Defaults.Exposed › September 2026 census › v10 registry
Methodology v10: the 34-check registry
Methodology v10 · 34 checks (25 scored + 9 informational) · census as of September 5, 2026
This is the versioned, citable registry of every check in the Defaults.Exposed grading methodology.
Each check has a permanent canonical ID and a stable URL, cite /v10/methodology/<check-id>
and it will keep meaning the same thing. Prevalence figures are computed from the census of
316,600,902 graded domains in the September 2026 edition and are
pinned to it; the check definitions are frozen for v10.
Machine-readable: /v10/methodology/checks.json ·
Headline statistics: /v10/data ·
Licence: open data ·
The edition these figures come from: September 2026 census →
How checks become a grade
25 of the 34 checks carry points; 9 are informational and never move the grade. Every check returns pass, fail, or N/A — the no-data rule: when a check couldn't be determined (timeout, SERVFAIL, redacted source) it is excluded from that domain's scoring denominator rather than counted as a failure. "Determined absent" (no DMARC record, no HTTPS) is a real fail. Grade bands are locked for comparability: A+ ≥ 95% · A ≥ 90% · B ≥ 80% · C ≥ 70% · D ≥ 60% · F below 60%.
Email Security
| Canonical ID | Check | Grade impact | Census prevalence (as of September 5, 2026) | Fix guide |
|---|---|---|---|---|
spf-exists | SPF record | Scored | 46.4% of graded domains publish a syntactically valid SPF record | /fix/spf |
spf-policy-strength | SPF policy strength | Scored | 18.2% of graded domains publish SPF with a hardfail (-all) policy | /fix/spf |
dmarc-policy | DMARC policy | Scored | 11.6% of graded domains publish an enforcing DMARC policy (p=quarantine or p=reject) | /fix/dmarc |
dmarc-reporting | DMARC reporting | Scored | 9.80% of graded domains publish a DMARC record with an aggregate-reporting (rua) address | /fix/dmarc |
dkim-exists | DKIM | Scored | 50.1% of domains where a DKIM selector could be determined publish one | /fix/dkim |
mx-record | MX records | Scored | 54.7% of graded domains publish at least one MX record | /fix/mx |
reverse-dns | Reverse DNS (PTR) | Scored | 77.8% of domains with a mail-relevant address have a PTR (reverse DNS) record | /fix/reverse-dns |
TLS & Certificates
| Canonical ID | Check | Grade impact | Census prevalence (as of September 5, 2026) | Fix guide |
|---|---|---|---|---|
https-available | HTTPS available | Scored | 67.0% of graded domains serve over HTTPS | /fix/https |
cert-valid | Certificate valid | Scored | 89.1% of HTTPS-serving domains present a valid, trusted certificate | /fix/certificate |
cert-expiry-warning | Certificate expiry | Scored | not published per-check in the census rollup | /fix/certificate |
cert-signature-algorithm | Signature algorithm | Scored | not published per-check in the census rollup | /fix/certificate |
cert-key-strength | Key strength | Scored | not published per-check in the census rollup | /fix/certificate |
tls-version | TLS version | Scored | 100.0% of HTTPS-serving domains negotiate TLS 1.2 or 1.3 | /fix/tls |
cipher-strength | Cipher strength | Scored | not published per-check in the census rollup | /fix/tls |
tls-compression | TLS compression | Informational | not published per-check in the census rollup | /fix/tls |
ocsp-stapling | OCSP stapling | Informational | not published per-check in the census rollup | /fix/tls |
secure-renegotiation | Secure renegotiation | Informational | not published per-check in the census rollup | /fix/tls |
Web Security
| Canonical ID | Check | Grade impact | Census prevalence (as of September 5, 2026) | Fix guide |
|---|---|---|---|---|
hsts-header | HSTS | Scored | 21.1% of HTTPS-serving domains send an HSTS header | /fix/hsts |
http-to-https-redirect | HTTP→HTTPS redirect | Scored | not published per-check in the census rollup | /fix/https |
csp-header | Content-Security-Policy | Scored | 10.1% of graded domains send an effective Content-Security-Policy header | /fix/csp |
x-frame-options | Clickjacking protection | Scored | 15.3% of graded domains send clickjacking protection (X-Frame-Options or CSP frame-ancestors) | /fix/clickjacking |
x-content-type-options | MIME-sniffing protection | Scored | 17.8% of graded domains send X-Content-Type-Options: nosniff | /fix/mime-sniffing |
referrer-policy | Referrer-Policy | Scored | 7.91% of graded domains send a Referrer-Policy header | /fix/referrer-policy |
coop-header | COOP (Cross-Origin-Opener-Policy) | Informational | not published per-check in the census rollup | /fix/cross-origin-headers |
corp-header | CORP (Cross-Origin-Resource-Policy) | Informational | not published per-check in the census rollup | /fix/cross-origin-headers |
coep-header | COEP (Cross-Origin-Embedder-Policy) | Informational | not published per-check in the census rollup | /fix/cross-origin-headers |
DNS Security
| Canonical ID | Check | Grade impact | Census prevalence (as of September 5, 2026) | Fix guide |
|---|---|---|---|---|
caa-record | CAA records | Scored | 1.38% of graded domains publish a CAA record | /fix/caa |
dnssec-ds | DNSSEC (DS) | Scored | 6.86% of graded domains have a valid, fully validating DNSSEC chain | /fix/dnssec |
dnssec-dnskey | DNSSEC (DNSKEY) | Scored | 6.86% of graded domains have a valid, fully validating DNSSEC chain | /fix/dnssec |
nameserver-diversity | Nameserver diversity | Scored | not published per-check in the census rollup | /fix/nameservers |
soa-configuration | SOA configuration | Scored | not published per-check in the census rollup | /fix/nameservers |
ipv6-support | IPv6 support | Informational | 21.8% of graded domains publish an AAAA (IPv6) record | /fix/ipv6 |
Infrastructure
| Canonical ID | Check | Grade impact | Census prevalence (as of September 5, 2026) | Fix guide |
|---|---|---|---|---|
cdn-waf-detection | CDN / WAF detection | Informational | not published per-check in the census rollup | /fix/infrastructure |
hosting-provider | Hosting provider | Informational | not published per-check in the census rollup | /fix/infrastructure |
Cite this registry
Check definitions are stable for methodology v10 and the prevalence figures are pinned to the September 2026 census. Please cite Defaults.Exposed and link the check's stable URL.
Defaults.Exposed, "Grading Methodology v10" (census as of September 5, 2026). https://defaults.exposed/v10/methodology
Permalink: https://defaults.exposed/v10/methodology ·
Machine-readable: /v10/methodology/checks.json ·
Per-check anchors: https://defaults.exposed/v10/methodology/<check-id>
Prevalence numbers are aggregates across the whole census, never a named third party's result. This edition is pinned; the next census publishes its own registry.