Do Registry Rules Work? .bank 3.1% F vs .com 72.4%
Published
Figures as of 16 August 2026 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.
The headline: rules beat the open market by 23×
In the August 2026 census, 3.1% of graded .bank domains earn an F. In .com, the figure is 72.4%. Same internet, same checks, same grading. The only structural difference is that one registry publishes security requirements its registrants must meet, and the other sells to anyone with a card.
That is a 23× gap, and it is not a fluke of one TLD. .insurance, run under the same security regime as .bank, posts a 9.9% F rate on a much smaller base. Both put a majority of their domains at grade B or better — 60.0% for .bank, 59.4% for .insurance — in a namespace where the global B-or-better rate is a rounding error. .com manages 2.0%.
But the interesting result is not that mandates work. It is the control group that proves why they work. .pharmacy also gates who may register: every registrant is vetted as a legitimate pharmacy operation. It imposes no comparable technical requirements. Its F rate is 84.5% — worse than .com. Checking who you are does nothing for your DNS. Only rules about configuration move configuration.
Key numbers
- .bank domains grade F at 3.1% (63 of 2,010 graded); .com grades F at 72.4% (101,970,017 of 140,810,926) — a 23× gap, August 2026 census.
- 98.2% of graded .bank domains publish DMARC at p=reject, versus 4.7% of .com — a 21× enforcement gap.
- 99.9% of .bank and 100% of graded .insurance domains have valid DNSSEC, versus 4.6% of .com and 1.3% of .xyz.
- .pharmacy — vetted registrants, no technical mandates — grades 84.5% F, worse than the open .com market it was supposed to be safer than.
- Rules move only what they name: CSP adoption on .bank is 9.1% versus 9.4% on .com — statistically identical, because no rule requires it.
- .gov sits in the middle: 60.0% of graded domains carry a DMARC policy, 28.0% grade F — a mandate that binds only part of the registrant base produces a partial result.
The natural experiment nobody had to design
Registries run three different admission regimes, and the August 2026 census lets us score all three against the same 34 checks.
Open registration. .com and .xyz sell to anyone. No identity checks, no configuration requirements. This is most of the internet.
Vetted registrants. .pharmacy verifies that you are a legitimate pharmacy before you can register. (Registry policy details here and below are public industry record, not census measurement.) The gate is about who you are, not what you configure.
Vetted registrants plus technical mandates. .bank and .insurance, operated under fTLD’s security requirements, verify eligibility and require specific technical controls — DNSSEC signing, email authentication, TLS — as a condition of keeping the domain. .gov restricts registration to US government bodies, and a subset of its registrants (federal executive-branch agencies) have been under binding security directives, including the 2017 DMARC-enforcement order BOD 18-01, for years.
Three regimes, one measurement pass. Here is the full grade distribution.
What does each regime’s report card look like?
Grade distribution per TLD, graded domains only (denominators in the table; grades A+ through F under census methodology v9):
| TLD | Regime | Graded | A+/A | B | C | D | F |
|---|---|---|---|---|---|---|---|
| .bank | vetting + mandates | 2,010 | 15.1% | 44.9% | 30.9% | 5.9% | 3.1% |
| .insurance | vetting + mandates | 101 | 13.9% | 45.5% | 16.8% | 13.9% | 9.9% |
| .gov | restricted + partial mandates | 14,071 | 4.2% | 13.3% | 27.7% | 26.7% | 28.0% |
| .com | open | 140,810,926 | 0.2% | 1.9% | 7.5% | 18.0% | 72.4% |
| .pharmacy | vetting, no mandates | 1,119 | 0.2% | 1.3% | 4.5% | 9.7% | 84.5% |
| .xyz | open | 7,728,016 | 0.03% | 0.2% | 1.1% | 9.6% | 89.1% |
Read the table top to bottom and the pattern is blunt. The two TLDs with technical mandates sit in a different universe: a randomly chosen .bank domain is about 30 times more likely to reach B or better than a .com domain (60.0% vs 2.0%). The restricted-but-partially-mandated .gov lands in the middle. And .pharmacy — the vetted TLD without configuration rules — lands below the open market.
One honesty note on sample sizes before anyone builds a slide out of this: .insurance has 101 graded domains and .pharmacy 1,119. Percentages on bases that small carry real noise. .bank’s 2,010 is sturdier, .gov’s 14,071 sturdier still, and the .com and .xyz columns rest on 148 million domains between them. The ordering survives any reasonable error bars; the second decimal place does not.
