The Hosting League Table: Domain Security by DNS Provider
Published
Figures as of 2026-08-16 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.
More than half of the internet’s A-grade domains sit behind one provider
We attributed 376.9 million graded domains to their DNS provider and built a security league table. The largest provider on the internet, GoDaddy, carries 52.4 million domains — 13.9% of the graded web — and 82.9% of them grade F. Meanwhile 52% of every A and A+ domain we found anywhere, under any provider, sits behind a single company: Cloudflare.
That is the league table in two lines. The internet’s biggest DNS operator runs a population that fails at eleven points above the global average, and the internet’s security elite has quietly consolidated behind one door. The rest of the table is stranger than either headline: a parking operator with 1.27 million domains and a 99.99% F rate, an aftermarket brand carrying 11.4 million domains with exactly one A among them. This is the mass-market web, sorted by who answers its DNS.
Key numbers
- The top 40 DNS provider nameserver tails carry 189.9 million domains — roughly half the 376.9 million graded in the August 2026 census round.
- GoDaddy (domaincontrol.com) is the largest single provider at 52.4 million graded domains (13.9% of the web); 82.9% grade F versus a 78.3% global F rate on the same basis.
- Cloudflare nameservers hold 261,435 A or A+ domains — 52.2% of the 500,806 that exist across the entire graded internet.
- Afternic, GoDaddy’s domain-aftermarket arm, carries 11.36 million domains; 94.4% grade F and exactly 1 reaches an A.
- GoDaddy plus Afternic together account for approximately 63.8 million domains — around 16.9% of the graded web — at an 85.0% combined F rate.
- The best mass-market F rates belong to SiteGround (37.5%) and Google Domains (42.6%) — though both cohorts mostly land at D, not at the top.
How the league table works — and what it can’t tell you
One paragraph of honesty before the rankings, because the attribution method is the whole story.
We assign each domain to a provider by the registrable domain of its first NS record. A domain whose nameserver is ns51.domaincontrol.com is attributed to GoDaddy; dara.ns.cloudflare.com to Cloudflare; dns1.registrar-servers.com to Namecheap. This is DNS-provider attribution, not web-hosting attribution. The two correlate strongly for the mass market — a small business on GoDaddy’s registrar defaults usually has GoDaddy DNS, GoDaddy parking or GoDaddy hosting — but they are not the same thing, and a domain can keep its registrar’s nameservers while its website lives anywhere.
Three more limits, stated up front. First, the league covers the top 40 nameserver tails; providers that fragment their NS estate across many domains are undercounted or invisible — AWS Route 53, which spreads across hundreds of awsdns-* tails, does not appear at all, and this is a measurement artifact, not an absence of AWS from the internet. Second, two entries in the raw top 40, co.uk and com.br, are attribution artifacts (many distinct national providers whose NS hosts sit directly under those public suffixes collapse into one bucket), so we exclude them from provider rankings. Third, and most important: a grade reflects what the domain owner configured, not the security of the provider’s own infrastructure. A provider’s row in this table is a portrait of its customer base and its defaults, not an audit of its network.
With that said: the table.
The league table: 376.9 million domains by DNS provider
Graded-domain basis (376,928,781 rows), August 2026 round. Global baseline on this basis: F 78.3% · D 13.6% · C 6.4% · B 1.5% · A/A+ 0.13%.
