Defaults.Exposed

Defaults.ExposedReports

Nine Million Domains Where A-Grades Round to Zero

Published

Figures as of 2026-08-16 (August 2026 round) — methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade.

The headline: what your MX record says about your security

We graded 164,658,913 domains by who runs their email. The starkest result is at the bottom of the table: across 9,338,016 domains parked on GoDaddy’s default mail server, exactly 198 earn an A — an A-rate that rounds to 0.00% — and 89.3% score an F. The tens of millions of domains left on registrar and hosting default mail servers are among the least protected multi-million-domain populations we measured, failing at 72-89%.

Every domain that receives email publishes an MX record — a public signpost saying “deliver my mail here.” That signpost tells you who the mailbox provider is. We took every graded domain in our census that has one, attributed it to the provider behind its primary MX, and asked a simple question: does the choice of email provider line up with the domain’s overall security grade?

It lines up — but not in the way the provider marketing war would suggest. One sentence to keep in mind throughout: your mailbox provider doesn’t set most of the records that decide your grade — you do. What the MX record reveals is not what the provider does to a domain, but what kind of owner the domain has.

Key findings, across 164,658,913 graded domains with a primary MX:

The league table: 18 providers, 164.7 million domains

Attribution is by the registrable tail of each domain’s highest-priority MX host. Here is every provider cohort we report on, sorted by share of domains scoring an F. Lower %F is better.

Provider (MX tail)Domains% scoring F% scoring A (A+/A)% B or better
Proofpoint (pphosted.com)136,64322.12.3919.63
SiteGround (mailspamprotection.com)1,323,13035.90.010.36
Mimecast (mimecast.com)163,31537.30.115.74
Cloudflare Email Routing (cloudflare.net)2,218,25741.60.885.61
Google Workspace (google.com)18,555,57142.70.896.59
Microsoft 365 (outlook.com)14,119,32844.40.495.19
Rackspace (emailsrvr.com)370,15746.50.133.47
Zoho (zoho.com)1,388,46949.90.082.79
Tucows/OpenSRS (hostedemail.com)1,801,26053.60.010.36
Yandex (yandex.net)490,48066.60.031.17
Amazon SES/WorkMail (amazonaws.com)281,51567.10.031.33
Hostinger (hostinger.com)4,157,34872.60.010.16
IONOS (ionos.com)1,739,84375.10.020.29
Legacy Google MX (googlemail.com)1,058,51575.70.231.95
Namecheap default (registrar-servers.com)7,524,69077.10.010.36
one.com889,34583.80.091.26
GoDaddy default (secureserver.net)9,338,01689.30.000.82
Tencent (qq.com)708,83192.40.010.16

Three bands are visible at a glance. At the top: paid security gateways and, a tier below, the big productivity suites, all under 50% F. In the middle: standalone mail hosts. At the bottom: the default mail servers that registrars and hosting companies attach to a domain automatically — plus one large consumer provider — where failure rates run from the seventies into the nineties. (One hosting-attached service bucks the band: SiteGround’s mailspamprotection.com, a spam-filtering MX, sits near the top of the table at 35.9% F — so the bottom band is specifically the registrar defaults named below, not hosting-attached MX as a class.)

The rest of this report walks through each band and what it actually tells you.

The set-and-forget majority: 20+ million domains on default MX

Buy a domain from a registrar or a hosting plan from a web host, and you often get a working mail server without lifting a finger. The MX records are pre-filled. Email arrives. Nothing prompts you to look at it again. Our census can see exactly how that population fares, and the answer is: worse than almost anyone else.

Set against the big-suite cohorts in the low-to-mid forties, domains on these five registrar and hosting default MX services fail at 1.7 to 2 times the rate — 1.7x for Hostinger at the gentle end, 1.8x for Namecheap, and a straight doubling for GoDaddy.

In a cohort of 9.3 million domains, A-grades round to zero: 198 out of 9,338,016.

To be clear about what this is and isn’t: the provider is not the cause. GoDaddy’s mail servers do not reach into your DNS and delete your DMARC record. The failing records — SPF, DMARC, and most of the rest of what we grade — live in the domain owner’s own DNS, and the owner is the one who never published them.

What the default MX is, is a marker. It marks a domain whose owner accepted every default at purchase and never came back. Nobody chose that mail server; it was simply there. And a domain nobody configured is a domain nobody protected. The default-MX cohorts are, in effect, a census of set-and-forget domain ownership — and it is over twenty million domains deep across just the five providers named above.

A domain nobody configured is a domain nobody protected.

The consequence is not abstract. A domain at F is typically one that can be impersonated in email — the raw material of fake-invoice fraud — and these tens of millions of domains skew toward exactly the small businesses least equipped to spot it.

The natural experiment: googlemail.com vs google.com

Buried in the data is something close to a controlled experiment on neglect.

