Defaults.Exposed

What we will and will not compare between census editions

You’ve got two figures from two editions of the census and you want to write “up from X to Y”. Before that sentence goes anywhere, you need to know whether the two figures were measured over the same thing, and with most published statistics you can’t tell. On this site the question is settled in advance, and the answer is narrow: a figure is compared across editions only when its denominator is a set of records the census observed in that same edition. A share of all domains, however familiar it looks, isn’t compared at all.

Why a share of domains can move without a record changing

Each edition of the census starts from a fresh source list. The census pulls the zone files and crawl indexes again and reruns the existence pass. A different set of names survives it each month. The number of domains inside a TLD moves between editions, and it moves for reasons that have nothing to do with anyone’s DNS.

Take a share like “domains with a DMARC record”. Its numerator is a count of records the census saw. Its denominator is the count of domains in the edition. If a source list picks up a few million parked names with no mail and no records, the denominator rises, the numerator stands still, and the share falls. Nobody removed a DMARC record; the ratio moved anyway. The same distortion runs the other way when a list shrinks.

So before comparing any two figures, check what sits under the line. When the denominator is a domain count, the composition of the list is baked into the number, and you can’t take it back out afterwards. When the denominator is a set of records the census observed, composition mostly cancels, because a domain that arrives with no record adds nothing to either side and a domain that leaves takes its record from both.

The same question applies when the domain under the line is your own. A cohort share, however well its denominator is chosen, describes a population; whether your DMARC record ends in p=none, or your web host still answers on TLS 1.2, is a fact about one row, and the free scan reads that row in under a minute. What it finds is free to fix as well.

The cohort the series are measured over

The census fixes the comparison set before it counts any fact. The September 2026 census defines it as 1244 TLDs present in the July, August and September lakes (IDN TLDs excluded: their partition names differ between lakes). A TLD that appears in only two of the three lakes is out, and the internationalised ones are out for the reason in the brackets.

Inside that cohort, each fact is computed identically per edition from the raw evidence, and disposition and grades play no part. The same code reads the same kind of evidence in each lake: the DMARC TXT string as fetched, the SPF string as fetched, the TLS version the handshake settled on, the HTTP response headers as received. Whether a domain was later marked graded, indeterminate, unreachable or dead has no bearing on the count, and neither does the grade it received. The grade stays out on purpose: grading rules get revised, and a series that inherited those revisions would be measuring the scorer rather than the internet.

The rule, in one line

Compare only lines whose denominator is itself an observed record set in the same edition.

Four families of line pass that test. The census counts the DMARC policy mix (p=none, p=quarantine, p=reject) over cohort_dmarc_present, the DMARC records it observed in that edition. The SPF qualifier mix (-all, ~all, ?all, +all) has cohort_spf_present under it. TLS version sits over cohort_handshakes, the handshakes that completed, and HSTS and CSP presence over cohort_http_answered, the hosts that returned an HTTP response. If you want to know what a DMARC policy or an HSTS or CSP header means for a single domain, those pages cover it; this page is only about whether the counts can be compared.

Two lines on the same sheet fail the test and are printed for transparency only: DMARC record present and SPF record present, both over cohort_domains. They’re there so you can watch the domain count move, which is the whole reason they aren’t quoted as a trend.

What isn’t compared, and why

This site keeps DKIM out of any edition comparison. The DKIM probe checks a fixed list of selectors. A domain whose selector isn’t on that list reads as not-determinable rather than absent, and the size of that not-determinable pool depends on which selectors are in use and when the list was last edited. A series with that much unmeasured mass in it can move for reasons nobody can name, so it isn’t published as one.

Grades and dispositions aren’t compared either. A grade is the output of a scoring rule, and the rule is the site’s to change. Each edition’s grade shares describe that edition and stop there.

Then there’s the break between the August and September editions. The list of domains under measurement changed shape between those two months, for reasons on the sourcing side rather than on the internet. The September 2026 sheet has no like-for-like figure for that break, so this page records it as a fact with no number attached, and no percentage-point change in the F share between August and September appears on this site. If you see one quoted with this census as the source, it wasn’t taken from here.

The series that obey the rule

Here are two series from the cohort above, quoted as the sheet prints them with the denominator in the sentence, so you can carry that denominator into your own.

The first is the share of DMARC records whose policy is p=none, measured over cohort_dmarc_present, the DMARC records the census observed in each edition.

editionp=none recordsof cohort_dmarc_presentshare
2026-0738,774,40674,902,71451.77%
2026-0840,909,34479,014,72751.77%
2026-0941,856,85680,986,76351.68%

Read across the rows and the record set grows each month. Read down the share column and the mix holds. The share describes the policy mix among records that exist and says nothing about how many domains have no record at all.

The second is the share of completed handshakes that negotiated TLS 1.3, measured over cohort_handshakes.

editionTLS 1.3 handshakesof cohort_handshakesshare
2026-07200,808,445211,807,99194.81%
2026-08220,653,014232,583,31394.87%
2026-09199,895,804211,728,09094.41%

The August denominator is larger than the ones on either side of it, which is the composition break showing up in the handshake count. The share column is the part that can be compared, because a handshake that didn’t complete is on neither side of the line. What a TLS version means for a single site, and why 1.2 still answers on some hosts, is a separate question from whether these three shares line up.

How big a move has to be before it counts

Once the denominator is sound, the next test is size. The p=none share above moves by less than a tenth of a percentage point across three editions, and the TLS 1.3 share stays inside a single point. Sound denominators don’t turn either of those into a trend, so this page doesn’t write them up as one.

This site describes a mix line as having shifted only when it has moved by at least one full percentage point, in the same direction, across three consecutive editions. Below that, month-to-month wobble in which domains happened to answer and which hosts timed out is enough to explain the movement, and the accurate description is “flat”. Above that, the sentence still carries the denominator, and it still says nothing about domains outside the record set.

What to write when you cite a change

Name the denominator in the sentence, in words. “Of the DMARC records observed in the September 2026 edition, 51.68% carried p=none” is a sentence that survives someone checking it. “51.68% of domains have p=none” is wrong twice over: wrong denominator, and a share of domains this site doesn’t publish as a series.

Keep the edition in the sentence, and quote the number as printed. If you’re comparing two editions, quote both rows and let the reader see the denominators move. If the thing you want to compare is a share of domains, a grade share, a DKIM figure or the F rate across the August break, the accurate citation is that the census doesn’t compare it, and you can say why in one line: the denominators aren’t the same thing.

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Census numbers move every month; the current values are on the census data page.