| Provider | NS tail | Graded domains | F | D | C | B | A/A+ |
|---|---|---|---|---|---|---|---|
| GoDaddy | domaincontrol.com | 52,445,186 | 82.9% | 11.2% | 5.0% | 0.9% | 16,223 |
| Cloudflare | cloudflare.com | 42,255,941 | 72.1% | 13.8% | 9.4% | 4.0% | 261,435 |
| Afternic (GoDaddy aftermarket) | afternic.com | 11,364,205 | 94.4% | 5.6% | 0.0% | 512 | 1 |
| Google Domains | googledomains.com | 9,687,615 | 42.6% | 30.8% | 21.3% | 5.2% | 9,031 |
| Hostinger parking | dns-parking.com | 9,206,156 | 81.8% | 12.9% | 5.1% | 0.2% | 841 |
| Namecheap | registrar-servers.com | 9,197,251 | 76.4% | 14.3% | 8.4% | 0.9% | 4,535 |
| Wix | wixdns.net | 7,114,267 | 65.4% | 22.2% | 11.3% | 1.0% | 4,480 |
| IONOS | ui-dns.com/.org/.biz/.de | 6,443,569 | 71.0% | 20.3% | 8.4% | 0.4% | 1,637 |
| NameBright | namebrightdns.com | 3,465,430 | 7.8% | 91.7% | 0.5% | 608 | 12 |
| OVHcloud | ovh.net | 2,775,504 | 53.0% | 32.7% | 12.0% | 2.0% | 7,486 |
| Strato | rzone.de | 2,296,212 | 80.0% | 15.3% | 3.9% | 0.7% | 405 |
| Alibaba (HiChina) | hichina.com | 2,252,909 | 88.0% | 8.6% | 3.1% | 0.3% | 69 |
| NS1 (IBM) | nsone.net | 2,235,002 | 81.0% | 13.3% | 4.6% | 0.8% | 3,417 |
| Spaceship | spaceship.net | 2,029,390 | 83.9% | 8.6% | 6.4% | 1.0% | 2,066 |
| Porkbun | porkbun.com | 1,804,023 | 77.1% | 13.5% | 8.1% | 1.2% | 1,467 |
| SiteGround | siteground.net | 1,564,665 | 37.5% | 55.7% | 6.4% | 0.5% | 221 |
| Squarespace | squarespacedns.com | 1,546,668 | 59.1% | 11.2% | 20.3% | 9.4% | 260 |
| Vercel | vercel-dns.com | 952,338 | 73.4% | 12.0% | 9.2% | 5.0% | 4,267 |
A few tails in the top 40 resist confident company attribution (share-dns.com/.net, julydns.com, dyna-ns.net, parity.domains). We keep them as hostnames rather than guess at owners; they matter to the story anyway, and they get their own section below.
Why do GoDaddy domains fail at a higher rate?
Start with the obvious defence, because it is largely correct: GoDaddy’s F rate is not a verdict on GoDaddy’s engineering. It is a portrait of who owns 51 million domains at the internet’s biggest registrar.
That population skews hard toward set-and-forget. Domains bought for an idea that never launched. Brand-protection registrations. Small businesses that configured nothing beyond what the purchase flow did for them. Such a domain gets whatever the defaults give it, and defaults — industry-wide, not just at GoDaddy — do not produce enforced DMARC, DNSSEC, HSTS or a content security policy. The result: 82.9% F, and an A/A+ rate of 0.031%, roughly 1 in 3,200 domains.
Then add the family business. Afternic is GoDaddy’s aftermarket and parking arm, and its 11.36 million domains are almost definitionally unconfigured: they exist to be sold, not to be run. 94.4% F. One single A-grade domain in the entire cohort — a number so low it is best read as noise. Fold Afternic into its parent and the GoDaddy family carries roughly 63.8 million domains, 16.9% of the graded web, at 85.0% F.
The takeaway is not “avoid GoDaddy.” It is that the largest slice of the internet’s namespace is administered by owners who have never touched a DNS record, under defaults that do not protect them. Whoever holds the mass market holds the failure rate.
What is Cloudflare doing differently?
Cloudflare’s row reads oddly at first. Its F rate, 72.1%, is below the global average of 78.3% — but the gap is less dramatic than it looks; the floor is pushed up by the expanded graded universe in the August census. No halo at the very bottom of the distribution.
The top is a different universe. Cloudflare nameservers hold 261,435 A and A+ domains. The entire graded internet, all 376.9 million domains across every provider, contains 500,806. One provider fronts 52.2% of the internet’s security elite. Its A/A+ rate, 0.62%, is twenty times GoDaddy’s.
