Web Security Statistics 2026

Last updated July 2026

A current snapshot of how well the web is secured, drawn from two authoritative datasets. Transport and HTTP-header figures come from the HTTP Archive Web Almanac 2025 Security chapter, which measures millions of sites. Email authentication and DNS figures come from DomainIntel's own scan of the Tranco top 10,000 domains. Every number below links to its source, and anything that could not be sourced exactly was left out rather than estimated.

Transport security: HTTPS and TLS

Encryption in transit is now close to universal. The protocol underneath it has shifted decisively to the modern version.

98.8%
of mobile requests are sent over HTTPS
Web Almanac 2025
-4.5%
year-over-year drop in TLS 1.2 use as sites move to the newer TLS 1.3
Web Almanac 2025

The headline story is the gap between having encryption and configuring it well. Nearly every site speaks HTTPS, but the security that depends on correct headers and policies, below, lags far behind. To inspect a single site's certificate and protocol, use the SSL checker.

HTTP security headers

Headers are where the picture gets uneven. Adoption is rising every year, but the headers that stop clickjacking, enforce HTTPS, and constrain scripts are still a minority.

36%
of mobile pages send an HSTS header to enforce HTTPS (up 6 points year over year)
Web Almanac 2025
21.9%
of pages set a Content-Security-Policy, up from 18.5% in 2024
Web Almanac 2025

Content-Security-Policy is the strongest riser among security headers year over year, but four in five sites still have none. See the guides on HSTS, CSP and X-Frame-Options, or run the security header checker on your own site.

Email authentication and DNS

These figures are DomainIntel's own, from a scan of the Tranco top 10,000 domains (data as of June 2026). The pattern mirrors the headers above: publishing a record is common, enforcing it is not.

75%
of top domains publish an SPF record
DomainIntel scan of 10,000 domains
66.7%
publish a DMARC record, but only 49.3% enforce it (quarantine or reject)
DomainIntel scan of 10,000 domains
46.6%
of domains with DMARC use the strongest policy, p=reject; 26.1% only monitor with p=none
DomainIntel scan of 10,000 domains
12.2%
of top domains are DNSSEC-signed
DomainIntel scan of 10,000 domains
20.5%
publish a CAA record to restrict which authorities can issue their certificates
DomainIntel scan of 10,000 domains

The full methodology, provider market share, and per-policy breakdown are in the State of Domain Security 2026 report. Check any single domain's SPF and DMARC with the DMARC checker, or read what is DMARC.

Cite this page

You are welcome to cite these figures. A link back is appreciated.

DomainIntel. "Web Security Statistics 2026." DomainIntel.app, July 2026. https://domainintel.app/research/web-security-statistics-2026

Sources: HTTP Archive Web Almanac 2025, Security and DomainIntel, State of Domain Security 2026.