Total Rows: 810563 Security Headers Grades: A 43,629 A+ 7,806 B 65,607 C 48,024 D 170,234 E 20,774 F 453,199 R 1,290 Sites using strict-transport-security: 243,551 Sites using content-security-policy: 117,484 Sites using content-security-policy-report-only: 8,882 Sites using x-webkit-csp: 701 Sites using x-content-security-policy: 3,655 Sites using public-key-pins: 910 Sites using public-key-pins-report-only: 12 Sites using x-content-type-options: 266,240 Sites using x-frame-options: 283,850 Sites using x-xss-protection: 174,069 Sites using x-download-options: 39,289 Sites using x-permitted-cross-domain-policies: 46,997 Sites using access-control-allow-origin: 53,132 Sites using referrer-policy: 166,935 Sites using feature-policy: 5,316 Sites using permissions-policy: 82,575 Sites using report-to: 230,997 Sites using nel: 227,377 Sites using security.txt: 9,545 Sites redirecting to HTTPS: 645,489 Sites using Let's Encrypt certificate: 238,810 Sites using EV Certificates: 5,422 Top 10 Server headers: cloudflare 301,109 nginx 127,131 Apache 76,372 LiteSpeed 23,618 Microsoft-IIS/10.0 16,942 AmazonS3 9,337 nginx/1.18.0 (Ubuntu) 8,366 openresty 6,129 Vercel 6,052 CloudFront 4,970 Top 10 TLDs: .com 367,732 .net 37,033 .ru 36,032 .org 35,432 .de 18,087 .br 15,036 .uk 14,460 .jp 10,554 .in 9,300 .nl 8,438 Top 10 Certificate Issuers: C = US, O = Google Trust Services, CN = WE1 222,930 C = US, O = Let's Encrypt, CN = R10 91,177 C = US, O = Let's Encrypt, CN = R11 89,972 C = US, O = Let's Encrypt, CN = E6 28,850 C = US, O = Let's Encrypt, CN = E5 28,568 C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA 23,799 C = US, O = Amazon, CN = Amazon RSA 2048 M02 17,052 C = US, O = Amazon, CN = Amazon RSA 2048 M03 16,801 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2 10,727 C = US, O = DigiCert Inc, CN = DigiCert Global G2 TLS RSA SHA256 2020 CA1 9,362 TLS Protocol Versions: TLSv1.3 536,159 TLSv1.2 98,820 TLSv1.0 206 Top 10 Cipher Suites: TLS_AES_256_GCM_SHA384 453,199 TLS_AES_128_GCM_SHA256 79,117 ECDHE-RSA-AES256-GCM-SHA384 46,621 ECDHE-RSA-AES128-GCM-SHA256 32,825 ECDHE-ECDSA-CHACHA20-POLY1305 6,316 ECDHE-RSA-CHACHA20-POLY1305 4,799 TLS_CHACHA20_POLY1305_SHA256 3,843 ECDHE-ECDSA-AES256-GCM-SHA384 3,190 ECDHE-RSA-AES256-SHA384 2,273 ECDHE-ECDSA-AES128-GCM-SHA256 1,307 Top 10 PFS Key Exchange Params: X25519, 253 bits 553,233 ECDH, P-256, 256 bits 59,201 ECDH, P-384, 384 bits 15,503 ECDH, P-521, 521 bits 6,002 DH, 1024 bits 395 DH, 2048 bits 278 DH, 4096 bits 20 X448, 448 bits 18 DH, 3072 bits 2 Top Key Sizes: 2048 bit 307,156 256 bit 272,719 4096 bit 41,920 384 bit 8,947 3072 bit 3,783 1024 bit 102 8192 bit 21 2056 bit 2 521 bit 1 Sites using CAA: 58,654 HTTP Protocol Versions: http/2.0 548,254 http/1.1 261,502 http/1.0 760