Skip to content
RU

HTTP/3 and QUIC in 2026: the real numbers, and why the Russian web trails fivefold

TL;DR. Is HTTP/3 at 21% or 30.4%? Both figures come from Cloudflare and both are right: the difference is whether bots are included, and bots speak HTTP/1.x almost universally.We probed 600 hosts and produced a cut that no open source publishes: in the .ru zone 7.1% of sites advertise…

Is HTTP/3 at 21% or 30.4%? Both figures come from Cloudflare and both are right: the difference is whether bots are included, and bots speak HTTP/1.x almost universally.

We probed 600 hosts and produced a cut that no open source publishes: in the .ru zone 7.1% of sites advertise HTTP/3 support against 36.5% in .com. The same measurement shows the reason, and it has nothing to do with administrators.

Check your site's SSL →

Why HTTP/3 figures oscillate between 21% and 30%

Both numbers come from Cloudflare, and both are correct. The difference is the bot filter, not the measurement:

PopulationHTTP/1.xHTTP/2HTTP/3Period
All requests, humans and bots29%50%21%Jan–Dec 2025
Human traffic only9.7%59.9%30.4%1–26 Aug 2026

Bots overwhelmingly speak HTTP/1.x, so including them drags the HTTP/3 share down. Any figure that does not say whether bots were filtered is misleading.

QUIC as a share of secure HTTP requests for 1–26 August 2026 is 30.7%; on the same chart TLS 1.3 is 66% and TLS 1.2 is 3.2%.

On the claim that "HTTP/3 is declining". It circulates citing roughly 19.8% for July 2026. Live Cloudflare data for a comparable window gives 30.4%; the divergence comes from taking the unfiltered population and presenting it as the general share. Primary sources show no downward trend.

Sites and requests are, once again, different quantities

W3Techs as of 27 August 2026: HTTP/3 is used by 40.3% of websites; by ranking — top 1,000 at 46.1%, top 10,000 at 44.5%, top 100,000 at 43.4%, top 1M at 44.6%.

The gap against Cloudflare’s 30.4% is expected: that is a share of requests, this a share of sites. A site can support HTTP/3 and receive almost no traffic over it if its visitors arrive on older clients.

A caveat worth knowing: W3Techs nowhere documents how it detects HTTP/3 support. The common claim that it reads alt-svc or the DNS HTTPS record appears nowhere on their pages. The correct phrasing is "detected as using HTTP/3", with no mechanism assumed.

Browsers are barely a constraint: 93.74% support by usage-weighted page views (caniuse data of 24 August 2026). One notable exception — current versions of Samsung Internet do not support HTTP/3.

Our measurement: the .ru zone advertises HTTP/3 five times less often

On 27 August 2026 we requested 150 hosts per zone over HTTPS and checked for an alt-svc header naming h3 — that is, whether the site advertises HTTP/3 support:

ZoneRespondedAdvertise h3Share
.com1154236.5%
.net942627.7%
.org1092825.7%
.ru11287.1%

Caveats: these are domains somebody brought to our tools, not a random slice of a zone, so the .ru figure cannot stand in for the Russian web; comparing zones is sound, as they were collected identically. Non-responders are excluded from the denominator. And crucially — alt-svc means advertised support, not connections that actually happened.

An indirect check: our 36.5% for .com sits between Cloudflare’s 30.4% (share of requests) and W3Techs’ 40.3% (share of sites), so the measurement does not stand apart from independent ones.

The same measurement shows the reason for the gap

We looked at which server was returned by those advertising h3. The picture explains the gap entirely:

ZoneAdvertise h3Of which behind Cloudflare
.com4227
.org2818
.net2614
.ru83

In .com two thirds of the sites advertising HTTP/3 sit behind one particular CDN. In other words, "does this site support HTTP/3" in practice nearly coincides with "is it behind a CDN" rather than with anything the owner configured.

A second source confirms this independently. Per the Web Almanac (July 2025 crawl), mobile HTML delivered through a CDN went over HTTP/3 in 29% of cases; delivered straight from the origin, in 0%. For third-party resources the same chasm: 45% via CDN against 7% from origin.

The practical conclusion for a Russian site owner: HTTP/3 can be switched on in your own nginx, but the fastest route to it is the same as for other network improvements — which is also why CDN penetration in .ru is a story of its own.

To check what your site sends, use the protocol test.

CertificateExpiry, issuer, domains (SAN)
ChainIntermediate and root CA validation
TLS ProtocolTLS version and cipher suite
VulnerabilitiesHeartbleed, POODLE, weak ciphers

Why teams trust us

TLS 1.3
supported
Full
CA chain check
1,761
checks in 30 days
30/14/7
days-to-expiry alerts

How it works

1

Enter domain

2

TLS chain verified

3

Expiry date & vulnerabilities

What Does the SSL Check Cover?

SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.

Certificate Details

Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).

Chain of Trust

Full chain verification: from leaf certificate through intermediates to root CA.

TLS Analysis

Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.

Expiry Alerts

Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.

DV vs OV vs EV Certificates

DV (Domain Validation)
  • Confirms domain ownership only
  • Issued in minutes automatically
  • Free via Let's Encrypt
  • Suitable for most websites
  • Most common certificate type
OV / EV
  • Organization (OV) or Extended Validation (EV)
  • Issued in 1-5 business days
  • Costs $50 to $500/year
  • For finance, e-commerce, government sites
  • Increases user trust

Who uses this

DevOps

SSL certificate monitoring

Security

TLS config audit

SEO

HTTPS as ranking factor

E-commerce

customer trust

Common Mistakes

Expired certificateBrowsers block sites with expired SSL. Set up auto-renewal or monitoring.
Incomplete certificate chainWithout intermediate CA, some browsers and bots cannot verify the certificate.
Mixed content on HTTPS siteHTTP resources on an HTTPS page — the browser lock icon disappears, reducing trust.
Using TLS 1.0/1.1Legacy TLS versions have known vulnerabilities. Use TLS 1.2+ or 1.3.
Domain mismatch in certificateThe certificate must cover all site domains, including www and subdomains.

Best Practices

Set up auto-renewalLet's Encrypt + certbot with cron — certificate renews automatically every 60-90 days.
Enable HSTSStrict-Transport-Security header forces browsers to always use HTTPS.
Use TLS 1.3TLS 1.3 is faster (1-RTT handshake) and safer — legacy ciphers removed.
Monitor expiration datesCreate a monitor on Enterno.io — get notified well before expiration.
Verify chain after renewalAfter certificate renewal, confirm that intermediate certificates are installed.

Get more with a free account

SSL certificate monitoring, check history and alerts 30 days before expiry.

Sign up free

Learn more

Frequently Asked Questions

Why aren't origin servers moving to HTTP/3?

Three reasons: (1) nginx HTTP/3 stable only since 1.25 (March 2023); (2) kernel UDP performance on Linux trails TCP in non-CDN scenarios; (3) operational complexity of QUIC (retries, NAT rebinding).

Is HTTP/3 always faster?

On fast wired connections it is a close call (HTTP/2 TCP + BBR is comparable). The gain shows up on mobile/Wi-Fi with packet loss — typically 100-200ms TTFB.

Do I need to change application code?

No. HTTP/3 is a transport-level change; the API is identical to HTTP/2. Only proxy/edge server configuration changes.

How do I check if a site uses HTTP/3?

Enterno SSL/TLS Checker shows supported protocols including HTTP/3. Or at the terminal: curl -I --http3 https://example.com.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.