Domain Dark Matter: 64 Million Delegated, Empty Domains
Published
Figures as of 2026-08-16 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.
The headline: one domain in six is a signpost to nowhere
Of the 432,127,908 domains in our August 2026 census, 63,840,407 — 14.8%, roughly one in seven — showed working nameserver delegation and nothing behind it: no address record, no mail route. Somebody registered each of these names. Somebody’s nameservers answer for them. Ask where the website is, and the answer is silence. Ask where the mail goes, and the answer is nowhere.
We call this cohort dark matter, and the physics metaphor is earned. You cannot see these domains — there is no page to visit, no mail server to greet. You can only detect them by their gravitational pull on the numbers: they are registered, they are delegated, they respond at the DNS layer, and they vastly outnumber the internet’s fully dead domains.
This is a different population from the one in our earlier report on the internet’s dead domains. Dead means the delegation itself is broken — no working nameservers, a name that has structurally collapsed. Dark matter is stranger. The plumbing works. Someone is paying to keep it working. There is simply nothing at the end of the pipe.
Key numbers
- 63,840,407 domains showed the dark-matter pattern in the August 2026 census: working NS delegation, no A record, no MX record — 14.8% of 432,127,908 scanned.
- Dark matter vastly outnumbers fully dead domains: 63.8 million delegated-but-empty domains sit far above the count of names with broken delegation entirely.
- More than one in three domains — 34.1% — never produced a gradable scan at all (dead + unreachable + indeterminate combined).
- .bond is the emptiest sizeable TLD we measured: 81.6% of its 1,168,294 scanned domains are delegated but unreachable, and 89.2% never produced a graded scan.
- 43,723 dead or unreachable domains still publish a live mail route — abandoned but still accepting mail. A floor, not a total (see methodology).
- 14,455,076 domains publish a Null MX record — the correct, standards-based way (industry knowledge: RFC 7505) to declare “this domain sends and receives no mail.”
What exactly is a dark-matter domain?
Picture domain aliveness as a ladder.
At the bottom: dead. The nameserver delegation is broken; the name resolves to nothing because nothing answers for it. Our census found 21,444,663 of these — 6.0% of everything scanned. They got their own report.
One rung up sits dark matter, and the definition is precise: the domain has working nameserver delegation — real NS records, servers that answer authoritatively — but publishes no A record (no IPv4 address for a website) and no MX record (no mail exchanger). The DNS infrastructure is alive and maintained enough to answer queries. The domain itself does nothing a human would ever notice.
Above that: the flaky middle — domains that answered inconsistently or incompletely across our scan passes — and finally the 269,417,759 domains (74.8%) that were alive enough to receive a security grade.
The distinction between the bottom two rungs matters more than it looks. A dead domain costs its owner nothing but the registration fee and has often simply been forgotten past the point of collapse. A dark-matter domain is different: delegation does not maintain itself. Someone pointed that name at nameservers, and those nameservers — usually a registrar’s or a DNS provider’s — are answering for it right now. These are deliberate registrations in a holding pattern. The lights are on at the front desk of 63.9 million empty buildings.
How much of the internet does nothing at all?
Here is the full disposition split of the August 2026 census, on the strict basis where every domain gets exactly one final state:
| Final disposition | Domains | Share of scanned |
|---|---|---|
| Graded (alive, scannable) | 284,598,752 | 65.9% |
| Indeterminate (inconsistent answers) | 19,814,020 | 4.6% |
| Unreachable (delegated, nothing responds) | 35,385,107 | 8.2% |
| Dead (no active service) | 92,330,029 | 21.4% |
| Total scanned | 432,127,908 | 100% |
Add the bottom three rows and you get the headline nobody in the domain industry puts on a slide: 147,529,156 registered domains — more than one in three — never produced a gradable scan. Not a badly configured website. Not a C grade. Nothing to grade.
The dark-matter cohort cuts across those bottom rows. Of the 63.8 million domains showing the NS-yes, no-A, no-MX pattern, the majority carried an unreachable scan disposition and the remainder an indeterminate one. And then there is a sliver that should not exist: domains that match the dark-matter pattern while still earning a security grade. The most plausible explanation is the IPv6-only cohort — a domain with only an AAAA record has no A record by definition, and if it also skips mail it matches the dark-matter pattern while still serving a scannable website. The rest of the IPv6-only story is its own report.
Where does dark matter concentrate?
