Fully Protected Domains: 1 in 39 — Two Definitions (2026)
Опубліковано · оновлено
Figures as of 2026-07-29 · methodology v8. This page shows aggregate census data. We never publish any individual domain’s status or grade. Per-check percentages are shares of the domains we could evaluate on that check. Dead domains grade F but cannot be evaluated. The headline club figure is the one exception: we quote it against all graded domains, dead included, and explain why below. See how we grade.
At least one domain in every 39 runs the complete core email-authentication stack with enforcement switched on. One in every 330 holds all five controls the census scores. The first number is a floor: our DKIM probes cannot find every signing key, so the real count may be higher. Both numbers come from the same census edition: 296,674,837 domains graded as of 2026-07-29, with every check matched up domain by domain. But the two numbers do not share a base. The email figure covers every graded domain. The five-control figure counts only the domains alive enough to be evaluated on all five checks. Both get quoted as “the fully protected club”. They are not the same club. They are two different membership tests, and this page defines each one precisely, so neither number gets stretched to cover the other.
”Fully protected” vs “fully locked”: the two definitions
| Definition A — the club | Definition B — fully locked | |
|---|---|---|
| What it measures | The complete email stack, enforced | The strictest five-of-five exposure score |
| Membership test | SPF present and DKIM present and DMARC at quarantine/reject | SPF and enforcing DMARC and DNSSEC and HTTPS and HSTS |
| Members this edition | 7,678,989 | 834,509 |
| Base | All 297 million graded domains | Domains evaluated on all five checks — dead domains excluded |
| Odds | one in 39 | one in 330 |
When you see “one in 39” quoted, that is Definition A. “One in 330” is Definition B. Neither is wrong. But swap one number onto the other’s base and both become false. We quote Definition A against every graded domain, because the club stat describes the full census population. Recompute it on Definition B’s base instead, counting only the evaluated domains, and the club’s odds shorten a little. That is because dead domains cannot pass any email check. Either way, the gap between the two definitions stays close to a factor of ten. Which test does your domain pass? Run the free check. The answer is instant and stays private.
What counts as a fully protected domain? (SPF + DKIM + enforcing DMARC)
Definition A is the census’s email bar. All three of the following must hold on the same domain at the same time:
- an SPF record is published. SPF is the DNS record that lists which servers may send mail as the domain.
- a DKIM signing key we can find in DNS. DKIM puts a cryptographic signature on outgoing mail. We probe the common provider selectors, the key names most email services use. A domain that signs only under a custom selector can slip past us, which is why this count is a floor. See how we grade.
- DMARC is published and set to an enforcing policy:
p=quarantineorp=reject. DMARC is the record that tells receiving servers what to do with mail that fails the other two checks.
That is the complete email-authentication stack with the switch actually flipped. Receiving servers are told to quarantine or refuse forged mail carrying the domain’s name, not just report it. Receivers may still apply their own local policy. 7,678,989 domains clear the bar this edition — 8 million, or 2.79% of the 297 million graded. One in 39. Enforcement carries a side benefit, too. BIMI, the standard that displays your logo in supporting inboxes, requires DMARC at quarantine or reject.
Note what Definition A does not test: the web and DNS tiers. A club member can still lack DNSSEC or skip HSTS. Definition A measures depth. It takes one attack surface, exact-domain email impersonation, and asks whether its designed defence is fully deployed and enforced. This page is only about the yardstick. For who these domains are, see which domains actually make the club.
What counts as fully locked? (SPF, DMARC, DNSSEC, HTTPS, HSTS)
Definition B is the top rung of the census exposure score. Every domain the census can evaluate on all five checks earns a point for each control it holds: SPF, enforcing DMARC, DNSSEC, HTTPS, and HSTS. DNSSEC signs a domain’s DNS records so resolvers can verify them. HSTS is the header that tells browsers to connect over HTTPS only. Dead domains grade F but cannot be evaluated, so they sit outside this ladder. Score five out of five and the domain is fully locked. That is 834,509 domains this edition — one in every 330 of the domains evaluated.
The two tests share a core: SPF plus enforcing DMARC. But neither contains the other. Definition A adds DKIM and stops at email. Definition B skips the DKIM test and demands the DNS and web tiers too. B measures breadth: every layer the score counts, locked at once. DNSSEC does most of the thinning. Valid signatures sit on just 6.28% of evaluated domains. That scarcity is much of the reason the fully-locked population is roughly a tenth the size of the club.
How many of the five controls does a typical domain hold?
Put every evaluated domain on the exposure-score ladder and the internet takes shape:
| Controls in place | Domains this edition | What that usually looks like |
|---|---|---|
| Zero — fully exposed | 23,298,293 | No SPF, no enforced DMARC, no DNSSEC, no HTTPS, no HSTS |
| One | 107,302,883 | HTTPS alone — the control that arrives by default |
| Two | 108,519,087 | HTTPS plus SPF — the pair every setup guide covers |
| Three | 29,461,853 | A first deliberate step beyond the defaults |
| Four | 6,249,650 | Everything except one final control |
| Five — fully locked | 834,509 | All five controls, deliberately deployed |
The middle rungs tell the story. Protection plateaus at whatever hosting providers and setup guides switch on automatically. Almost every rung above two needs an owner to take a step nobody took for them. The main exception is DNSSEC, in the handful of country-code TLDs where registrars sign zones by default. At each of those deliberate steps, the population collapses.