Two forces produce this, and neither is mysterious. Selection: people who care about security migrate to Cloudflare, so the motivated tail of the internet concentrates there. Defaults: once a domain is on Cloudflare, several graded checks come cheap or automatic — TLS termination on modern protocol versions, one-click DNSSEC, easy HSTS. A motivated owner on Cloudflare has a shorter climb to an A than the same owner almost anywhere else. (Our methodology grades externally observable configuration; it does not care why a check passes.)
There is a concentration story buried in this that deserves its own moment: if half the internet’s best-defended domains stand behind one company’s nameservers, that company’s operational bar becomes a systemic fact. We examined the same phenomenon for DNS generally in nameserver concentration and the DNS concentration report; the league table shows the elite is even more concentrated than the population.
Who actually has the best security record?
Depends entirely on what “best” means, and the table punishes lazy definitions.
Lowest F rate: SiteGround, at 37.5% — barely half the global baseline — with Google Domains next at 42.6%. But look one column right. SiteGround’s domains pile up at D (55.7%, the highest D share of any conventional host) and only 0.48% reach A or B territory combined. Google Domains is similar: 30.8% D, 21.3% C, a real B share of 5.2%, but only 9,031 A/A+ among 9.7 million. These providers’ defaults reliably lift domains out of F — working TLS, sane baseline records — and then stop. Escaping F is not the same as being secure. (One label needed here: Google wound down its Google Domains registrar business and sold the customer base to Squarespace in 2023 — industry knowledge, not census data. The nameserver tail still answers for 9.7 million domains; treat the cohort as a legacy population in slow migration.)
Best at the top: Cloudflare by raw count and rate (0.64% A/A+), with Vercel the interesting runner-up at 0.45% — a developer-platform population whose owners deploy from code and evidently configure like it. Squarespace posts the highest B share in the table, 9.4%, consistent with a managed platform that sets good web-tier headers by default but can’t reach the DNS-layer checks an A requires.
Worst, honestly: the parking tier, which is the next section.
The parking basement: where F approaches 100%
The bottom of the league table is not populated by negligent hosts. It is populated by domains that were never meant to do anything.
| NS tail | Function | Graded domains | F rate | A grades |
|---|---|---|---|---|
| parity.domains | parking | 1,273,611 | 99.99% | 0 |
| julydns.com | parking-style | 1,184,562 | 98.6% | 0 |
| share-dns.com | parking-style | 1,414,398 | 97.7% | 0 |
| share-dns.net | parking-style | 1,228,784 | 97.7% | 0 |
| abovedomains.com | Above.com parking | 1,322,364 | 97.5% | 0 |
| afternic.com | GoDaddy aftermarket | 11,364,205 | 94.4% | 1 |
| onamae.com | GMO registrar defaults | 1,238,267 | 93.7% | 0 |
| sedoparking.com | Sedo parking | 1,159,603 | 86.0% | 0 |
parity.domains is the purest cohort we have ever measured: 1,273,611 graded domains, 1,273,495 of them F, three B grades, not one A. That is what a namespace looks like when every single name is inventory. Across the eight tails above — roughly 20 million domains — A grades total exactly one.
This matters beyond trivia. Around one graded domain in fourteen sits behind an NS tail whose function is parking or aftermarket holding, and every one of those domains drags the global average down while representing no operating business at all. When you read “72% of the internet fails,” remember that a measurable slice of the internet is a for-sale sign.
And then there is NameBright, the anomaly that proves grades are earned at the margin: 3.47 million domains, only 7.8% F — and 91.7% D, the strangest distribution in the table. NameBright is a drop-catch and aftermarket operation whose parked pages evidently serve just enough working web configuration to scrape past the F threshold, and not one point more. Twelve A grades in 3.5 million. The lowest F rate in the top 40 belongs to a parking operation. League tables without context are how bad conclusions get published.
Where are AWS, Azure and the enterprise providers?
Mostly invisible to this method, and it is worth being precise about why. Route 53 assigns each customer nameservers across a large pool of awsdns-* domains, so no single tail accumulates enough domains to enter a top-40 ranking built on registrable NS domains. Azure DNS fragments similarly. NS1 (IBM) is the one enterprise-leaning operator that does appear, at 2.2 million domains and — a caution to anyone assuming enterprise means configured — an 81.0% F rate.