Empty domains are not spread evenly. Some TLDs are mostly signal; a few are mostly void. The table below shows the share of scanned domains that never produced a graded scan on any pass, for TLDs with at least one million domains scanned — with the composition split out, because how a TLD is empty tells you what is going on there.
| TLD | Scanned | Dead (no NS) | Unreachable (delegated, silent) | Indeterminate | Never graded |
|---|---|---|---|---|---|
| .bond | 1,168,294 | 67,301 | 952,864 | 21,982 | 89.2% |
| .top | 12,548,818 | 6,465,016 | 2,315,271 | 952,575 | 77.6% |
| .lol | 1,055,345 | 7,097 | 697,178 | 16,111 | 68.3% |
| .dev | 1,426,652 | 717,415 | 124,613 | 15,920 | 60.1% |
| .app | 2,978,730 | 1,499,232 | 213,612 | 39,691 | 58.8% |
| .sbs | 1,148,611 | 55,614 | 506,724 | 51,924 | 53.5% |
| .com | 172,325,990 | 8,815,700 | 14,344,330 | 8,355,034 | 18.3% |
| .de | 9,378,239 | 274,367 | 205,825 | 362,590 | 9.0% |
| .nl | 3,160,821 | 69,434 | 54,378 | 9,333 | 4.2% |
| .ch | 1,462,570 | 23,072 | 25,396 | 4,119 | 3.6% |
(This table credits a domain as graded if any scan pass graded it, so its shares run slightly kinder than the strict single-disposition split above. One large TLD is deliberately excluded: .ph shows a 98.7% never-graded rate, but that figure is an artifact of TLD-level DNS wildcarding inflating its inventory with phantom names, not a real emptiness measurement.)
Read the composition column by column and three different failure stories emerge.
.bond is the purest dark matter we found. Not dead — delegated and silent. 952,864 of its 1.17 million scanned domains answer at the DNS layer and then go quiet: 81.6% of the entire TLD. Whatever drove those registrations — bulk promotional pricing is the obvious suspect, though that is industry inference, not census data — almost none of it turned into anything a visitor or a mail server would ever encounter.
.top and .app are graveyards, not voids. Their emptiness skews dead: 51.5% of all scanned .top domains and 50.3% of .app have no working delegation at all. That is the signature of mass registration followed by mass abandonment — names that were cheap to acquire, briefly delegated, then left to rot when renewal came due or the free nameservers lapsed.
The European ccTLDs barely register. .ch at 3.6%, .nl at 4.2%, .de at 9.0%. Country-code domains cost more, renew annually at real prices, and are disproportionately registered by people who wanted that specific name for a specific purpose. The never-graded rate is a fairly direct readout of how much of a TLD’s namespace was bought to be used versus bought to be held.
And .com, the giant, sits at a similar rate — close to the global average, as it arithmetically must, since it is a large share of the measured internet. The world’s most valuable namespace still carries an empty district the size of a mid-sized country’s entire internet.
Why would anyone pay for 64 million empty domains?
The census can count the void precisely; it cannot read the motives behind it. But the candidate explanations are well understood in the domain industry, and they are worth stating — labelled clearly as industry knowledge, not census data.
Speculation stock. Domains held purely for resale. A speculator needs the registration and the delegation (registrars provide parking nameservers by default) but has no reason to build anything. Note the boundary though: classic parked pages — the ad-covered “this domain may be for sale” placeholders — usually do have an address record, because serving ads requires a web server. Our census graded about 2.15 million domains sitting on the five major parking-nameserver providers (Sedo, ParkLogic, ParkingCrew, Bodis, Above); those are visible, gradable, and mostly graded F. Dark matter is the quieter stratum beneath: held, delegated, and not even monetised with ads.
Brand protection. Companies defensively register their name across dozens or hundreds of TLDs and variants. The point is that nobody else can have the name; pointing it at an actual server is optional and often skipped. Multiply the world’s trademark portfolios by the ever-growing list of TLDs and you get a standing population of deliberately inert names.
Abandoned projects. The side project that never launched, the startup that pivoted, the newsletter that never got issue one. The domain was step one; there was no step two. Auto-renew keeps the delegation alive for years after the ambition died.
What all three have in common: the registration fee — typically around ten dollars a year for a .com at retail, less during TLD promotions (industry knowledge) — is cheap enough that holding costs never force a decision. At those prices, 63.8 million empty delegations represent a licence-fee economy comfortably in the hundreds of millions of dollars a year, paid for names that resolve to nothing. We cannot split the cohort between speculators, brand lawyers and dreamers; the DNS records look identical. [DATA GAP: registrant-intent classification — WHOIS/RDAP data and page content are not captured in this census round, so the motive split is unmeasurable here.]