Which checks do the mandates actually move?
Grades summarise. The per-check data shows the mechanism. These are the controls fTLD’s requirements and the .gov directives explicitly name — DNSSEC and DMARC — measured per graded domain:
| TLD | Valid DNSSEC | DMARC (any policy) | DMARC at p=reject |
|---|---|---|---|
| .bank | 99.9% | 99.0% | 98.2% |
| .insurance | 100% | 98.0% | 97.0% |
| .gov | 11.7% | 60.0% | 19.0% |
| .com | 4.6% | 23.5% | 4.7% |
| .pharmacy | 1.2% | 10.1% | 6.5% |
| .xyz | 1.3% | 8.6% | 4.1% |
The .bank column is what compliance looks like when the registry can pull your domain. 2,008 of 2,010 graded .bank domains have valid DNSSEC. 1,973 publish DMARC at p=reject — not p=none monitoring theatre, actual enforcement. Across the whole graded .com zone, we found 6.57 million domains at p=reject. As a share of the zone: 4.7%. The .bank rate is 21 times higher.
And .pharmacy’s row reads like any open TLD’s. DNSSEC at 1.2% is below .com. A registrant-vetting programme rigorous enough to keep rogue pharmacies out has no detectable effect on whether anyone signs a zone or publishes a DMARC record. Nobody asked, so nobody did.
Rules move only what they name
Here is the finding that should temper any enthusiasm for mandates as a cure-all. We checked the controls that no registry requires — the web-hardening layer — on the same domains:
| TLD | HSTS (of HTTPS sites where measured) | CSP (where measured) | CAA record |
|---|---|---|---|
| .bank | 22.9% | 9.1% | 4.2% |
| .com | 26.7% | 9.4% | 1.2% |
| .gov | 27.6% | 7.2% | 2.7% |
| .xyz | 10.3% | 2.9% | 0.6% |
Look at the CSP column. .bank — the best-run TLD in this census by a mile — deploys Content-Security-Policy at 9.1%. .com deploys it at 9.4%. The most heavily regulated registrant population on the internet and the open market are statistically identical on the one header nobody ordered them to set. On HSTS, .bank actually trails .com slightly.
The compliance boundary is a hard edge. Domains under mandate do exactly what the mandate says, to near-total coverage, and then stop. There is no spillover effect where a security-conscious registrant, having signed their zone under compulsion, spontaneously hardens their headers. The 3.1% F rate is not evidence that .bank registrants are security enthusiasts. It is evidence that the graded checks weight the fundamentals — DNS integrity, email authentication, TLS — and the mandate covers the fundamentals. Where the rulebook ends, .bank is ordinary.
For policy people, that cuts both ways. It means a mandate is a scalpel, not a culture change: you get precisely the controls you write down. It also means writing them down works, at 98–100% coverage, which no awareness campaign in the history of the industry has ever approached.
Why is .gov stuck in the middle?
.gov looks like a puzzle: registration restricted to government bodies, binding federal directives since 2017, and still a 28.0% F rate with DNSSEC at just 11.7%.
The likely resolution is scope, and it needs the industry-context label: BOD 18-01 and its successors bind US federal executive-branch agencies. The .gov zone also contains thousands of state, county, city, tribal and territorial registrants that no federal directive reaches. Our census sees the whole zone, not the federal slice, so the 60.0% DMARC-with-policy figure blends a heavily-directed population with a merely-eligible one. We cannot split federal from municipal in our data — registrant class is not externally observable — so treat .gov’s middle position as consistent with partial-coverage mandates rather than proof of them.
Even so, the blended zone publishes DMARC at 2.6× the .com rate and reaches p=reject at 4× the .com rate. A mandate that covers part of a population still shows up in the aggregate. It just cannot carry the whole zone to .bank’s numbers.
The half of .bank that doesn’t exist
One more number from the same files, on a different denominator. The census inventory carries 4,659 .bank names, of which 2,336 — 50.1% — are dead: no functioning delegation to measure. .insurance is the same shape: 166 of 327 inventoried names, 50.8%, dead. Compare .com at 5.1% dead and .xyz at 2.1% (all on the inventory basis, not the graded basis used everywhere else in this article).
That reads like defensive registration: institutions buying their .bank name to keep others from having it, and never launching. It quietly flatters the headline stat — the graded 3.1% F rate describes the .bank domains that are actually live, a self-selected half of the zone. It also means the strictest namespace on the internet is, by volume, mostly empty shelf space.
