DNSSEC · Sweden (domains)

What share of domains in Sweden have no validated DNSSEC (unsigned, or signed with no DS at the parent)?

55.62%

55.62% of domains in Sweden (95% CI 48.09–62.9%), measured across 169 domains on 2026-08-11.

signed: 44.38%broken_chain: 17.16%unsigned: 38.46%
signed · 44.38%broken_chain · 17.16%unsigned · 38.46%
Trend

Measured every Tuesday since 2026-08-01 — 5 observations to date. Last measured 2026-08-11.

How this is measured

local probe (deliberately, ADR-0009): DNSKEY at the child, then DS at the parent. Denominator: any.

Passive measurement: a single DNS lookup, TLS handshake, or homepage GET per domain. Aggregate-only; no individual company is named. 95% Wilson confidence intervals. Population: domains sampled from the Common Crawl web graph, filtered to those that do email. Parked domains excluded. Snapshot: common-crawl-domain-stratified-c400-g2500-seed20260729.

Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.

Check a specific domain against this control with the free Email authentication audit.

Why it matters

broken_chain is the quiet failure and the reason this metric exists — DNSKEY published but no DS at the parent means the zone is signed and unverifiable. The operator has done the work, the dashboard says DNSSEC is on, and no resolver on earth validates it. Unsigned is merely the default.

Limits of this measurement

Must be measured locally. The DomainAPI health endpoint exposes no DNSSEC state and resolves DS at the child, which cannot distinguish broken_chain from signed.

The same check, other segments

Show the remaining 64 segments

Share or cite this figure

Reuse is free under CC BY 4.0 — attribution to Quiet Failures is all we ask.

Post on X

Embed this stat

Free to reuse under CC BY 4.0 — the card links back and updates as the data does.

<iframe src="https://quietfailures.com/embed/dnssec/se" width="380" height="210" style="border:0;max-width:100%" loading="lazy" title="What share of domains in Sweden have no validated DNSSEC (unsigned, or signed with no DS at the parent)?"></iframe>