The zombie fringe: abandoned, but still accepting mail
Dark matter is defined by publishing no mail route. Its neighbour cohort is more unsettling: domains that are dead or unreachable as websites but still publish a working MX record. The census found 43,723 of these — 10,645 among dead domains, 33,078 among unreachable ones.
Treat that number as a floor, and a low one. This census round only enumerated mail records in full for graded domains, so the zombie count comes from partial capture (the gap is logged in our methodology notes). The true population of abandoned-but-mail-accepting domains is likely much larger.
Why it matters: a domain nobody watches, with a mailbox that still works, is a standing gift to an attacker. Password resets, invoice redirects, account recovery flows — anything sent to an address at that domain lands somewhere nobody is monitoring. The web presence dying does not end a domain’s security story. Sometimes it is the beginning of the interesting part. Our internet rot report digs further into this cohort.
There is also a right way to be empty, and 14,455,076 domains have found it: a Null MX record (industry knowledge: RFC 7505, published 2015) explicitly declares that a domain handles no mail, telling the world’s mail servers to reject rather than retry. An empty domain with a Null MX and a restrictive SPF/DMARC pair is honestly, safely empty. An empty domain with no records at all is merely ambiguous — and ambiguity is what spoofers use.
Does dark matter pose a security risk?
Mostly, an empty domain is just inert capital. But two risks are worth naming, both consequences of the same fact: these domains are maintained at exactly one layer (DNS) and ignored at every other.
First, spoofing. Receiving mail servers judge a forged sender by the claimed domain’s SPF and DMARC records. A domain does not need a mailbox — or an MX record — to be worth impersonating; it needs only a recognisable name and absent email authentication. Dark-matter domains, by definition unattended, rarely publish any. A brand-protection registration with no DMARC policy protects the brand from squatters while leaving it open to spoofers, which rather misses the point of protection. (Whether a given empty domain lacks these records is measurable per domain; we publish only the aggregate pattern here. The mechanics are in our email spoofability index.)
Second, dangling delegation. A domain pointed at nameservers nobody thinks about is a domain whose fate depends entirely on infrastructure nobody audits. If the DNS provider account lapses, or the nameserver hostnames themselves become registrable, the delegation can be quietly taken over — and a takeover of a “worthless” empty domain still yields a name with age, history, and possibly residual trust. Our report on single-nameserver domains covers the adjacent fragility.
Neither risk requires the domain to do anything. That is the uncomfortable property of dark matter: doing nothing is not the same as being harmless.
How we measured this
- Population and denominator: 432,127,908 domains scanned in the August 2026 census round (methodology v9), from EU-based measurement infrastructure. Disposition figures (graded / indeterminate / unreachable / dead) use the strict single-final-state resolution, which sums exactly to the scanned total.
- Dark-matter definition: working NS delegation, no A record at the apex, no MX record — measured from raw DNS evidence, not from check pass/fail status.
- The 63,840,407 figure and its bounds: the cohort was counted from per-scan evidence, and domains retried across multiple census passes can appear under more than one scan disposition. Read 63.8 million as the pattern’s footprint in our evidence and a modest upper bound on unique domains; the largest single bucket (48,942,960 unreachable-disposition domains under the dark-matter lens) is the conservative floor. Even on the strictest reading, the cohort exceeds 48.9 million unique domains.
- AAAA records were not part of the exclusion, which is how 28,872 graded domains (plausibly overlapping the IPv6-only cohort) appear inside the dark-matter pattern.
- Per-TLD table basis: the TLD rollup credits a domain as graded if any scan pass graded it, so per-TLD never-graded shares are slightly lower than the strict global split. Both bases are stated where used.
- The zombie count (43,723) is a floor: MX records were fully enumerated only for graded domains this round; the dead/unreachable MX census is partial by construction.
- What we cannot see: registrant intent (speculation vs brand protection vs abandonment) — WHOIS/RDAP and page content are outside this round’s capture, so the motive split is explicitly unmeasured. Parked-page detection via page body is likewise unavailable this round; the parking figures quoted come from parking-provider nameserver fingerprints among graded domains only.
- Industry knowledge is labelled as such wherever it appears (RFC dates, typical registration pricing, motive taxonomy). Everything else is census measurement.
- Aggregate only. We report cohort counts and TLD-level patterns. We never name, grade, or publish data about an individual registrant’s domain. Data is stored and processed within the EU.
