLD See where your grade sits in your own registry, with that registry's F share, from the September 2026 census.

Read next

What SPF is and what it protects · What DMARC does, and what p= changes · The HTTP headers a browser reads before your page

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Census numbers move every month; the current values are on the census data page.