So do registry rules work?
On the evidence of this census round: yes, precisely, and only precisely.
Mandates with teeth produce near-total compliance on the named controls — 98–100% on DNSSEC and DMARC enforcement in .bank and .insurance, against single digits in the open market. The grade gap that follows is the largest structural effect we have measured between comparable TLD populations: 3.1% F versus 72.4%.
Vetting without mandates produces nothing measurable. .pharmacy’s registrants are verified, legitimate, regulated businesses, and their domains are configured like everyone else’s — slightly worse than .com’s, on this round’s numbers.
And mandates do not travel. The unnamed controls sit at open-market levels even inside the strictest regime. If a future rulebook wants HSTS, it will have to say the word HSTS.
The practical corollary for everyone who can’t register a .bank domain: nothing in .bank’s winning column is exclusive. DNSSEC, DMARC at p=reject, valid TLS — every one is available on a .com for the cost of configuration, which is mostly zero. The .bank zone is what the whole internet would look like if anyone required it. Or if domain owners simply did, unrequired, what 2,008 banks did.
How we measured this
- Source: the August 2026 Defaults.Exposed census round (figures as of 16 August 2026, methodology v9) — 432 million domains scanned, more than 376.9 million graded across 34 externally observable checks.
- Denominator: unless stated otherwise, percentages are per graded domain within each TLD (graded-only basis): .bank 2,010 · .insurance 101 · .pharmacy 1,119 · .gov 14,071 · .com 140,810,926 · .xyz 7,728,016. The dead-domain paragraph uses the inventory basis and says so. The site’s headline F-rate uses a different, dead-inclusive basis; the two are never mixed here.
- Per-check rates come from per-TLD applicable-and-pass counts. HSTS and CSP rates use each check’s own applicable denominator (sites where the check could be evaluated), which is smaller than the graded count; DNSSEC and DMARC rates use the graded count.
- Small samples: .insurance (101) and .pharmacy (1,119) are small bases; percentages on them carry material noise. The cross-regime ordering is robust; fine-grained comparisons between the small TLDs are not.
- Vantage and limits: all measurements are external, from our EU scanning infrastructure, of the registrable domain. We observe published DNS records, TLS handshakes and HTTP responses; we cannot observe DKIM keys beyond selector guessing, internal controls, or registrant identity. A check “pass” reflects our tri-state methodology, not mere record presence.
- Registry-policy context is industry knowledge, not census data: fTLD’s security requirements for .bank/.insurance, NABP’s vetting model for .pharmacy, .gov eligibility rules and BOD 18-01’s federal-only scope are public record. We measured outcomes; we did not audit any registry’s enforcement, and we did not seek comment from any registry operator for this edition.
- No causal claim beyond the design: this is an observational comparison across TLD populations that differ in more than their rulebooks (registrant sophistication, budgets, institutional pressure). The .pharmacy control — vetted registrants, no mandates, open-market outcomes — is what lets us attribute the .bank/.insurance gap to the technical requirements rather than to vetting, but selection effects cannot be fully excluded.
- Aggregate only. We report TLD-level distributions. We never name, grade or publish data about an individual registrant’s domain.
- Data is stored and processed within the EU.
What this means
For IT managers and security teams evaluating vendor or partner domains, this data offers an immediately useful signal: a domain on .bank or .insurance is near-certain to have DNSSEC and enforcing DMARC in place, because the registry requires it. That makes TLD a reasonable first-pass indicator when triaging a supplier list — not a substitute for checking the actual domain, but a fast filter. Conversely, a .com or .xyz counterpart starts with no such guarantee, and the census confirms the baseline: fewer than 5% of .com domains have either control deployed correctly.
For organisations building or influencing security policy, the .pharmacy finding is the most practically important result in this article. Your organisation may be considering registration requirements, employee-computer policies, or supply-chain vetting programmes. The data says clearly: verifying identity without specifying configuration achieves nothing measurable. A security programme that tells people to comply without defining what compliance means technically will produce .pharmacy outcomes. The mandate has to name the control.
For any business on a .com or similar open TLD, the takeaway is simple but worth stating plainly: the protections .bank registrants are required to have are available to you today, for free, on your existing domain. DNSSEC signing, DMARC at p=reject, and valid TLS are not .bank exclusives. They are DNS records and a certificate. The gap this article documents is a configuration gap, not a product gap, and it closes the same way regardless of which TLD you’re on.