FAQ
What is a dark-matter domain? A registered domain with working nameserver delegation but no address record and no mail route — DNS answers for it, yet there is no website to visit and no mail server to deliver to. Our August 2026 census found 63,840,407 domains matching this pattern, 14.8% of the 432 million scanned.
How is that different from a dead domain? A dead domain’s delegation is broken: no working nameservers at all. A dark-matter domain’s delegation works — someone is actively maintaining the DNS layer — but nothing is published behind it. The dark-matter cohort alone (63.8M) exceeds the combined unreachable and indeterminate populations.
How much of the internet actually works? 65.9% of scanned domains — 284,598,752 of 432,127,908 — were alive enough to receive a security grade in the August 2026 census. More than one in three produced nothing gradable: 21.4% dead or inactive, 8.2% delegated but unreachable, 4.6% answering too inconsistently to measure.
Are empty domains a security problem? Sometimes. An unattended domain rarely publishes SPF or DMARC, which leaves its name available for email spoofing regardless of whether it has a mailbox. And 43,723 dead or unreachable domains still publish a live mail route — abandoned addresses that quietly accept whatever is sent to them. That figure is a floor given this round’s capture limits.
What should I do with a domain I own but don’t use?
Make it honestly empty. Publish a Null MX record (RFC 7505 — industry standard) to declare it handles no mail, add an SPF record of v=spf1 -all, and set a DMARC reject policy. 14,455,076 domains already publish a Null MX. Three DNS records turn an ambiguous name into an unspoofable one, at zero cost.
What This Means
For IT managers and security teams, the dark-matter finding is most actionable in two contexts. First, domain portfolio audits: any organisation that has defensively registered brand variants, old project names, or regional TLDs should check whether those domains are “honestly empty” — publishing a Null MX, restrictive SPF, and a DMARC reject policy — or merely silent. A silent domain looks like a spoofing target. A properly declared empty domain does not. The three DNS records required take minutes to publish and cost nothing.
Second, the 43,723 abandoned-but-mail-accepting domains are a specific threat surface worth understanding. If your organisation has decommissioned domains in the past — discontinued products, old trading names, acquired companies’ domains — any that still have MX records are accepting mail to addresses nobody monitors. That mail could include password resets, account recovery links, invoice copies, or regulatory correspondence. An annual check of your domain portfolio for live MX records on decommissioned names is straightforward and the consequence of not doing it is genuine.
For security researchers and threat intelligence teams, the concentration of dark matter in specific TLDs is a useful filter. The 81.6% delegated-but-silent rate in .bond, 77.6% in .top, and similar patterns in other heavily promoted new gTLDs mean that a domain in those namespaces is statistically far more likely to be an empty registration than an operated site. Phishing infrastructure that uses these TLDs is operating against a backdrop of genuine emptiness, which can complicate attribution and reputation-based filtering.
Data to Cite
- “63,840,407 domains — 14.8% of 432,127,908 scanned — had working DNS delegation but no website and no mail route in the August 2026 census.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “More than one in three registered domains — 147,529,156 of 432,127,908 — never produced a gradable scan at all in the August 2026 census.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “43,723 dead or unreachable domains still publish a live mail route — abandoned names that quietly accept whatever is sent to them, with nobody monitoring.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “14,455,076 domains already publish a Null MX record — the standards-based way to declare a domain handles no mail and protect it from spoofing at zero cost.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “.bond is the purest dark matter measured: 81.6% of its 1,168,294 scanned domains are delegated and silent — DNS answers, but nothing is behind it.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “65.9% of scanned domains — 284,598,752 of 432,127,908 — were alive enough to receive a security grade; the remainder produced no gradable signal at all.” — defaults.exposed August 2026 Domain Security Census (432M domains)
See where your own domain stands
Dark matter can’t be graded, but your domain can. Our census grades real, live domains across 34 externally observable security checks — and if you hold unused domains, the handful of records that make them safely inert are free and take minutes. The barrier is almost never cost; it’s that nobody told the owner it mattered.
Read the companion report: The Internet’s Dead Domains →
Aggregate data only. Data stored and processed in the EU.
Check your domain free at defaults.exposed — find out whether your active domain has the email authentication records that keep unused and parked names from being spoofed in your name. Takes 30 seconds. No account needed.
How to cite this report
Press / blog: defaults.exposed (2026). Domain Dark Matter: 64 Million Delegated, Empty Domains. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/domain-dark-matter
Academic: defaults.exposed. (2026, August 18). Domain Dark Matter: 64 Million Delegated, Empty Domains. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/domain-dark-matter
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=432,127,908)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026