Domains pointing at googlemail.com MX hosts are on the same Google mail service as everyone else — it’s a legacy MX configuration from years ago. A domain still carrying it was set up long ago, and its MX records have not been revisited since. That gives us two cohorts on the same product, separated mainly by whether anyone has looked at the DNS recently:

Same provider. Same underlying service. A 33-point gap in failure rate. This is an age signal, not a product difference — and it is the cleanest evidence in the whole dataset that attention, not provider, is the variable that decides a domain’s security. The domains whose owners updated their MX records are also the domains whose owners published DMARC. The ones frozen in time failed to do either.

Same Google mail service, two eras of configuration: domains on the current MX fail at 42.7%; domains still on the legacy MX from years ago fail at 75.7%.

Google vs Microsoft: a real gap, and a shared blind spot

The two providers that host business email for most of the professional world make a natural head-to-head. On our data, Google leads at every tier we measured — though the headline gap is smaller than either side’s marketing would have you guess.

MeasureGoogle WorkspaceMicrosoft 365
Domains in cohort18,555,57114,119,328
% scoring F42.744.4
% scoring A (A+/A)0.890.49
% B or better6.595.19

The F-rate gap is modest: 42.7% versus 44.4%, less than two points. The gap at the top is more pronounced. A Google-hosted domain is roughly 1.8 times as likely to earn an A as a Microsoft-hosted one — 0.89% versus 0.49% — and clears the B-or-better bar more often too (6.59% versus 5.19%).

Why might that be? We measure outcomes, not causes. One checkable hypothesis: the two suites differ in how hard their onboarding pushes domain DNS. Google Workspace’s domain setup walks the admin through publishing SPF and DKIM records as a gating step before mail flows reliably, while Microsoft 365’s custom-domain flow has historically treated some of those records as optional add-ons. Both flows are publicly documentable, so we offer this as a hypothesis to test, not a finding. The customer populations also differ. Whatever the mechanism, the outcome is consistent across 32 million domains.

The more important story is what the two giants share. More than four in ten domains on the world’s two premium business email platforms score an F. These are paying customers, on platforms that support every protection we check for. The subscription buys a mailbox; it does not buy a configured domain.

A premium mailbox is not a premium security posture. Over 40% of domains on both Google Workspace and Microsoft 365 score an F.

Cloudflare’s free Email Routing deserves a mention here, because it undercuts the idea that price sets the ceiling: 41.6% F and a 0.88% A-rate — practically shoulder-to-shoulder with Google Workspace, at a price of zero. Cloudflare Email Routing users are self-selected, DNS-literate people who chose an unusual product, and that self-selection is doing the work. But it shows the ceiling isn’t set by what you pay for the mailbox.

Money talks: the paid-security effect

At the top of the table sit the dedicated email-security gateways — services a company pays for specifically to filter and protect its mail, sitting in front of the actual mailboxes.

Proofpoint-fronted domains are the best cohort we measured: 22.1% F, 19.63% B or better, and a 2.39% A-rate — roughly 2.7 times Google’s, and nearly five times Microsoft’s. Mimecast-fronted domains, at 37.3% F, also beat both Google and Microsoft.

Before anyone writes the headline “buy Proofpoint, get an A”: organisations that route mail through a paid gateway are a different species of domain owner — large enough to have an IT function, security-conscious enough to spend real money on email defence, and usually staffed by the kind of team that publishes an enforced DMARC record before coffee. The gateway doesn’t hand out A-grades; it identifies the organisations that were always going to earn them.

But that reading is itself the finding. Where a domain’s owner demonstrably cares about email security, the whole domain posture follows — B-or-better rates roughly three to four times those of the business-suite cohorts (19.63% against Google’s 6.59% and Microsoft’s 5.19%). Security posture travels together. It is bought with attention, and the spend is just the visible trace of the attention.

And the inverse of the Proofpoint story is the qq.com story. Domains using Tencent’s consumer qq.com mail service form the worst large cohort we measured: 92.4% F across 708,831 domains — a consumer mailbox pressed into domain duty, with almost no domains reaching a passing posture: 37 A-grades in the cohort, and 0.16% at B or better.

The subscription buys a mailbox; it does not buy a configured domain.

What this means if you run a business

Find your provider in the table, and read your cohort’s F-rate as a base rate, not a verdict. Then act on three things:

1. Your provider will not do this for you. Whichever row you’re in, the records that decide most of your grade — SPF, DMARC and their companions — live in your DNS. Google can’t publish them for you. Neither can GoDaddy. The 42.7% of Google Workspace domains at F are proof that even the best mainstream provider leaves the domain’s fate in the owner’s hands.

2. If you’ve never touched your email settings, assume you’re in the failing majority. The default-MX and legacy-MX cohorts tell one story from two directions: domains that were set up once and left alone fail at 72-89% — 1.7 to 2 times the rate of the big suites. If you can’t remember configuring your domain’s email security, the odds say it isn’t configured.