Which rung is your domain on? Run the free check.
Why do so many domains publish DMARC but so few enforce it?
The collapse has a precise mechanism, and DMARC shows it most clearly. 74.20% of evaluated domains publish no DMARC record at all. Of the minority that do publish one, 54.1% sit at p=none. That is how publishing collapses to 11.83% of evaluated domains enforcing. For contrast: 51.24% of evaluated domains publish SPF. Publishing a record is common. Enforcing a policy is not.
Publishing is quick: you paste a record from your provider’s guide and you are done. Enforcement is a project. You publish DMARC at p=none with reporting. You collect the reports and identify every legitimate sender. Only then do you flip to quarantine or reject, and a mistake there can block your own invoices. A p=none record asks receivers to take no action. It is a subscription to bad news, not a defence. So most owners stop at the step that feels finished, and never take the one that actually finishes the job.
Repeat that publish-to-enforce gap across five separate controls, and you have the whole reason both clubs are small.
What this means for your business
The club is small for one reason: for almost every domain, membership is manual. The ladder above shows the result. Most domains hold only the controls that arrive switched on by default, and no common provider setup ships all five together. HTTPS shows what happens when even one control gets automated. Hosts and CDNs switched it on for everyone, and it became near-universal on actively served websites. It is now the one control most domains on the ladder hold. Defaults, again.
Four blunt conclusions follow from the data.
At one in 39, the odds say any given counterparty’s domain lacks the enforced stack designed to block exact-domain impersonation. Assume that until you know otherwise, and verify every payment-detail change through a second channel — a phone number already on file, never one taken from the email. Business email compromise is consistently among the costliest cybercrime categories in FBI IC3 reporting. One redirected invoice can erase a year of margin. An enforced email stack costs nothing but attention, and it closes one of the attacker’s cheapest routes: sending as your exact domain. It does not stop lookalike domains or compromised mailboxes, which is why the second channel is never optional. The same odds say your own domain is outside the club too, until you check.
Membership is also a differentiator that carries no licence fee. Only 2.79% of graded domains qualify. On this edition’s numbers, “we run the full enforced email stack — SPF, DKIM and enforcing DMARC” is a claim few counterparties could match. Verify your own configuration before you write it anywhere. The free check tells you whether you can put that claim on your next security questionnaire or cyber-insurance form, and exactly what stands between you and it if you cannot.
The direction of travel is enforcement. Google’s and Yahoo’s bulk-sender rules already require DMARC from large senders. The lever is deliverability: unauthenticated mail increasingly lands in spam or gets refused outright. Enforce today and you stand with the 11.83% who are already beyond the current minimum.
Target Definition A before B. The fraud that reaches a normal business arrives as a forged invoice in an inbox, not a poisoned DNS answer. Close that door first, then go completionist. That risk-first sequencing, worked out for your specific domain, is what the A-Grade Playbook turns your free scan into.
How to join the club: SPF, DKIM, then DMARC enforcement
First, find out which steps you actually need. Run the free check. It shows which of the five controls you already hold. Then work through the rest in order. Every step is a DNS record or a server header:
- SPF — publish one record listing your real senders, ending
-all. (Fix SPF →) - DKIM — turn on signing in every service that sends mail as you. For most services, that is a checkbox in the sending settings plus one DNS record. (Fix DKIM →)
- DMARC — publish at
p=nonewith reporting, watch the reports, then enforce. This is the wall where DMARC publishers become the 11.83% who enforce. It costs attention, not money. If attention is the one thing you cannot spare, the A-Grade Playbook turns your scan into an exact, sequenced runbook for your domain. (Fix DMARC →)
That is Definition A: the one-in-39 club. For Definition B, add HSTS on your HTTPS site, then DNSSEC through a provider that manages the signing for you.
Run the free domain security check. It scans your domain in seconds, shows every control you pass, and gives step-by-step guidance for the ones you don’t. It never publishes your result. The club admits new members every day; the paperwork is DNS.
Quick answers
How many domains have every core email protection in place? One in 39. In the 2026-07-29 census edition, 7,678,989 of the 297 million graded domains (2.79%) run SPF, DKIM and an enforcing DMARC policy together.
How many domains hold all five core protections at once? 834,509 domains — one in every 330 of those evaluated on all five checks. In the 2026-07-29 edition they score five out of five on the census exposure score: SPF, enforcing DMARC, DNSSEC, HTTPS and HSTS, all at the same time.
What share of domains enforce DMARC? In the 2026-07-29 edition, 11.83% of evaluated domains set DMARC to quarantine or reject. Of the DMARC records that are published, 54.1% still sit at p=none. For contrast, 51.24% of evaluated domains publish SPF. Publishing is common; enforcement is not.
How do I check whether my own domain qualifies? Run the free check at defaults.exposed. It tests all five controls (SPF, DMARC enforcement, DNSSEC, HTTPS and HSTS) and keeps the result to you.