So read the league table as what it is: a census of the mass-market web, where defaults decide almost everything. The enterprise internet is graded in our data; it just doesn’t sort neatly by nameserver tail.
How we measured this
- Denominator: 376,928,781 graded domain rows from the August 2026 census round (432,127,908 domains scanned). This article uses the graded-only basis throughout; the global F rate on this basis is 78.3%. (Our site headline F rate of 73.8% uses a different, dead-domains-count-as-F basis; the two are not comparable and we do not mix them.)
- Attribution: registrable domain of the domain’s first NS record, mapped to an operator. This measures DNS provision, not web hosting. The mapping from NS tail to company name was verified by hand for every named provider; tails we could not attribute with confidence are shown as hostnames.
- Coverage: the top 40 NS tails by domain count, which together hold approximately 189.9 million domains (roughly 50% of graded). Providers fragmenting NS across many domains (AWS Route 53, Azure DNS) are undercounted or absent — an artifact of the method, not a finding.
- Exclusions:
co.ukandcom.brappear in the raw top 40 but are public-suffix artifacts (many distinct providers whose NS hosts sit directly under those suffixes), not providers; they are excluded from all rankings above. - Row basis: counts are raw-pass rows and include a small re-scan duplicate fraction (roughly 0.75%); proportions and rates are unaffected.
- What a grade measures: externally observable configuration of the domain (DNS, email authentication, TLS, web security headers) under methodology v9’s 34 checks with the no-data rule (not-applicable is never scored as fail). A provider’s aggregate grade profile reflects its customer population and its defaults, not the security of the provider’s own systems. No causal claim is made about any provider.
- Industry-knowledge labels: provider corporate facts (Afternic’s ownership by GoDaddy, the 2023 Google Domains sale to Squarespace, NameBright’s drop-catch business model) are public industry knowledge, not census measurements, and are labelled as such where used.
- Vantage: EU-based measurement infrastructure; single vantage per scan pass.
- Aggregate only. We publish provider-level and TLD-level aggregates. We never name, grade or publish data about an individual registrant’s domain.
What this means
For IT managers and security teams, the league table is a calibration tool, not a provider comparison. The F-rate in your provider’s row tells you the base rate of failure among other organisations in the same position — the proportion whose DNS and email security was never configured beyond the purchase defaults. A domain on GoDaddy does not fail because GoDaddy is insecure; 82.9% fail because 82.9% of GoDaddy-registrar domains were set up once and never revisited. If your domain is on any registrar-default nameserver and you have not explicitly published SPF, DMARC, DNSSEC, and security headers, your probability of failing is close to the cohort average.
For business owners, the practical implication of Cloudflare holding 52.2% of A-grade domains is not “switch to Cloudflare.” It is that organisations that invest the attention to configure DNS security tend to concentrate on tools that make that configuration easier — and Cloudflare’s one-click DNSSEC, free TLS, and integrated DNS zone are easier than most. The A-grade is earned by configuration discipline, not by provider choice. A domain on GoDaddy with properly published SPF, DMARC, DNSSEC, and HSTS can outgrade the average Cloudflare domain. The 16,223 GoDaddy A and A+ domains in this census are proof that the provider is not the obstacle.
For organisations assessing supply chain security, this table provides a probabilistic prior for evaluating a partner or vendor’s domain security posture before you check it directly. A vendor whose domain sits on a registrar default nameserver has a 72–94% probability of failing basic domain security checks. A vendor on Cloudflare has a better-than-average chance of passing the top checks — not because Cloudflare publishes their security records, but because Cloudflare customers skew toward the technical population that does.
