CAA Has Been Mandatory Since 2017 but 93.1% of Company Domains Skip It
CAA checking has been mandatory for certificate authorities since 2017, but across 130,700 company domains we checked, 93.1% still don't publish a CAA record.
Data-driven insights on cybersecurity breaches, vulnerabilities, and infrastructure signals.
CAA checking has been mandatory for certificate authorities since 2017, but across 130,700 company domains we checked, 93.1% still don't publish a CAA record.
DMARC has been public since 2012. Across 67,336 company domains we checked, 45.1% have no record at all, and of the rest, most are set to p=none: collecting reports, not enforcing a policy.
Browse observed tech stacks, DNS posture, and open services for organisations. All data sourced from public authority records.