Defaults.Exposed

Our headline F rate fell, and the internet did not get safer

If you quoted our F rate from an earlier edition and you’re now looking at the September one, don’t put the two in the same sentence. The September figure is 234,955,475 domains with an F, which is 74.2% of the 316,600,902 graded and dead domains in this edition. It’s lower than the share we published before, and the drop is mostly the population changing shape. The domains under the new number are a different set, chosen by a stricter existence check, and nothing in the movement tells you that operators fixed their records.

The headline is a fraction, and both halves changed

A grade share is a numerator over a denominator. When we publish “F 74.2%”, the 74.2 says nothing on its own. It’s 234,955,475 over 316,600,902, and if the names in the denominator change, the fraction changes even when nobody touched a DNS record, which is what happened in September.

Before grading anything this edition, the census ran a two-pass existence check over the sourced list. Names that don’t resolve at all were removed before the scanners saw them. So were the phantom names that only appear to exist because a registry answers with a wildcard for anything you ask it. The set that reached the grader is a tighter definition of “a registered domain that exists” than the one behind any earlier headline.

Removing names that were never going to answer changes the mix of what’s left. A share of F among domains that exist is a different statistic from a share of F among names that appeared on a zone file. Both are honest measurements. Or rather, each is honest about the thing it measures, and neither says anything about the other.

Two denominators, and which one you cite

You’ll meet both in our own tables. Quote the one that matches the claim you’re making.

For any grade share, the basis is graded+dead = 316,600,902. Those are the domains with a letter against them: the ones the grader could score, plus the ones it classed dead. Every band on the data page, A+ through F, is a share of that number.

For any per-check figure (a DMARC policy state, an SPF qualifier, whether HSTS was present) the basis is disposition graded = 315,211,826. Those are the domains where the checks ran. A dead domain has no HTTPS response to inspect and no mail records to parse, so it isn’t counted under any check.

Behind both is scanned = 347,691,016, the number of domains the edition attempted at all. Use it for “how big was the census” and don’t use it for “what share is F”. Between scanned and graded are the indeterminate and unreachable dispositions, domains where the scan got an answer that wasn’t good enough to grade.

The pairing we published is 74.2% of the 316,600,902 domains graded or classed dead in the September 2026 edition. Any other pairing, 74.2% over scanned or over disposition graded, is a number we didn’t publish, and a reader who checks will find it doesn’t reconcile.

What a dead domain does to the share

This edition counts a dead domain inside the grade denominator. Dead means the name is registered and the scan reached the point of grading, then found nothing alive to assess: the nameservers don’t work, or there’s no address behind the name and nothing answers on any port we try. There were 1,389,076 of them, 0.40% of scanned, and they grade F.

We chose that on purpose, and you should know about it when you cite the band. A registered name with no live DNS can still be written into a From: header by anyone, and it publishes no policy telling a receiving mail server to refuse that message. A live domain with no records has the same exposure, which is why a parked or abandoned domain gets spoofed as readily as a busy one. Treating it as a pass, or dropping it from the denominator, would flatter the share.

If the figure you cited earlier came from a count where a non-responding name fell out of the statistics, you’ve found a second reason the editions don’t line up, on top of the existence pass.

Why we won’t publish the delta

We hold the earlier editions. We could put two F shares in a table with a difference column and it would look like a trend. We won’t, because the two numbers describe different inventories, so the difference column would be measuring how we built the list, and a reader would take it as a change in the world.

The per-check files for each edition describe that edition’s population and nothing else. Subtracting one from another produces a figure with no population under it. If you see that subtraction quoted somewhere, it wasn’t from us, and the person quoting it hasn’t read this page.

What you can do is hold the method still and watch. The existence pass is now part of how the census builds its population, so the next edition’s graded+dead denominator will be assembled the same way, and when the F share moves after that, the movement will be about the domains.

The same logic applies to a year-on-year claim. If you ask this dataset whether domain security is improving, it can only tell you that a comparison needs the same denominator built the same way at both ends of the interval. September is the first edition built with the existence pass, which makes it the earliest baseline a like-for-like comparison can start from. Measure against an edition before it and you’re comparing two definitions of “domain”, so the gap you get is the definition changing.

Wording for your footnote

Four things belong in a citation of a census figure: the count, the basis it’s a share of, the edition and its as-of date, and a note that the figure is edition-scoped. Paste and adjust the one below.

F grade: 234,955,475 domains, 74.2% of the 316,600,902 graded and dead domains in the September 2026 edition of the defaults.exposed census (figures as of 5 September 2026). Edition-scoped: the September population was built with a two-pass existence check before grading and is not comparable with earlier editions.

For a per-check claim, swap the basis and say so: “of the 315,211,826 domains in the September 2026 edition where the checks ran”. For a claim about the size of the census, use scanned, 347,691,016, and don’t attach a grade share to it.

If your piece needs the current values rather than a frozen quote, point your reader at the census data page linked in the footnote, where each band and each check is listed with its own denominator. The dates on that page move with each edition, which is the reason a footnote should state the as-of date rather than rely on the link.

The same grader, applied to one domain

The grader that produced the 74.2% is the one behind the free scan on this site. Run the domain you’re writing about, or your own, and you’ll get the same checks with the same thresholds. The DMARC policy check reads the record as the census reads it, and DNS is resolved as the existence pass resolves it. The letter grade uses the scale the band you’re citing comes from. You’ll also see which state each check ended in, which is the detail a headline share hides.

That report is the same measurement the census makes, on one domain, and reading it is a quick way to check that the figure you’re about to quote means what you think it does.

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. Census numbers move every month; the current values are on the census data page.