Defaults.Exposed

Defaults.ExposedSeptember 2026 census › Data

Domain security statistics: September 2026 (v10)

As of September 2026, 74.2% of 317M graded domains score an F, and fewer than 0.20% score an A in the Defaults.Exposed September 2026 census of 347,691,016 domains across 1,433 TLDs.

This is a permanently pinned snapshot of the September 2026 (v10) census. Every figure below is dated and individually linkable. Download the underlying aggregates as /v10/data/census.json or /v10/data/tld-grades.csv, or explore interactively at Census Explorer.

Grade distribution

As of September 2026 · September 2026 (v10)

The census reached 1,433 top-level domains. 497 of them clear the reporting floor and are broken out here; the remaining 936 are too small for a percentage to be stable, so they are counted in the totals but not broken out.

As of September 2026, the September 2026 (v10) census has graded 316,600,902 domains (317M) drawn from 347,691,016 scanned domains (348M) across 1,433 TLDs.

74.2% of graded domains score an F, 234,955,475 domains.

Fewer than 0.20% score an A or A+ (627,144 domains); an A+ is rarer still at 0.03%.

0.4% of scanned domains no longer resolve (1,389,076 dead domains). The share is taken over everything scanned, which is the denominator the sentence names.

Email authentication

As of September 2026 · September 2026 (v10)

Only 11.6% of domains publish an enforcing DMARC policy (quarantine or reject).

75.2% have no DMARC record at all, leaving them open to email spoofing.

47.4% publish an SPF record; 52.6% publish none.

50.1% of the 75,823,110 domains where DKIM could be determined publish a discoverable selector. It could not be determined for the other 240,777,792, because the census probes a fixed list of common selectors, so treat this as a floor rather than a DKIM adoption rate.

DNS & infrastructure

As of September 2026 · September 2026 (v10)

Only 6.9% of domains have a valid DNSSEC chain; a further 0.1% are signed but broken.

1.4% publish a CAA record restricting which CAs may issue their certificates.

21.8% publish an AAAA record (IPv6-reachable).

TLS & web security

As of September 2026 · September 2026 (v10)

67.0% of domains serve over HTTPS.

Of domains serving HTTPS, 89.1% present a valid, trusted certificate (59.7% of all graded domains).

94.4% of HTTPS-serving domains negotiate TLS 1.3; 5.6% top out at TLS 1.2.

Only 21.1% of HTTPS-serving domains send an HSTS header (14.1% of all graded domains).

Cite this

Statistics from the September 2026 (v10) census. This URL is permanently pinned, figures will never change.

Defaults.Exposed, "Domain Security Census: September 2026 (v10)" (as of September 2026). https://defaults.exposed/v10/data

Permalink: https://defaults.exposed/v10/data · Machine-readable: /v10/data/census.json, /v10/data/tld-grades.csv · Licence: open data

Explorer: /v10/explore, filter by TLD + security check, shareable permalinks · Methodology: /v10/methodology · Edition hub: /v10

This is the current edition data page. It is pinned to the September 2026 census and never moves; the next edition gets its own address.