Skip to content
RU

Security headers in 2026: what sites actually serve

TL;DR. In the independent top-million survey of 13 June 2026, 30.9% of sites serve HSTS, 20.8% serve CSP, 12.4% serve Permissions-Policy, and 53.9% score an F.

In the independent top-million survey of 13 June 2026, 30.9% of sites serve HSTS, 20.8% serve CSP, 12.4% serve Permissions-Policy, and 53.9% score an F. Our own checks run higher on all six headers — by 10–25 points — which follows directly from who brings a domain to a security scanner. The one header where .ru clearly trails .com is HSTS: 54% against 69%.

Where the numbers come from. Only figures with a stated origin: an independent survey with a citation, and our own checks with the sample and its limits spelled out.

Check your site's security →

Methodology and the limits of this data

Numbers here come from two places and are kept apart.

An independent survey, cited with its date and coverage. Per-header adoption shares are directly comparable — "the header is served or it is not" counts the same everywhere. Letter grades are computed differently by different tools and are not comparable.

Our own checks. Between 19 March and 27 August 2026 our header scanner ran 1,498 checks across 963 hosts. This is not a sample of the Russian web: these are domains somebody chose to check. Comparing zones inside the sample is sound; carrying the levels over to "all websites" is not.

Separately, on 27 August 2026, we requested headers directly from 113 hosts drawn from that history (59 in .ru, 54 in .com).

The independent survey: top 1,000,000, June 2026

Scott Helme’s recurring Top 1 Million Analysis of 13 June 2026 covers 819,002 responding sites from the Tranco Top 1 Million. Adoption by header:

HeaderSitesAdoption
X-Frame-Options327,91840.0%
X-Content-Type-Options311,65938.1%
Strict-Transport-Security252,84630.9%
Referrer-Policy229,13028.0%
Content-Security-Policy170,05720.8%
Permissions-Policy101,36412.4%

The same report gives the grade distribution: F — 53.9%, D — 20.3%, C — 5.0%, B — 8.8%, A — 7.5%, A+ — 1.3%. More than half the web still scores an F. The trend is upward, though: since June 2022 CSP more than doubled (79,549 → 170,057 sites) and Referrer-Policy tripled.

Our checks against the top million

Coverage across the 113 hosts we queried directly, next to the top million:

HeaderTop 1M, Jun 2026Ours .ru (59)Ours .com (54)
Strict-Transport-Security30.9%54%69%
X-Frame-Options40.0%53%56%
X-Content-Type-Options38.1%47%46%
Content-Security-Policy20.8%29%39%
Referrer-Policy28.0%32%31%
Permissions-Policy12.4%20%22%

Our sample runs above the top million on all six headers, by 10–25 percentage points. That does not mean the sites we check are better defended than the average site on the web: it follows directly from who brings a domain to a security scanner in the first place. The sampling caveat we attach to every page gets a number here.

The useful part of the comparison: the ranking barely changes. In both populations Permissions-Policy and Content-Security-Policy are the least served. The difference between "the ordinary web" and "operators who pay attention" is in the level, not the priorities.

Grade distribution in our own checks

Latest verdict per host across 961, mean score 50.8 out of 100:

GradeHostsShare
A+252.6%
A535.5%
B808.3%
C17918.6%
D48650.6%
F13814.4%

8.1% earn an A or A+; 65% land on D or F. Our scale and the survey’s are computed differently, so the letters cannot be compared — only the per-header shares in the previous section can.

ZoneHostsMean scoreA–BD–F
.org5855.120.7%50.0%
.com22852.314.9%63.2%
.ru43448.413.8%69.1%

The spread between zones is about four points — smaller than the spread between everyone and a decent configuration: even the best zone averages 55 out of 100. The one header where .ru clearly trails is HSTS (54% against 69%), and it drags the TLS score down too: in a separate measurement HSTS was missing from 83% of Russian hosts graded B.

What a site owner should do

  1. Start with HSTS — the clearest gap between zones and the cheapest to close: one header. Steps and pitfalls in HSTS and HSTS Preload.
  2. Add X-Content-Type-Options: nosniff and Referrer-Policy — one line each, and they almost never break anything.
  3. Permissions-Policy is the most neglected header on the web (12.4% in the top million). Switch off what the page does not use: camera, microphone, geolocation.
  4. Leave CSP for last, and start in Report-Only. How to read and fix violations: CSP blocked a script; inspect an existing policy with the CSP analyzer.
  5. Check your own domain — the header scanner scores the same components.
HeadersCSP, HSTS, X-Frame-Options, etc.
SSL/TLSEncryption and certificate
ConfigurationServer settings and leaks
Grade A-FOverall security score

Why teams trust us

OWASP
guidelines
15+
security headers
<2s
result
A–F
security grade

How it works

1

Enter site URL

2

Security headers analyzed

3

Get grade A–F

What Does the Security Analysis Check?

The tool checks HTTP security headers, SSL/TLS configuration, server info leaks, and protection against common attacks (XSS, clickjacking, MIME sniffing). A grade fromA to F shows overall security level.

Header Analysis

Checking Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and more.

SSL Check

TLS version, certificate expiry, chain of trust, HSTS support.

Leak Detection

Finding exposed server versions, debug modes, open configs, and directories.

Report with Recommendations

Detailed report explaining each issue with specific steps to fix it.

Who uses this

Security teams

HTTP header audit

DevOps

config verification

Developers

CSP & HSTS setup

Auditors

compliance checks

Common Mistakes

Missing Content-Security-PolicyCSP is the primary XSS defense. Without it, script injection is much easier.
Missing HSTS headerWithout HSTS, HTTPS-to-HTTP downgrade attacks are possible. Enable Strict-Transport-Security.
Server header exposes versionServer: Apache/2.4.52 helps attackers find exploits. Hide the version.
X-Frame-Options not setSite can be embedded in iframe for clickjacking. Set DENY or SAMEORIGIN.
Missing X-Content-Type-OptionsWithout nosniff, browsers may misinterpret file types (MIME sniffing).

Best Practices

Start with basic headersMinimum: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy. Takes 5 minutes.
Implement CSP graduallyStart with Content-Security-Policy-Report-Only, monitor violations, then enforce.
Hide server headersRemove Server, X-Powered-By, X-AspNet-Version from responses.
Configure Permissions-PolicyRestrict camera, microphone, geolocation access — only what is actually used.
Check after every deploySecurity headers can be overwritten during server configuration updates.

Get more with a free account

Security check history and HTTP security header monitoring.

Sign up free

Learn more

Frequently Asked Questions

Is the data current?

Data collected in Q1 2026. Updated quarterly.

Can I cite this?

Yes, with attribution to Enterno.io.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.