In our measurement not one host in either .ru or .com supports legacy TLS 1.0 or 1.1 — on that the Russian web is level with the rest. The difference lies elsewhere: six in ten under-configured Russian hosts speak only TLS 1.2 and not 1.3, against fewer than four in ten for .com.
Where the numbers come from. Only figures with a stated origin: an independent survey with a citation, and our own checks with the sample and its limits spelled out.
Free online tool — SSL certificate checker: instant results, no signup.
Numbers here come from two places and are kept apart.
An independent survey, cited with its date and coverage. It runs against a list of the world’s most visited sites and does not describe the Russian web.
Our own checks. Between 20 March and 26 August 2026 our SSL checker ran 2,803 checks across 2,249 hosts. This is not a sample of the Russian web. Comparing zones inside the sample is sound; carrying the levels over to "all websites" is not.
Separately, on 27 August 2026, we ran two measurements: a component breakdown across 87 hosts graded B or C, and a protocol-version check across 113 hosts from the general sample.
Scott Helme’s Top 1 Million Analysis — The State of Crypto of 13 June 2026 covers 819,002 responding sites from the Tranco Top 1 Million:
| Version | Sites | Share |
|---|---|---|
| TLS 1.3 | 576,464 | 70.4% |
| TLS 1.2 only | 70,395 | 8.6% |
| TLS 1.1 | 0 | 0% |
| TLS 1.0 | 106 | 0.01% |
The striking part is the zeros at the bottom: legacy protocol versions are extinct at the top of the web. Not one site of 819,000 supports TLS 1.1, and TLS 1.0 survives on a hundred and six.
The same report gives certificate authority shares — Let’s Encrypt 302,116, Google Trust Services 203,436, Amazon 37,690, DigiCert 34,961, Sectigo 29,006 — and validity: 77.4% issued for 48–90 days, the signature of ACME automation.
On 27 August 2026 we checked which protocol versions hosts from the general sample support — 80 per zone, of which 56 and 57 answered:
| Zone | Answered | TLS 1.3 | TLS 1.2 only | TLS 1.0 / 1.1 |
|---|---|---|---|---|
| .ru | 56 | 83.9% | 16.1% | 0% |
| .com | 57 | 80.7% | 19.3% | 0% |
This deserves saying plainly, because it contradicts the common expectation. Not one host in either zone supports TLS 1.0 or 1.1. On this the Russian web is not behind — it is exactly level. If anything our .ru sample runs slightly ahead on TLS 1.3, 83.9% against 80.7%, though a sample this size does not establish that.
Note the gap with the top million too: 70.4% there against over 80% in both of our zones. That is expected — people bring domains here when they are already working on them, while the Tranco list includes long-abandoned sites.
Latest verdict per host across all 2,249:
| Outcome | Hosts | Share |
|---|---|---|
| A / A+ | 1,414 | 62.9% |
| B / C | 414 | 18.4% |
| D–F | 93 | 4.1% |
| TLS does not answer | 328 | 14.6% |
Nearly one checked host in seven never completes a TLS connection at all.
| Zone | Hosts | A / A+ | B / C | D–F | No TLS |
|---|---|---|---|---|---|
| .com | 567 | 70.0% | 13.6% | 2.6% | 13.8% |
| .org | 61 | 67.2% | 11.5% | 3.3% | 18.0% |
| .ru | 858 | 57.7% | 26.0% | 4.0% | 12.4% |
| .net | 49 | 38.8% | 18.4% | 10.2% | 32.7% |
Outright bad configuration (D–F) is almost equally rare: 4.0% against 2.6%. The whole difference lives in the middle band — B/C is twice as common in .ru, 26.0% against 13.6%. Russian sites are not breaking more often; they are more often under-configured.
We re-checked 87 previously B/C-graded hosts and broke the score down by component:
| Where points are lost | .ru (42 hosts) | .com (45 hosts) |
|---|---|---|
| No HSTS | 83% | 87% |
| Key below the scale’s maximum | 90% | 89% |
| No TLS 1.3 (only 1.2 supported) | 60% | 38% |
| Cipher not among the strongest | 45% | 76% |
| Certificate expiring or invalid | 4% | 15% |
The protocol difference is not old versions left on, but the new one left off. Six in ten of the under-configured Russian hosts speak only TLS 1.2, against fewer than four in ten for .com. TLS 1.0 and 1.1 are off everywhere, as the measurement above shows.
Second: missing HSTS is not a Russian trait — 83–87% lack it in both zones, the common gap and the cheapest to close.
On sample size: 42 and 45 hosts is small. The 22-point spread on TLS 1.3 support is large and matches the direction of the independent survey; the cipher difference we do not consider established.
SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freeData collected in Q1 2026. Updated quarterly.
Yes, with attribution to Enterno.io.
Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.