Data to cite
- “GoDaddy carries 52,445,186 graded domains in the August 2026 census — 13.9% of the web — with 82.9% grading F, compared to a global baseline of 78.3%.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “Cloudflare nameservers hold 261,435 A or A+ domains — 52.2% of the 500,806 that exist across the entire 376.9 million graded domain internet.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “Afternic, GoDaddy’s aftermarket arm, carries 11,364,205 domains at 94.4% F, with exactly one A-grade domain in the entire cohort.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “The parity.domains parking namespace scores 99.99% F across 1,273,611 graded domains, with no A grades — the purest cohort of unconfigured domains in the August 2026 census.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “GoDaddy and Afternic together hold approximately 63.8 million graded domains — 16.9% of the web — at a combined 85.0% F rate.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “SiteGround posts the lowest F rate among conventional hosts at 37.5%, but 55.7% of its domains land at D — the best provider at avoiding failure and among the weakest at reaching the top.” — defaults.exposed August 2026 Domain Security Census (432M domains)
FAQ
Which DNS provider has the most secure domains? By share of top grades, Cloudflare, and it isn’t close: 261,435 of the internet’s 500,806 A and A+ domains (52.2%) sit behind Cloudflare nameservers, an A/A+ rate of 0.62% versus a global 0.13%. By lowest failure rate the answer flips to SiteGround (37.5% F) and Google Domains (42.6% F) — but both cohorts overwhelmingly land at D or C rather than reaching the top, as of the August 2026 census round.
Does a bad provider grade mean my domain is insecure? No. The grades aggregate what each domain’s owner configured; the provider is where the population lives, not the cause of its failures. A domain on GoDaddy can reach A+ (16,223 do) and a domain on Cloudflare can fail (29.5 million grade F). Your own configuration decides your grade, and most of the failing checks cost nothing to fix.
Why doesn’t AWS appear in the table?
Route 53 spreads customer nameservers across hundreds of registrable domains (awsdns-*), so no single NS tail accumulates enough domains to rank. Our attribution method — registrable domain of the first NS record — systematically undercounts any provider built that way. AWS-hosted domains are in the census and are graded; they just don’t consolidate into one league-table row.
How much of the internet do the big DNS providers control? The top 40 nameserver tails carry a substantial share of the 376.9 million graded domains — approximately 189.9 million domains — as of 2026-08-16. GoDaddy alone holds 13.9% (52.4M domains), and with its Afternic aftermarket arm, roughly 16.9%. Add Cloudflare’s 11.2% (42.3M domains) and two companies answer DNS for roughly a quarter of the graded web.
Are parked domains dragging down the global security average? Measurably, yes. The eight parking and aftermarket NS tails in our table hold roughly 20 million graded domains at F rates between 86% and 99.99%, with one A grade among them. A meaningful share of graded domains sits behind a parking-function nameserver. The global 78.3% F rate includes them; an operating-web-only figure would be lower, though still a large majority failing.
What is the trend compared to July 2026? This August 2026 census establishes the per-DNS-provider grade breakdown at this level of detail across 376.9 million domains. Future editions will track whether registrar-default cohorts improve their F-rates as bulk sender requirements and increasing security awareness reach smaller domain owners. The 82.9% GoDaddy F-rate and 52.2% Cloudflare A-grade share are the August 2026 baselines.
How does my provider choice actually affect my security grade? Directly, mostly through defaults and tooling. Providers that apply working TLS, HTTPS redirection, and HSTS by default (Cloudflare, SiteGround, Wix) produce lower F-rates by getting those checks right without the owner doing anything. Providers that do not apply those defaults leave more work to the owner. But the checks that most failing domains fail — SPF, DMARC, DNSSEC — are always the owner’s responsibility regardless of provider. Switching to a better-rated provider without publishing those records changes nothing.
See where your own domain stands
Check your domain free at defaults.exposed — see which checks your domain passes and fails, independently of your DNS provider’s cohort average. Takes 30 seconds. No account needed.
Read the flagship census report: The State of Domain Security 2026 →
More from this series: nameserver concentration · the DNS concentration report · who hosts the internet’s email · the internet security grade curve
Aggregate data only. Data stored and processed in the EU.
How to cite this report
Press / blog: defaults.exposed (2026). The Hosting League Table: Domain Security by DNS Provider. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/the-hosting-league-table-domain-security-by-dns-provider
Academic: defaults.exposed. (2026, August 18). The Hosting League Table: Domain Security by DNS Provider. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/the-hosting-league-table-domain-security-by-dns-provider
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=376,928,781 graded domains)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026