Defaults.Exposed › September 2026 census › Data
Domain security statistics: September 2026 (v10)
As of September 2026, 74.2% of 317M graded domains score an F, and fewer than 0.20% score an A in the Defaults.Exposed September 2026 census of 347,691,016 domains across 1,433 TLDs.
This is a permanently pinned snapshot of the September 2026 (v10) census. Every figure below is dated and individually linkable. Download the underlying aggregates as /v10/data/census.json or /v10/data/tld-grades.csv, or explore interactively at Census Explorer.
Grade distribution
As of September 2026 · September 2026 (v10)
¶ The census reached 1,433 top-level domains. 497 of them clear the reporting floor and are broken out here; the remaining 936 are too small for a percentage to be stable, so they are counted in the totals but not broken out.
¶ As of September 2026, the September 2026 (v10) census has graded 316,600,902 domains (317M) drawn from 347,691,016 scanned domains (348M) across 1,433 TLDs.
¶ 74.2% of graded domains score an F, 234,955,475 domains.
¶ Fewer than 0.20% score an A or A+ (627,144 domains); an A+ is rarer still at 0.03%.
¶ 0.4% of scanned domains no longer resolve (1,389,076 dead domains). The share is taken over everything scanned, which is the denominator the sentence names.
Email authentication
As of September 2026 · September 2026 (v10)
¶ Only 11.6% of domains publish an enforcing DMARC policy (quarantine or reject).
¶ 75.2% have no DMARC record at all, leaving them open to email spoofing.
¶ 47.4% publish an SPF record; 52.6% publish none.
¶ 50.1% of the 75,823,110 domains where DKIM could be determined publish a discoverable selector. It could not be determined for the other 240,777,792, because the census probes a fixed list of common selectors, so treat this as a floor rather than a DKIM adoption rate.
DNS & infrastructure
As of September 2026 · September 2026 (v10)
¶ Only 6.9% of domains have a valid DNSSEC chain; a further 0.1% are signed but broken.
¶ 1.4% publish a CAA record restricting which CAs may issue their certificates.
¶ 21.8% publish an AAAA record (IPv6-reachable).
TLS & web security
As of September 2026 · September 2026 (v10)
¶ 67.0% of domains serve over HTTPS.
¶ Of domains serving HTTPS, 89.1% present a valid, trusted certificate (59.7% of all graded domains).
¶ 94.4% of HTTPS-serving domains negotiate TLS 1.3; 5.6% top out at TLS 1.2.
¶ Only 21.1% of HTTPS-serving domains send an HSTS header (14.1% of all graded domains).
Cite this
Statistics from the September 2026 (v10) census. This URL is permanently pinned, figures will never change.
Defaults.Exposed, "Domain Security Census: September 2026 (v10)" (as of September 2026). https://defaults.exposed/v10/data
Permalink: https://defaults.exposed/v10/data · Machine-readable: /v10/data/census.json, /v10/data/tld-grades.csv · Licence: open data
Explorer: /v10/explore, filter by TLD + security check, shareable permalinks · Methodology: /v10/methodology · Edition hub: /v10
This is the current edition data page. It is pinned to the September 2026 census and never moves; the next edition gets its own address.