Total Rows: 812866 Security Headers Grades: A 43,697 A+ 7,649 B 65,858 C 48,250 D 172,111 E 20,770 F 453,312 R 1,219 Sites using strict-transport-security: 244,215 Sites using content-security-policy: 119,291 Sites using content-security-policy-report-only: 8,936 Sites using x-webkit-csp: 705 Sites using x-content-security-policy: 3,683 Sites using public-key-pins: 906 Sites using public-key-pins-report-only: 12 Sites using x-content-type-options: 268,207 Sites using x-frame-options: 284,490 Sites using x-xss-protection: 175,831 Sites using x-download-options: 40,758 Sites using x-permitted-cross-domain-policies: 46,945 Sites using access-control-allow-origin: 53,196 Sites using referrer-policy: 167,363 Sites using feature-policy: 5,334 Sites using permissions-policy: 82,565 Sites using report-to: 230,957 Sites using nel: 227,356 Sites using security.txt: 9,511 Sites redirecting to HTTPS: 646,218 Sites using Let's Encrypt certificate: 238,960 Sites using EV Certificates: 5,449 Top 10 Server headers: cloudflare 301,396 nginx 128,609 Apache 76,392 LiteSpeed 23,679 Microsoft-IIS/10.0 16,984 AmazonS3 9,372 nginx/1.18.0 (Ubuntu) 8,423 openresty 6,131 Vercel 6,036 CloudFront 5,015 Top 10 TLDs: .com 368,126 .net 37,081 .ru 36,127 .org 35,508 .de 18,093 .br 15,074 .uk 14,385 .jp 10,591 .in 9,287 .cn 8,642 Top 10 Certificate Issuers: C = US, O = Google Trust Services, CN = WE1 222,875 C = US, O = Let's Encrypt, CN = R10 91,189 C = US, O = Let's Encrypt, CN = R11 90,032 C = US, O = Let's Encrypt, CN = E6 28,830 C = US, O = Let's Encrypt, CN = E5 28,665 C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA 23,821 C = US, O = Amazon, CN = Amazon RSA 2048 M02 17,143 C = US, O = Amazon, CN = Amazon RSA 2048 M03 16,875 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2 10,709 C = US, O = DigiCert Inc, CN = DigiCert Global G2 TLS RSA SHA256 2020 CA1 9,410 TLS Protocol Versions: TLSv1.3 536,752 TLSv1.2 98,930 TLSv1.0 216 Top 10 Cipher Suites: TLS_AES_256_GCM_SHA384 453,471 TLS_AES_128_GCM_SHA256 79,410 ECDHE-RSA-AES256-GCM-SHA384 46,629 ECDHE-RSA-AES128-GCM-SHA256 32,868 ECDHE-ECDSA-CHACHA20-POLY1305 6,344 ECDHE-RSA-CHACHA20-POLY1305 4,825 TLS_CHACHA20_POLY1305_SHA256 3,871 ECDHE-ECDSA-AES256-GCM-SHA384 3,179 ECDHE-RSA-AES256-SHA384 2,268 ECDHE-ECDSA-AES128-GCM-SHA256 1,313 Top 10 PFS Key Exchange Params: X25519, 253 bits 553,864 ECDH, P-256, 256 bits 59,306 ECDH, P-384, 384 bits 15,463 ECDH, P-521, 521 bits 6,012 DH, 1024 bits 402 DH, 2048 bits 277 DH, 4096 bits 19 X448, 448 bits 18 DH, 3072 bits 2 Top Key Sizes: 2048 bit 307,906 256 bit 272,666 4096 bit 41,953 384 bit 8,933 3072 bit 3,779 1024 bit 102 8192 bit 21 2056 bit 1 521 bit 1 Sites using CAA: 58,803 HTTP Protocol Versions: http/2.0 548,944 http/1.1 263,113 http/1.0 762