Aggregate dataset — Batch 1

96 Dental Practices, Scanned From Outside. Here's What Your Insurer Would Find.

We ran a passive, external scan against 96 of 100 U.S. dental practice domains (4 failed to scan after repeated retries) in July 2026. 50% had at least one critical-severity finding. The single most common significant gap was email authentication — 96% of practices had no DMARC record configured.

96
Domains Scanned
43.1
Average Score / 100
50%
Have ≥1 Critical Finding
96%
Missing DMARC
This page reflects only what a passive external scan can see — DNS, TLS, exposed services, and public web hygiene. It does not cover MFA enforcement, endpoint monitoring, backups, patch history, or staff training, since none of those are visible from outside a network. See what your insurer checks beyond this.

Grade Distribution

Scored 100 → 0, deducting per unique finding by severity. No domain in this batch scored an A.

B
3 (3%)
C
22 (23%)
D
6 (6%)
F
65 (68%)

Average Score by Category

Higher is healthier. These are the six categories this scan actually measures.

01Threat Intel100
02Compliance / Privacy99.9
03Web Server Hygiene99.2
04TLS / Certificate86.9
05Network Exposure84.7
06Email Authentication70.9

Lowest score in the dataset — and business email compromise drives 58% of the claims insurers actually pay out on.

Email authentication is the clear weak point across the dataset — consistent with the DMARC/SPF/CAA gaps below. Everything else is fairly healthy on average, which tracks with most of these being near-default hosting setups rather than actively misconfigured systems.

Most Common Findings

FindingSeverity% of domains
DMARC not configuredHIGH96%
SPF not configuredHIGH58%
Exposed service (non-cleartext port)MED/HIGH*99%
Certificate invalidCRITICAL39%
Cleartext credentials exposed (FTP)CRITICAL26%
Self-signed certificateHIGH21%
CAA record missingLOW98%
DNSSEC not enabledLOW100%

*Inherited directly from the scan API's own per-port risk label, not assigned by our severity taxonomy.

Not covered by this free scan

These require internal access or documentation — a passive external scan structurally can't see them, no matter how the tooling improves:

Methodology

All checks are passive and external: DNS records, TLS configuration, HTTP response headers, exposed ports, and public breach-exposure data. No authentication was attempted against any system, and no practice's internal network was accessed.

Every discovered subdomain (cPanel, webmail, webdisk, mail, etc.) is scanned, but findings are deduplicated by issue type per practice — the same problem across five subdomains counts once, not five times, so practices on shared hosting with many auto-generated subdomains aren't penalized just for having more surface area.

Scoring starts at 100 and deducts per unique finding: CRITICAL −25, HIGH −15, MEDIUM −8, LOW −3, INFO 0, floored at 0. Taxonomy v1.0 — severity weights are a first pass and may be recalibrated in a future batch.

Refresh Cadence

This dataset is re-run against a larger or updated domain list every 4–6 weeks, with the published numbers updated in place and prior figures kept for longitudinal comparison.

Last updated: July 22, 2026 · Sample size: 96 of 100 domains attempted · Method: passive external scan, see methodology.