Skip to content
DnsLister Forum

Where domain hunters compare notes

We graded 432 million domains. Here is what we found, and what owners did with it.

I run a free domain security scanner. It grades every live domain on the internet each month and publishes the results as open data. The August run covered 376,928,750 domains across 1,471 top-level domains.

The numbers are what you would expect.

78% of all domains score an F. Fewer than 1 in 5,000 score a perfect A+. Most domains have at least one configuration that lets a stranger send email as them, to their own customers, with their own logo, from an address their customers would trust.

That part gets said a lot. Here is the part that does not.

What happened when owners got a fix list

Between 6 July and 29 August, 301 distinct domains scanned. Twenty-two came back more than once with a real gap between visits, which is what it looks like when someone goes away, makes a change, and checks again. Ten had requested the fix guide. Twelve had not.

Got the guide No guide
Share that improved 70% (7 of 10) 25% (3 of 12)
Mean score change +10.8 pts +1.6 pts

One domain scanned at an F on 17 August. Nothing for four days. On 21 August at 13:26 it scanned again, still an F. At 13:34 the owner requested the fix list. At 13:51, seventeen minutes later, they had already made changes. They came back eleven times over ten days. Fifteen failing checks became four. They finished on an A.

Another went from F to A in twelve hours. A third hit a perfect score in 23 hours. One went from C to B in fifty minutes, three security headers in one sitting.

These are people going into live production settings on a stranger's say-so because somebody gave them an ordered list. Nobody in the data looks unwilling.

Where almost everyone stopped

Security headers got repaired fourteen times. DNS records three. But the one record that decides whether someone can forge invoices to your customers moved exactly once.

I do not think that is apathy. Fixing a header costs nothing if it goes wrong. Fixing the impersonation record risks bouncing your own outbound mail, and you find out when a customer calls asking where their invoice went. So people fix the safe ones and leave the one that matters, because the one that matters requires knowing who actually sends your mail, and often nobody inside the company knows anymore.

Every adoption report for a decade has blamed owner apathy. The data suggests the real problem is that nobody handed owners an ordered list and told them which fix to do last.

You can grade your own domain in about 20 seconds: defaults.exposed

No sign-up. The first fix is free with a breakdown emailed to you. If your domain is already clean, the result tells you that too.

Source: r/uae_startups · by /u/Tricky_Victory_8519

Leave a Reply

Your email address will not be published. Required fields are marked *