Defaults.Exposed

Why .nl and .fr look safer this month, and what changed in the counting

If .nl or .fr is your zone and it looks safer in the September 2026 census than it did in the previous edition, the thing that moved is the inventory being graded. A two-pass existence check now removes names that no longer resolve before any grading runs, so this edition grades a smaller and more alive set of domains in both zones.

The September composition is real and you can quote it. The movement between editions describes the counting, and you shouldn’t quote it as a change in what your registrants did.

What September says about .nl and .fr

In the September 2026 edition, .nl has an F share of 39.8% of domains carrying a grade (3,748,769 graded), and .fr has 48.3% (3,192,307 graded). Both sit well below the F share for all TLDs taken together, and that gap is wide enough that it isn’t a rounding artefact or a source-list quirk. Whatever else the counting did this month, the two zones grade better than the scanned internet as a whole.

An F means a domain failed enough weighted checks to land below the D threshold. The check the grade treats as most serious is the DMARC policy check, so a zone’s F share is largely a statement about how many of its names publish an enforcing DMARC record. What an enforcing record looks like is the same in .nl as in .fr; the zone doesn’t change the record, and it doesn’t change the weight the record carries.

What changed in the counting

Before the existence pass, a sourced name could reach the grading stage whether or not it still resolved. September is a two-pass edition. The first pass asks whether each sourced name exists in the DNS at all. It drops the ones that answer NXDOMAIN, and it drops the wildcard phantoms: names that only appear to exist because their TLD answers for anything. Only the survivors go to the second pass, which runs the checks and assigns the grade.

The effect on a zone is mechanical. A dead name can’t pass a DMARC check or a TLS check, so any dead name that reached grading sat at the bottom of the scale. Take those names out before grading and the remaining set grades better, with no registrant having touched a record. That mechanism alone can move a zone’s F share between editions, and it’s the one to rule out first.

Across all TLDs scanned, the September edition marks 1,389,076 domains dead, 0.40% of scanned. That’s how small the dead band is once the existence pass has done its work: it has already taken out most of what would otherwise arrive at the grader with nothing to grade. The census doesn’t publish that count per zone, so there’s no .nl or .fr dead figure to give you here.

Why the number can’t be compared with last month

A league table implies one ruler laid across two editions. The census doesn’t have that ruler for a per-zone grade share, and the reason is the denominator.

The set of domains inside a TLD moves between editions because the source lists differ: zone files and crawl-derived lists are each refreshed on their own schedule, and this edition added the existence pass on top. A count of “domains in .nl with DMARC” over all domains in .nl is therefore a fraction whose bottom half changed shape, and a change in the fraction tells you nothing on its own about the top half.

That is why you get a September composition here and no delta. The census hasn’t published an earlier F share or an earlier dead count for either zone, and without those there’s no move to print. The rule for what the census will and won’t compare across editions is written out on the method page, and the short form is that the census prints a presence count over a moving population for transparency and never quotes it as a trend.

What the three-edition trend lines can and can’t do for a zone

The census does publish trend lines across July, August and September, and for a registry they look like the obvious place to go.

They’re built on a cohort of TLDs present in all three editions, and each line quoted as a trend uses a denominator that is itself an observed record set in the same edition: the DMARC policy mix over domains with a DMARC record, the SPF qualifier mix over domains with an SPF record, the TLS version over completed handshakes, HSTS and CSP over pages that answered. That construction is what makes them safe to quote, because the population being counted is the population that produced the record.

Those lines describe the cohort as a whole and none of them is per zone, so they say nothing about .nl or .fr. DKIM is left out of the trend lines altogether. If someone hands you a per-zone DMARC adoption trend built from this census, they built it from the transparency lines, and those carry the composition warning printed beside them.

The sentence to use when someone quotes the jump at you

You’ll be asked about it. A board pack or a journalist’s email will put the movement in front of you and ask what your registrants did, and one reply holds up: “The September edition of the census removed domains that no longer resolve before grading, so what moved is the inventory being counted, and the September figure is the one to quote.”

Then quote the September composition from the top of this piece, with the denominator said out loud. Domains carrying a grade in the September edition is the phrase, and it matters because the next question will be about it.

What you shouldn’t say is that registrants improved. You don’t know that from the grade share, and neither does the census. A zone can grade better because names went dead and left, because the source list changed, because a large parking operator moved its records, or because registrants published DMARC. The grade share alone doesn’t separate those four, and claiming the last one while the first three are in play is the kind of statement that gets corrected in public.

What to ask for instead of the grade share

If you want to compare months, ask for the disposition split rather than the grade share. Each edition sorts each scanned name into graded, indeterminate, unreachable or dead before any grade exists, and the size of each bucket tells you what the population did. If the dead and unreachable buckets shrank while graded held steady, the counting changed. If graded grew and the mix inside it moved, you have a reason to look at registrant behaviour.

The parked names in your zone deserve the same split. A parked name that still resolves gets graded, and a parking page that publishes no mail policy while the name still accepts mail is a spoofing surface; why parked domains can be spoofed walks through it. A zone with a large parked share can carry a high F share that says little about its active registrants, which is one more reason the grade share is a poor thing to compare.

It also helps to know which source lists fed your zone this month. A ccTLD registry is the one party that knows the true size of its zone, and when the census count and the zone count disagree, the difference is the composition effect in raw form, which only the registry is placed to measure.

Check one name in your zone the same way

The fastest way to see what the grade is made of is to run one domain from your zone through the scan and read the checks it fails. The scan uses the same measurement as the census, so the report you get for a single name is the report that rolled up into the September composition.

Pick a name you know is live and well run, and one you know is parked. The difference between the two reports is the composition effect at the scale of two domains, and it’s a demonstration you can put in front of a board that a zone’s number is a sum of names in very different states. The scan is free, and the parked report will show which records a registrant would need to publish to move that name out of F.

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Census numbers move every month; the current values are on the census data page.