Total Rows: 731775 Security Headers Grades: A 64,669 A+ 8,635 B 52,978 C 37,333 D 146,685 E 22,463 F 397,991 R 1,021 Sites using strict-transport-security: 215,993 Sites using content-security-policy: 162,808 Sites using content-security-policy-report-only: 8,867 Sites using x-webkit-csp: 562 Sites using x-content-security-policy: 2,994 Sites using public-key-pins: 533 Sites using public-key-pins-report-only: 9 Sites using x-content-type-options: 279,720 Sites using x-frame-options: 293,681 Sites using x-xss-protection: 146,851 Sites using x-download-options: 35,610 Sites using x-permitted-cross-domain-policies: 44,753 Sites using access-control-allow-origin: 44,225 Sites using referrer-policy: 213,495 Sites using feature-policy: 4,145 Sites using permissions-policy: 97,458 Sites using report-to: 257,356 Sites using nel: 254,310 Sites using security.txt: 8,744 Sites redirecting to HTTPS: 590,134 Sites using Let's Encrypt certificate: 273,133 Sites using EV Certificates: 3,845 Top 10 Server headers: cloudflare 320,414 nginx 94,634 Apache 60,630 LiteSpeed 20,741 Microsoft-IIS/10.0 13,356 AmazonS3 7,813 nginx/1.24.0 (Ubuntu) 7,320 openresty 7,172 Vercel 6,687 CloudFront 5,516 Top 10 TLDs: .com 320,318 .net 31,401 .org 30,052 .ru 26,147 .uk 25,789 .de 24,043 .br 13,450 .nl 10,067 .jp 9,586 .in 8,587 Top 10 Certificate Issuers: C = US, O = Google Trust Services, CN = WE1 171,422 C = US, O = Let's Encrypt, CN = R12 71,571 C = US, O = Let's Encrypt, CN = R13 71,525 C = US, O = Let's Encrypt, CN = E7 65,076 C = US, O = Let's Encrypt, CN = E8 64,663 C = GB, O = Sectigo Limited, CN = Sectigo Public Server Authentication CA DV R36 17,110 C = US, O = Amazon, CN = Amazon RSA 2048 M04 15,166 C = US, O = Amazon, CN = Amazon RSA 2048 M01 12,707 C = US, O = DigiCert Inc, CN = DigiCert Global G2 TLS RSA SHA256 2020 CA1 8,118 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2 7,456 TLS Protocol Versions: TLSv1.3 505,528 TLSv1.2 63,929 TLSv1.0 97 Top 10 Cipher Suites: TLS_AES_256_GCM_SHA384 431,774 TLS_AES_128_GCM_SHA256 71,802 ECDHE-RSA-AES256-GCM-SHA384 29,155 ECDHE-RSA-AES128-GCM-SHA256 20,449 ECDHE-ECDSA-CHACHA20-POLY1305 5,371 ECDHE-RSA-CHACHA20-POLY1305 2,793 ECDHE-ECDSA-AES256-GCM-SHA384 2,575 TLS_CHACHA20_POLY1305_SHA256 1,952 ECDHE-RSA-AES256-SHA384 1,356 ECDHE-ECDSA-AES128-GCM-SHA256 1,225 Top 10 PFS Key Exchange Params: X25519, 253 bits 518,207 ECDH, P-256, 256 bits 34,765 ECDH, P-384, 384 bits 11,214 ECDH, P-521, 521 bits 4,528 DH, 1024 bits 237 DH, 2048 bits 161 X448, 448 bits 20 DH, 4096 bits 17 DH, 3072 bits 4 Top Key Sizes: 256 bit 288,654 2048 bit 234,251 4096 bit 35,510 384 bit 7,414 3072 bit 3,258 1024 bit 52 8192 bit 12 2056 bit 2 Sites using CAA: 43,679 HTTP Protocol Versions: http/2.0 511,696 http/1.1 219,448 http/1.0 607