Why So Many Small-Business Websites Score a D, and How to Climb Out
We ran the same free scan across every small-business website in whole cities and published the aggregate. The typical independent business scored a D. Not an F, not an A, a D, over and over. This is why that keeps happening, and it is almost never what site owners assume.
By Nathan Cross, Co-Founder, Network & Security Engineering·
What we saw when we scanned entire regions
CyberBadger Labs runs BadgerScan's free, passive scan across every small-business website in a region, drawn from public map data, then publishes the results. The figures are aggregated and anonymized: no individual business is ever named, and nothing is published below a minimum sample size. The scan only reads what any browser or mail server can already see, so no one is probed or tested.
One pattern shows up in city after city: the typical independent business scores a D. That surprised us less than it surprises most owners, because a D is not the score of a broken or hacked site. It is the score of a site that works fine, looks fine, and quietly skips two or three of the settings that a security grade weighs heavily. The interesting question is not that the grade is a D, it is why so many different sites land on the exact same grade.
The grades cluster at the ends, not the middle
If you plotted every site, you would not get a smooth bell curve centred on C. You get two clumps: a group up at A and B, and a much larger group down at D, with a thin middle between them. A security grade is not a gentle spectrum where each small flaw shaves off a point. It hinges on a handful of near pass-or-fail settings. Get the big ones right and you land in the A to B range. Miss one particular setting and you drop toward a D almost regardless of how tidy everything else is.
That is what makes the result so consistent. Thousands of small businesses use different themes, hosts, and builders, but they tend to make the same one or two omissions, so they land on the same grade. Understanding which omission does the damage is the whole story.
The setting behind most D grades: DMARC
The single biggest driver is email authentication, and specifically DMARC. A domain with no DMARC record, or one set to p=none, which only monitors and enforces nothing, can be impersonated: a stranger can send email that looks like it genuinely came from your business. You can check your own in seconds with our SPF and DMARC checker, and there is a plain-English walkthrough in is your business email spoofable.
We grade a missing or unenforced DMARC policy as a high-severity gap, and we do it on purpose. Spoofable business email is not theoretical: it is the mechanism behind invoice fraud and phishing aimed at your own customers and staff. In region after region, the majority of independent businesses have no DMARC enforcement at all (CyberBadger Labs), which is exactly why so many sites start their grade already in a hole. The fix is a DNS change, not a rebuild, and we lay it out step by step in how to move DMARC off p=none.
Why one gap can pull the whole grade down
Here is the mechanism, in plain terms. Your overall grade is built half from your single worst area and half from your overall breadth across every category. That design is deliberate: it stops a site with one seriously exposed area from hiding behind nine clean ones and scoring an undeserved A. A high-severity gap like unenforced DMARC drops your email score to the floor, and because half of your headline grade comes from that worst area, a floored email score puts you within arm's reach of a D on its own.
From there, to hold even a C you would need almost everything else to be close to perfect. Real small-business sites are not: the same sites that skip DMARC usually also skip HSTS, are missing security headers, and sometimes have no SPF record either. Each of those nudges the breadth half downward, and the two halves together slide the grade into the D band. A useful way to see how strict this is: a site with no DMARC and no SPF cannot score better than a low D even if every other check on the page is perfect. Those two email settings alone are enough to cap the grade.
Franchises and chains are not immune
You might expect national brands and franchises, with real IT budgets, to sit safely up in the A range. On the Labs page we set the chains and franchises aside and grade them as a separate group, so you can compare them directly against the local independents. They do score better on average, but many still land in the C to D range, and for exactly the same reasons.
The catch is that email authentication and security headers are process and platform problems, not budget problems. A franchise location often runs a microsite that inherited the brand's look but not its email authentication, or sits on a marketing platform where nobody ever published a DMARC record or turned on the headers. Money does not automatically fix a setting that no one owns. That is the quietly useful lesson of the comparison: the gap between a local plumber and a national chain is far smaller than either would guess, because the weak spots are the same handful of unconfigured defaults.
How to climb from a D to an A
The encouraging flip side is that because a few settings do most of the damage, a few fixes do most of the climbing, and none of them are a redesign. In rough order of payoff: get DMARC to real enforcement (move from p=none to quarantine and then reject once your SPF and DKIM are aligned and your legitimate mail passes); publish or correct your SPF record; turn on HSTS and the core security headers; and make sure you enforce HTTPS with a valid, trusted certificate, which you can confirm with our SSL and TLS checker.
Every one of those is a DNS or server-config change measured in minutes, not a rebuild measured in weeks. The Labs page is the aggregate view of your whole region; the free scan is your own specific version of it. Run a free scan to see your grade and get the same gaps back as an ordered fix-list, and if you would rather have a local team do the fixing, that is what we are here for.
See your own version of the D
The Labs page shows the whole region; a free BadgerScan shows you. Run the free scan to get your grade and the same gaps back as a clear, ordered fix-list, no login. Based in Hamilton and Burlington, our team can also do the fixing, from DMARC enforcement to the security headers, so you actually climb out of the D.
Run a free security scanFrequently asked questions
My site got a D but it isn't hacked. Why?
A grade measures exposure and hardening, not whether you have been compromised. A D almost always means your site works fine but skips a few settings the grade weighs heavily, most often email authentication (DMARC) and HTTP security headers. It is a list of fixable gaps, not a sign of a breach.
Why does a missing DMARC record hurt the grade so much?
Because unenforced or missing DMARC lets a stranger send email that looks like it came from your domain, which is the mechanism behind invoice fraud and customer phishing. We treat that as a high-severity gap, and the grade is built so that your worst area carries real weight. A floored email score on its own puts most sites within reach of a D.
Do big brands and franchises score better than local businesses?
On average, a little, but not as much as you would expect. On the CyberBadger Labs page we grade chains and franchises as a separate group, and many still land in the C to D range. Email authentication and security headers are process and platform problems, not budget problems, so a franchise microsite skips them just as often as a local shop.
How do I raise my website's security grade?
Start with email: move DMARC from p=none to enforcement once SPF and DKIM are aligned, and publish a correct SPF record. Then turn on HSTS and the core security headers, and confirm you enforce HTTPS with a valid certificate. These are DNS and config changes, not a rebuild. Running a free BadgerScan gives you your grade and the fixes in priority order.