See what lists miss
17.6M
domains that no zone file we receive lists. We found them through certificate transparency.
Zone files are the usual way to list domains. They are not enough.
Internet Infrastructure Intelligence
Datazag measures 360M+ live domains, the global routing table and the mail systems behind them, every day. Then we read it: what each domain is, what it depends on, and what changed. You get meaning, not just records.
Coverage
Intelligence is only as good as what it can see. This is what Datazag observes, and exactly what each figure counts.
Distinct domains that resolve — every name answering with a record or an empty response. Names that no longer exist (NXDOMAIN) and names whose servers failed or timed out are excluded, so this counts the live corpus rather than every domain ever queried.
Measured 27 Sept 2026, 00:25 UTC
Distinct IPv4 addresses that a domain in the measured corpus resolves to, taken over the same population as the domain figure above.
Measured 27 Sept 2026, 00:25 UTC
IPv4 space announced in BGP and attributed to a network, counted once per address however many announcements cover it — a more-specific prefix inside its parent is not counted twice.
Measured 27 Sept 2026, 00:25 UTC
Autonomous systems with ownership and routing context attached, used to place infrastructure in the network that announces it.
Measured 27 Sept 2026, 00:25 UTC
Coverage measured 27 September 2026. What the internet is doing right now — certificates, newly observed domains, routing changes — lives in the Observatory.
Intelligence, not just data
A list of domains is data. Knowing which ones matter is intelligence. Here is what our data shows once it is read. Every figure is measured, dated and linked to its method.
See what lists miss
17.6M
domains that no zone file we receive lists. We found them through certificate transparency.
Zone files are the usual way to list domains. They are not enough.
Know who can take mail
A domain with an MX record is not a mailbox. We classify each one.
See where risk concentrates
7
networks carry half of all domains that sit on a network. 229 carry nine in ten. A problem at one of them reaches a large share of the internet.
Out of 52,700 networks observed carrying domains.
Each domain carries labels a machine can act on: can it take mail, is it parked, who runs its mail, which network hosts it.
Domains, certificates, IPs and networks are linked. One record leads to the rest.
We measure every day. You see what changed, not only what exists.
Every published figure states what it counts, when it was measured and how.
Figures as of 2026-09-27. We publish findings like these at internet scale, with the numbers to check them, in the Observatory.
Who it’s for
Know which domains can take mail, who runs it, and which are parked.
Explore→External exposure and provider concentration, for underwriting and portfolio monitoring.
Explore→Infrastructure intelligence and investigations you can offer across your client base.
Explore→Explainable intelligence delivered into the stack you already run.
Explore→Into your stack
One platform · multiple delivery methods
Reports, alerts, APIs and datasets are not separate products. They are different ways to consume Datazag’s continuously updated infrastructure intelligence.
Datazag Intelligence Platform
Infrastructure Graph
Domains, DNS, certificates, hosting, ASNs, platforms, history, evidence and risk context.
Executive and technical views for domain posture, platform exposure and remediation.
Continuous intelligence for SOC workflows, partner monitoring and platform abuse teams.
Sender diligence for email service providers: assess the domains a sender uses, and get the evidence behind the answer rather than an approve-or-reject verdict.
Infrastructure intelligence in your own warehouse, to join against your own tables. This is the route for enrichment at scale.
Datazag Observatory
Open statistics from Datazag's continuously updated internet graph: email authentication, routing hygiene, hosting concentration, domain parking and impersonation. Explore, compare, visualize and cite — every figure carries its date and population.
The same graph mapped 150 domains from a single signal: read the investigation →
Live from the Observatory
Data as of 2026-09-27
366.6M
resolving domains measured
domains in gold.dns_wide that resolve · as of 2026-09-27
Method and denominator →
49.71%
of DMARC records at enforcement
88.7M domains publishing DMARC · as of 2026-09-27
Method and denominator →
98.08%
of multi-origin prefixes are stable multi-homing
194,370 MOAS prefixes observed · as of 2026-09-27
Method and denominator →
Free Domain Health Report
Datazag reviews public DNS, visible platforms, subdomains, certificates and infrastructure exposure, then sends a detailed multi-page report for technical and executive teams.
Not ready to enter an email? View a sample report
We use publicly observable infrastructure signals. No agent, questionnaire or asset inventory is required.
Generated analysis
The report is generated from live checks, platform fingerprints, subdomain review and infrastructure intelligence.
Multi-page report
example.com
Executive summary
Overall risk · key exposure · priority actions
Platform exposure
Microsoft 365 · Cloudflare · Google Workspace
DNS & subdomain health
SPF · DMARC · MTA-STS · ownership · takeover signals
Technical findings
Evidence, context and prioritized remediation
Recommended action
Review email authentication, exposed platforms and subdomain ownership before attackers exploit weak signals.