Datazag Observatory
See how the internet is changing.
Datazag continuously observes domains, DNS, certificates, email infrastructure and internet routing. The Observatory turns those observations into open statistics you can explore, compare and cite.
Live from the Observatory
Data as of 2026-09-09
367.2M
resolving domains measured
domains in gold.dns_wide that resolve · as of 2026-09-09
Method and denominator →
49.56%
of DMARC records at enforcement
86.2M domains publishing DMARC · as of 2026-09-09
Method and denominator →
97.23%
of multi-origin prefixes are stable multi-homing
193,325 MOAS prefixes observed · as of 2026-09-09
Method and denominator →
7
networks carry half of all attributable domains
51,805 networks observed carrying domains · as of 2026-09-09
Method and denominator →
What it measures
Organized around the questions people ask, not the datasets behind them.
Every section opens with the question it answers, and every figure on it carries a denominator, an as-of date, a source and a method.
Email security posture
Who actually runs the world's email, and how much of it is protected?
SPF, DMARC, MTA-STS and BIMI adoption across every resolving domain, split by whether a domain operates mail, by parking, and by mail provider. Enforcement is measured separately from publication.
Open the section →
Malicious actors
Where is malicious infrastructure being built?
Impersonation detections by platform and brand, and how few networks carry them. Routing anomalies are measured from Datazag's own BGP collection, and the share that turns out to be benign multi-homing is published alongside the share that does not.
Open the section →
Internet infrastructure
Who controls the routes and the hosting?
How few networks carry most of the internet's domains, and what share of prefix announcements carry a valid, missing or invalid RPKI origin claim.
Open the section →
The internet, explained
What do these terms mean, and what does the corpus say about each?
Plain-language explanations of ASN, prefix, MOAS, BGP hijacking, RPKI, SPF, DMARC, BIMI, MTA-STS, CAA, DNSSEC and domain parking, each drawn as a diagram and paired with the figure measured for it.
Open the section →
Population and cadence
Measured over the whole corpus, not sampled from a survey.
Population
Every resolving domain in the Datazag corpus, and the networks, prefixes and certificates it resolves to. A figure states which population it is computed over — resolving domains, mail-operating domains, announced prefixes — because a rate without its denominator is not a measurement.
Cadence
The threat landscape is published daily from the previous complete day. The corpus statistics are re-measured on a stated cadence and each carries the date it describes, with the change since the previous measurement beside it.
Source
Datazag's own DNS, certificate and BGP collection, cross-referenced over time. Routing figures come from Datazag's own BGP feeds checked against public RPKI data, not from a third-party report.
Why it is open
Evidence is more useful when other people can check it.
The Observatory publishes measurements, definitions and methods. It does not argue. Analysts, journalists and researchers can quote any figure freely with attribution, download the data behind it, and follow every number to the page that defines it.
How to cite it
Name the source, the date and the population.
Every figure on the Observatory has a Copy-figure control that produces a citation in this form, and a stable link that survives a rebuild.
Source: Datazag Observatory, 2026-09-09.
DMARC records at enforcement, resolving domains publishing DMARC.
https://observatory.datazag.com/mail#dmarc_enforcedThe statistics are also served as Parquet, so a figure can be checked rather than trusted:
SELECT * FROM read_parquet('https://observatory.datazag.com/observatory_statistics.parquet');Need this intelligence at domain level?
The Observatory publishes population-level figures. The per-domain answers are available as reports, alerts and cloud-native datasets.