In the independent top-million survey of 13 June 2026, 30.9% of sites serve HSTS, 20.8% serve CSP, 12.4% serve Permissions-Policy, and 53.9% score an F. Our own checks run higher on all six headers — by 10–25 points — which follows directly from who brings a domain to a security scanner. The one header where .ru clearly trails .com is HSTS: 54% against 69%.
Where the numbers come from. Only figures with a stated origin: an independent survey with a citation, and our own checks with the sample and its limits spelled out.
Free online tool — website security scanner: instant results, no signup.
Numbers here come from two places and are kept apart.
An independent survey, cited with its date and coverage. Per-header adoption shares are directly comparable — "the header is served or it is not" counts the same everywhere. Letter grades are computed differently by different tools and are not comparable.
Our own checks. Between 19 March and 27 August 2026 our header scanner ran 1,498 checks across 963 hosts. This is not a sample of the Russian web: these are domains somebody chose to check. Comparing zones inside the sample is sound; carrying the levels over to "all websites" is not.
Separately, on 27 August 2026, we requested headers directly from 113 hosts drawn from that history (59 in .ru, 54 in .com).
Scott Helme’s recurring Top 1 Million Analysis of 13 June 2026 covers 819,002 responding sites from the Tranco Top 1 Million. Adoption by header:
| Header | Sites | Adoption |
|---|---|---|
X-Frame-Options | 327,918 | 40.0% |
X-Content-Type-Options | 311,659 | 38.1% |
Strict-Transport-Security | 252,846 | 30.9% |
Referrer-Policy | 229,130 | 28.0% |
Content-Security-Policy | 170,057 | 20.8% |
Permissions-Policy | 101,364 | 12.4% |
The same report gives the grade distribution: F — 53.9%, D — 20.3%, C — 5.0%, B — 8.8%, A — 7.5%, A+ — 1.3%. More than half the web still scores an F. The trend is upward, though: since June 2022 CSP more than doubled (79,549 → 170,057 sites) and Referrer-Policy tripled.
Coverage across the 113 hosts we queried directly, next to the top million:
| Header | Top 1M, Jun 2026 | Ours .ru (59) | Ours .com (54) |
|---|---|---|---|
Strict-Transport-Security | 30.9% | 54% | 69% |
X-Frame-Options | 40.0% | 53% | 56% |
X-Content-Type-Options | 38.1% | 47% | 46% |
Content-Security-Policy | 20.8% | 29% | 39% |
Referrer-Policy | 28.0% | 32% | 31% |
Permissions-Policy | 12.4% | 20% | 22% |
Our sample runs above the top million on all six headers, by 10–25 percentage points. That does not mean the sites we check are better defended than the average site on the web: it follows directly from who brings a domain to a security scanner in the first place. The sampling caveat we attach to every page gets a number here.
The useful part of the comparison: the ranking barely changes. In both populations Permissions-Policy and Content-Security-Policy are the least served. The difference between "the ordinary web" and "operators who pay attention" is in the level, not the priorities.
Latest verdict per host across 961, mean score 50.8 out of 100:
| Grade | Hosts | Share |
|---|---|---|
| A+ | 25 | 2.6% |
| A | 53 | 5.5% |
| B | 80 | 8.3% |
| C | 179 | 18.6% |
| D | 486 | 50.6% |
| F | 138 | 14.4% |
8.1% earn an A or A+; 65% land on D or F. Our scale and the survey’s are computed differently, so the letters cannot be compared — only the per-header shares in the previous section can.
| Zone | Hosts | Mean score | A–B | D–F |
|---|---|---|---|---|
| .org | 58 | 55.1 | 20.7% | 50.0% |
| .com | 228 | 52.3 | 14.9% | 63.2% |
| .ru | 434 | 48.4 | 13.8% | 69.1% |
The spread between zones is about four points — smaller than the spread between everyone and a decent configuration: even the best zone averages 55 out of 100. The one header where .ru clearly trails is HSTS (54% against 69%), and it drags the TLS score down too: in a separate measurement HSTS was missing from 83% of Russian hosts graded B.
X-Content-Type-Options: nosniff and Referrer-Policy — one line each, and they almost never break anything.Permissions-Policy is the most neglected header on the web (12.4% in the top million). Switch off what the page does not use: camera, microphone, geolocation.The tool checks HTTP security headers, SSL/TLS configuration, server info leaks, and protection against common attacks (XSS, clickjacking, MIME sniffing). A grade fromA to F shows overall security level.
Checking Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and more.
TLS version, certificate expiry, chain of trust, HSTS support.
Finding exposed server versions, debug modes, open configs, and directories.
Detailed report explaining each issue with specific steps to fix it.
HTTP header audit
config verification
CSP & HSTS setup
compliance checks
Strict-Transport-Security.Server: Apache/2.4.52 helps attackers find exploits. Hide the version.DENY or SAMEORIGIN.nosniff, browsers may misinterpret file types (MIME sniffing).Content-Security-Policy-Report-Only, monitor violations, then enforce.Server, X-Powered-By, X-AspNet-Version from responses.Security check history and HTTP security header monitoring.
Sign up freeData collected in Q1 2026. Updated quarterly.
Yes, with attribution to Enterno.io.
Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.