Data to cite
- “In the August 2026 census, 3.1% of graded .bank domains earn an F, compared to 72.4% of .com domains — a 23× gap produced entirely by registry-mandated technical controls.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “98.2% of graded .bank domains publish DMARC at p=reject, versus 4.7% of .com domains — a 21× enforcement gap driven by mandatory registry requirements.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “99.9% of graded .bank domains and 100% of graded .insurance domains have valid DNSSEC, compared to 4.6% of .com and 1.3% of .xyz domains.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “.pharmacy domains, whose registrants are vetted as legitimate pharmacies but face no technical configuration mandates, grade 84.5% F — worse than the open .com market.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “CSP adoption on .bank is 9.1% versus 9.4% on .com — statistically identical on the one security layer no registry mandate names.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “60.0% of graded .gov domains carry a DMARC policy and 28.0% grade F — the result of a mandate that binds only part of the registrant base.” — defaults.exposed August 2026 Domain Security Census (432M domains)
FAQ
Why does .bank score so much better than .com? Because its registry requires the controls our census grades most heavily. Under fTLD’s security requirements (industry record), .bank domains must deploy DNSSEC and email authentication — and in the August 2026 census, 99.9% have valid DNSSEC and 98.2% publish DMARC at p=reject, versus 4.6% and 4.7% respectively in .com. The result is a 3.1% F rate against .com’s 72.4%.
Doesn’t vetting who registers a domain make a TLD safer? Not measurably, on its own. .pharmacy verifies every registrant as a legitimate pharmacy but imposes no comparable configuration mandates, and it grades 84.5% F — worse than the open .com market. Identity checks and DNS configuration are simply different variables; a registry that only gates the former has no lever on the latter.
Should I move my domain to .bank or .insurance for the security? You almost certainly can’t — eligibility is restricted to verified financial institutions and insurers — and you don’t need to. Nothing in their winning column is registry magic: DNSSEC, DMARC at p=reject and valid TLS are available on any TLD, and the DNS records involved are free. The gap in this report is a configuration gap, not a product gap.
If mandates work, why is .gov at 28% F? Because the strongest .gov mandates bind only part of the zone. Federal directives like BOD 18-01 (industry context) cover federal executive-branch agencies, while .gov also holds state, county, city and tribal registrants no directive reaches. The blended zone still publishes DMARC at 60.0% — 2.6 times the .com rate — but a partial mandate produces a partial result.
Does this prove the rules caused the good grades? It is strong observational evidence, not a controlled trial. .bank registrants are well-resourced institutions and might be better-configured anyway. Two facts argue the rules do the work: vetted-but-unmandated .pharmacy performs like the open market, and .bank’s excellence stops exactly at the rulebook’s edge — CSP adoption is 9.1% on .bank versus 9.4% on .com, statistically identical on the one layer no rule names.
How does this data compare to prior census rounds? This is the August 2026 round; each edition re-measures the same TLD populations so results can be tracked over time. The cross-TLD ordering — mandated TLDs far ahead, vetted-only TLDs indistinguishable from the open market — is consistent with prior rounds. The 23× gap between .bank and .com reflects the structural mandate difference, not a one-round anomaly.
What should my organisation do if we cannot register a .bank domain? Deploy the same controls .bank registrants are required to have: DNSSEC at your registrar, DMARC at p=reject with a reporting address, and valid TLS on every hostname. All three are free, all three are available on any TLD, and all three are what separate a 3.1% F rate from a 72.4% one.
Most of what separates a 72.4%-F namespace from a 3.1%-F one is a handful of free DNS records and a certificate that renews itself. The barrier is almost never cost; it’s that nobody told the owner it mattered — or, in .bank’s case, somebody did.
Check your domain free at defaults.exposed — see whether your domain has the same DNSSEC and DMARC controls that .bank mandates for its registrants. Takes 30 seconds. No account needed.
Read the flagship census report: The State of Domain Security 2026 →
Related: Does mandatory DNSSEC work? — the DNSSEC-only predecessor to this full-posture comparison · The Internet Security Grade Curve · The Most and Least Secure TLDs · DMARC Enforcement Report
Aggregate data only. Data stored and processed in the EU.
How to cite this report
Press / blog: defaults.exposed (2026). Do Registry Rules Work? .bank 3.1% F vs .com 72.4%. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/do-registry-rules-work
Academic: defaults.exposed. (2026, August 18). Do Registry Rules Work? .bank 3.1% F vs .com 72.4%. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/do-registry-rules-work
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=140,810,926 .com graded; n=2,010 .bank graded)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026