3. The fix is free. The protections that separate an F from a respectable grade are typically a few lines of DNS — no new subscription, no migration, no gateway contract required. The Proofpoint cohort’s grades come from configuration discipline, and configuration is free. The barrier is awareness, not cost. The stakes are concrete: an unprotected domain can be impersonated in email to your customers and suppliers (the mechanics of fake-invoice fraud), your genuine mail is more likely to be junked by increasingly strict receivers, and you will fail the quick security checks bigger customers now run before signing.

How we measured it


What this means

For IT managers at small and medium businesses, the practical takeaway is that your email provider is not responsible for the DNS records that determine your security grade. Whether you are on Google Workspace, Microsoft 365, or any other platform, the SPF, DMARC, DKIM, and other records that separate a failing grade from a passing one live in the DNS zone you control. The 42.7% of Google Workspace domains and 44.4% of Microsoft 365 domains grading F are not failing because of their provider — they are failing because no one published those records. Your provider subscription does not include that work.

For small businesses on registrar default mail servers — GoDaddy, Namecheap, Hostinger, IONOS — the data is unambiguous: 72 to 89% of organisations in the same position as you are failing their domain security grade. The default MX is not the cause; it is a marker for the domain that was set up once and never revisited. The same person who did not configure SPF and DMARC also did not change the mail server. Fixing the security posture does not require changing your email provider — it requires publishing a handful of DNS records, which is free and takes an afternoon.

For larger organisations reviewing supply chain risk, this table provides a practical baseline for understanding what a vendor or partner’s domain posture is likely to be based on their MX provider alone. A domain on a registrar default MX has a 72–89% probability of failing domain security checks — which means it is likely spoofable, its email is likely unauthenticated, and the organisation may not know. If fake-invoice fraud is in your threat model, the provider row a business appears in tells you the base rate of risk before you even check their record.


Data to cite


FAQ

How do I check which cohort my domain is in? Look up your own MX record — it takes thirty seconds. On any computer, run nslookup -type=mx yourdomain.com (or dig mx yourdomain.com on Mac/Linux), and read the registrable tail of the highest-priority host it returns: aspmx.l.google.com puts you in the Google Workspace row, mailstore1.secureserver.net in GoDaddy’s default row, and so on. If you’ve never run that command before, that itself is a data point about which band you’re likely in.

Does this mean I should move my email to Google (or to Proofpoint)? No — and the data doesn’t support that conclusion. The gaps between providers mostly reflect who their customers are, not what the product does to your security grade. Moving providers without configuring your domain changes nothing; conversely, a domain on a registrar default MX with properly published SPF, DMARC, TLS and headers can out-grade the average Google Workspace domain without moving anywhere.

My domain is on my registrar’s default mail server. Am I automatically insecure? Not automatically — but the odds are against you. As of 2026-08-16, 89.3% of domains on GoDaddy’s default MX and 77.1% on Namecheap’s score an F. It’s worth knowing that these defaults are usually basic POP/IMAP mail with none of the domain-level protections pre-published — the registrar sells DNS and mail as separate concerns, and nothing in the purchase flow circles back to connect them. The fix is to publish the protections — which is free — not necessarily to change provider.

Google hosts my email. Doesn’t Google handle all this security for me? It handles the mailbox, spam filtering and inbound delivery. What it cannot do is publish records in a zone it doesn’t control: SPF, DMARC and your TLS and header posture live in your DNS, at your registrar or DNS host, under your login. That division of control is why 42.7% of Google Workspace domains still score an F despite sitting on first-rate infrastructure.

Which cohort is worst overall? Among large cohorts, domains on Tencent’s qq.com mail: 92.4% score an F as of 2026-08-16, with 37 A-grades across 708,831 domains. Among the biggest Western cohorts, GoDaddy’s default secureserver.net at 89.3% F — with 198 A-grades across 9,338,016 domains.

What is the trend compared to July 2026? This August 2026 edition establishes the per-provider grade breakdown at this level of detail across 164.7 million domains. Future editions will track whether the default-MX cohorts improve their F-rates as domain owners respond to tightening bulk-sender requirements from Google and Yahoo. The 89.3% GoDaddy F-rate and the 198 A-grades are the August 2026 baseline.

Why does paying more for email security produce better grades? The Proofpoint and Mimecast cohorts score better not because the gateway writes the DNS records, but because organisations that pay for dedicated email security gateways tend to be the same ones with IT teams who also publish enforced DMARC, complete SPF, and signed DKIM. Security posture is holistic — the spend is a visible indicator of the attention that produces grades across all checks, not just email.


See where your own domain stands

Check your domain free at defaults.exposed — see whether you are in the failing majority of your email provider’s cohort or the small minority that has actually configured its security posture. Takes 30 seconds. No account needed.

The State of Domain Security 2026 →

Aggregate data only. Data stored and processed in the EU.


How to cite this report

Press / blog: defaults.exposed (2026). Nine Million Domains Where A-Grades Round to Zero. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/nine-million-domains-where-a-grades-round-to-zero

Academic: defaults.exposed. (2026, August 20). Nine Million Domains Where A-Grades Round to Zero. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/nine-million-domains-where-a-grades-round-to-zero

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=164,658,913 graded domains with primary MX)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026