IntoDNS.ai data study

The State of Email & DNS Security 2026

We scanned 134 domains 86 well-known brands and 48 security-niche domains — and scored each one on DNS, DNSSEC, IPv6, email authentication and web security. Snapshot dated June 10, 2026.

71/100
Average score
46%
score a D or F
134
domains analyzed

Grade distribution

Every domain earns a letter grade from A+ down to F. Here is how the full corpus breaks down.

A+
0% (0)
A
10% (13)
B
9% (12)
C
36% (48)
D
43% (57)
F
3% (4)

Security control adoption

Share of domains that pass each control, ordered from the biggest gaps first. The controls at the top are where the corpus is weakest — and where most domains have the most to gain. Critical-severity controls are flagged.

MTA-STS policy enforced
email
9% pass (12 of 134)
HTTPS DNS record (SVCB)
security
10% pass (13 of 134)
TLSA records (DANE)
security
15% pass (20 of 134)
DANE configuration valid
security
15% pass (20 of 134)
MTA-STS record present
email
19% pass (25 of 134)
security.txt valid
security
31% pass (42 of 134)
DNSSEC validation OK
Critical
dnssec
41% pass (55 of 133)
MX domains use DNSSEC
email
43% pass (57 of 134)
MX DNSSEC validation OK
email
43% pass (57 of 134)
Verification records reviewed
security
43% pass (57 of 134)
HTTP/3 (QUIC) supported
security
43% pass (58 of 134)
Modern DNSSEC algorithm
dnssec
44% pass (59 of 133)
DNSSEC signed
dnssec
45% pass (60 of 134)
Referrer-Policy header
security
45% pass (60 of 134)
AAAA record present
dns
46% pass (62 of 134)
Website reachable via IPv6
ipv6
46% pass (62 of 134)
BIMI record present
email
46% pass (62 of 134)
BIMI configuration valid
email
46% pass (61 of 134)
Content-Security-Policy header
security
49% pass (65 of 134)
security.txt present
security
51% pass (68 of 134)
SPF policy strict (-all)
email
54% pass (72 of 134)
CAA policy strict
security
54% pass (72 of 134)
CAA records present
security
55% pass (74 of 134)
Mail servers reachable via IPv6
ipv6
57% pass (77 of 134)
X-Frame-Options header
security
57% pass (77 of 134)
X-Content-Type-Options header
security
63% pass (85 of 134)
DMARC policy reject
email
71% pass (95 of 134)
HSTS max-age >= 1 year
security
72% pass (96 of 134)
SOA timers valid
dns
82% pass (110 of 134)
DKIM found
email
82% pass (110 of 134)
HSTS enabled
security
83% pass (111 of 134)
HTTP redirects to HTTPS
Critical
security
87% pass (117 of 134)
NSEC3 RFC 9276 compliant
dnssec
90% pass (120 of 133)
MX servers have FCrDNS
dns
93% pass (125 of 134)
DMARC policy quarantine or better
email
93% pass (125 of 134)
MX servers have PTR records
dns
94% pass (126 of 134)
RRSIG TTL safe
dnssec
95% pass (127 of 133)
Nameservers reachable via IPv6
ipv6
95% pass (127 of 134)
Chain of trust complete
Critical
dnssec
97% pass (129 of 133)
Mail servers not blacklisted
Critical
email
97% pass (130 of 134)
MX records present
dns
98% pass (131 of 134)
DS digest algorithm modern
dnssec
98% pass (131 of 133)
MX records valid
Critical
email
98% pass (131 of 134)
SPF record present
Critical
email
99% pass (133 of 134)
SPF syntax valid
Critical
email
99% pass (133 of 134)
DMARC record present
email
99% pass (132 of 134)
No critical blacklist listings
Critical
email
99% pass (133 of 134)
HTTPS available
Critical
security
99% pass (133 of 134)
A record present
Critical
dns
100% pass (134 of 134)
NS records present
Critical
dns
100% pass (134 of 134)
SOA record present
Critical
dns
100% pass (134 of 134)
Multiple nameservers
dns
100% pass (134 of 134)
SOA serial format
dns
100% pass (134 of 134)
No lame nameservers
dns
100% pass (134 of 134)
Glue records present
dns
100% pass (134 of 134)
WWW record configured
dns
100% pass (134 of 134)
RRSIG signatures valid
dnssec
100% pass (133 of 133)
DNSKEY algorithm secure
dnssec
100% pass (133 of 133)
No sensitive info in TXT
Critical
security
100% pass (134 of 134)
Valid certificate
Critical
security
100% pass (134 of 134)
QUIC UDP reachable
security
100% pass (134 of 134)

TLD breakdown

The most common top-level domains in the corpus and how they score on average.

TLDDomainsAvg score
.com9270
.nl2082
.org970
.io469
Top performers

Hall of Fame

The domains that get it right — top scores across DNS, DNSSEC, IPv6 and email security. Each links to its full report.

DomainGroupGradeScore
overheid.nl
brand
A95
kpn.com
brand
A95
cloudflare.com
brand
A92
hackerone.com
security
A92
belastingdienst.nl
brand
A91
digid.nl
brand
A91
redsift.com
security
A91
internet.nl
security
A91
rijksoverheid.nl
brand
A90
easydmarc.com
security
A90
ncsc.nl
security
A90
globalcyberalliance.org
security
A90
checkpoint.com
security
A90
abnamro.nl
brand
C89
politie.nl
brand
B89
tuta.com
brand
B89
crowdstrike.com
security
B89
rabobank.nl
brand
C88
postnl.nl
brand
C88
hubspot.com
brand
B88

Methodology

This study is a fast, non-intrusive scan of a curated corpus of 134 domains — 86 well-known consumer and enterprise brands plus 48 domains in the security and infrastructure niche. We deliberately mix the two so the numbers reflect both how the mainstream web is configured and how security-focused organisations hold themselves to a higher bar.

Each domain is scored the same way the public IntoDNS.ai scanner scores any domain you enter: through DNS resolution and HTTPS probing only — no credentials, no agents, no impact on the target's servers. Scores aggregate DNS configuration, DNSSEC, IPv6 readiness, email authentication (SPF, DKIM, DMARC, MTA-STS, BIMI) and web-security controls into a single 0–100 score and a letter grade.

Because results come from a single point-in-time scan, transient resolver hiccups or rate-limiting can occasionally understate a domain. We treat inconclusive checks conservatively rather than as confident failures. This snapshot was generated on June 10, 2026. It is a benchmark of observable configuration, not an audit of internal controls or a compliance certificate.

How does your domain compare?

Scan your own domain for free and see exactly where you sit against this corpus — grade, score and a fix list for every gap. No signup required.

Building automation? The same scoring is available through the free public API and the IntoDNS MCP server for AI agents.