The September 2026 edition: how 347,691,016 domains were counted
You’re about to write “347,691,016 domains” into a report and you want to know what that number counts before somebody asks. It counts the domains the September 2026 edition of the defaults.exposed census scanned: the names three independent feeds carried, after an existence pass removed the ones that no longer resolve and the ones a wildcarded top-level domain invents on demand. So the number describes one edition’s scanned universe, produced on a stated date by a stated method, and it won’t support a wider claim than that.
It isn’t the size of the internet, because many registries publish no zone file and a name no feed has observed can’t be counted. What the number comes with is a ledger you can check, in the order it happened: a sourced total, two subtractions, a scanned total, and four dispositions that account for each scanned name.
Where the names came from
Three feeds contribute names. Zone files give the registered names for the top-level domains whose registries publish them, which is the closest thing to a registry-issued list that exists. DNS measurement data adds names observed in active resolution, which reaches domains under registries that don’t publish. Web crawl data brings in the hostnames found in page links, adding names neither of the others has seen, including under country-code TLDs with no public zone at all.
The three lists overlap heavily, so the census unions them and a name that appears in all three counts once. Before the union it normalises each name to one form, because an internationalised domain can arrive from one feed in Unicode and from another in its punycode encoding, and those are the same registration. The census counts registrable domains, so a hostname from the crawl counts for the domain it sits under, once.
That union came to 516,856,999 names. That figure sits at the top of the ledger, and you shouldn’t quote it on its own, because a large part of it doesn’t exist.
Line one: 154,021,121 names that don’t exist
The existence pass asks the DNS one question per name: does this name exist? A registered domain has a delegation at its parent, so a query for it returns something, even if that something is only a referral or an empty answer. A name that sat in a zone file until it expired, or that a crawl saw in a link that was already stale, returns NXDOMAIN, the authoritative “no such name”.
154,021,121 names in the sourced list returned NXDOMAIN and were removed before scanning. No other line in the ledger is as large, which is why a raw feed total is the wrong number to cite. Zone files carry names right up to the moment they’re dropped, crawl data carries links to sites that shut years ago, and a measurement feed remembers names it resolved once. None of those feeds is wrong about what it saw; each recorded a name as it stood on its own day, and the existence pass re-checks the whole list on a single date instead.
Line two: 15,109,274 wildcard phantoms
A few registries configure their top-level zone with a wildcard, so a query for any name under that TLD returns an address whether or not the name was registered. Under such a TLD the existence pass can’t say no. A name nobody registered resolves, would get scanned, and would get a grade for a website that is the registry’s catch-all page. Left in, those names inflate the total and distort the grade shares of the TLD they sit under.
The census tests each TLD for wildcard behaviour by querying random names under it that can’t have been registered and seeing whether they resolve. Where they do, the census records the answer the wildcard gives and treats any sourced name under that TLD which resolves only to that same answer as a phantom. It removed 15,109,274 names this way, before scanning.
A scrape would have kept those names, since they answered. The census asks instead whether the same answer would have come back for a name nobody registered, and drops the ones where it would.
What was left: 347,691,016 domains across 1,433 TLDs
Sourced, minus the NXDOMAIN names, minus the wildcard phantoms, leaves the scanned universe of 347,691,016 domains across 1,433 top-level domains. That’s the number in the title. Cite it with the word “scanned” next to it.
The September 2026 edition ran in two passes and finished on 2026-09-05. The first pass covers the full universe and either grades a domain or parks it. The second pass returns to the parked domains, so that one timed-out name server at three in the morning doesn’t decide a domain’s result for a month. Both passes ran against the same universe, so the total doesn’t move between them; what moves is how many domains end with a definite result.
Each figure on this page carries the date 2026-09-05 for that reason. The scanned universe is a fact about that day. Run the same three feeds and the same two subtractions a month later and each line will shift, which is why the edition is stated alongside the number wherever it’s quoted.
A scanned domain and a graded domain are different things
Scanning a domain means running the checks against it, from the delegation up through the DNS records that govern mail and the web server’s certificate and headers. Grading it means those checks returned enough to score. Confusing those two verbs is how a citation goes wrong, so the census records a disposition for each scanned domain, and there are four of them.
Graded, 315,211,826 domains (90.7%): the checks ran and the scorer had enough to grade. Indeterminate, 15,865,500: the domain answered, and after both passes the checks still hadn’t returned enough to grade. Unreachable, 15,224,614: the name is delegated, and nothing behind that delegation answered the scanner in either pass. Dead, 1,389,076 (0.40% of scanned): the delegation itself is broken, with the registry pointing at name servers that don’t serve the zone, so no record of any kind can be read.
Dead is the one bucket outside graded with a definite answer, and the census grades a dead domain F, because a domain in that state has published no protection of any kind. Unreachable sounds like a scanner fault, and the domain’s own configuration can put it there. A domain whose DNSSEC chain is broken answers SERVFAIL to any resolver that validates, and that failure puts a registered, paid-for domain into unreachable through no fault of the scan. Name servers that time out and firewalls that drop the scanner’s source ranges do the same, and the second pass exists to give those domains another chance before the bucket is final.
Your own domain has a disposition in this edition. The free scan runs the same checks the census ran, against today’s records rather than the 2026-09-05 snapshot, so you can see which bucket you’d land in now and why.
Two denominators, and which one your percentage needs
Shares on the data page rest on one of two bases, and a share needs the base it was computed on beside it, or it misleads in the same way as the sourced total quoted alone.
Grade shares, the proportion of domains at A+, A, B, C, D or F, use 316,600,902 as the denominator. That is the graded domains plus the dead ones, because a dead domain carries an F and belongs in the distribution. The checks themselves ran against the 315,211,826 graded domains, and some of them run on a subset again: a DKIM check needs a selector to look up and a TLS check needs a server that completed a handshake, so their n is smaller, and the data page states the n for each check beside its result.
So a sentence about the share of domains at F needs “of the 316,600,902 domains carrying a grade” beside it, and a sentence about a single check needs the n that check ran against. The DMARC page shows what that check reads from a record and what its states mean, and the TLS page does the same for the handshake, which is why the two are counted on different bases.
The wording to use when you cite it
Write the number with its verb and its date: “the September 2026 edition of the defaults.exposed census scanned 347,691,016 domains across 1,433 TLDs, as of 5 September 2026”. If the point you’re making is about grades, cite the graded plus dead base; if it’s about one check, cite that check’s n. Don’t describe the scanned universe as the number of domains on the internet, and don’t set it against an earlier edition’s total, because the feeds, the wildcard list and the existence pass all move between editions, and the difference would reflect those changes as much as any change in the internet.
The full ledger, each check’s n and the machine-readable files behind them are on the September 2026 census data page, refreshed when the next edition runs. Link to that page when you’re citing the figure, and to this one when you’re explaining the method.
Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Census numbers move every month; the current values are on the census data page.