Skip to content
RU

TLS in 2026: what the checks actually show

TL;DR. In our measurement not one host in either .ru or .com supports legacy TLS 1.0 or 1.1 — on that the Russian web is level with the rest.

In our measurement not one host in either .ru or .com supports legacy TLS 1.0 or 1.1 — on that the Russian web is level with the rest. The difference lies elsewhere: six in ten under-configured Russian hosts speak only TLS 1.2 and not 1.3, against fewer than four in ten for .com.

Where the numbers come from. Only figures with a stated origin: an independent survey with a citation, and our own checks with the sample and its limits spelled out.

Check your site's SSL →

Methodology and the limits of this data

Numbers here come from two places and are kept apart.

An independent survey, cited with its date and coverage. It runs against a list of the world’s most visited sites and does not describe the Russian web.

Our own checks. Between 20 March and 26 August 2026 our SSL checker ran 2,803 checks across 2,249 hosts. This is not a sample of the Russian web. Comparing zones inside the sample is sound; carrying the levels over to "all websites" is not.

Separately, on 27 August 2026, we ran two measurements: a component breakdown across 87 hosts graded B or C, and a protocol-version check across 113 hosts from the general sample.

The independent survey: top 1,000,000, June 2026

Scott Helme’s Top 1 Million Analysis — The State of Crypto of 13 June 2026 covers 819,002 responding sites from the Tranco Top 1 Million:

VersionSitesShare
TLS 1.3576,46470.4%
TLS 1.2 only70,3958.6%
TLS 1.100%
TLS 1.01060.01%

The striking part is the zeros at the bottom: legacy protocol versions are extinct at the top of the web. Not one site of 819,000 supports TLS 1.1, and TLS 1.0 survives on a hundred and six.

The same report gives certificate authority shares — Let’s Encrypt 302,116, Google Trust Services 203,436, Amazon 37,690, DigiCert 34,961, Sectigo 29,006 — and validity: 77.4% issued for 48–90 days, the signature of ACME automation.

Our version check: legacy is extinct in .ru too

On 27 August 2026 we checked which protocol versions hosts from the general sample support — 80 per zone, of which 56 and 57 answered:

ZoneAnsweredTLS 1.3TLS 1.2 onlyTLS 1.0 / 1.1
.ru5683.9%16.1%0%
.com5780.7%19.3%0%

This deserves saying plainly, because it contradicts the common expectation. Not one host in either zone supports TLS 1.0 or 1.1. On this the Russian web is not behind — it is exactly level. If anything our .ru sample runs slightly ahead on TLS 1.3, 83.9% against 80.7%, though a sample this size does not establish that.

Note the gap with the top million too: 70.4% there against over 80% in both of our zones. That is expected — people bring domains here when they are already working on them, while the Tranco list includes long-abandoned sites.

Grade distribution in our own checks

Latest verdict per host across all 2,249:

OutcomeHostsShare
A / A+1,41462.9%
B / C41418.4%
D–F934.1%
TLS does not answer32814.6%

Nearly one checked host in seven never completes a TLS connection at all.

ZoneHostsA / A+B / CD–FNo TLS
.com56770.0%13.6%2.6%13.8%
.org6167.2%11.5%3.3%18.0%
.ru85857.7%26.0%4.0%12.4%
.net4938.8%18.4%10.2%32.7%

Outright bad configuration (D–F) is almost equally rare: 4.0% against 2.6%. The whole difference lives in the middle band — B/C is twice as common in .ru, 26.0% against 13.6%. Russian sites are not breaking more often; they are more often under-configured.

Where the points are actually lost

We re-checked 87 previously B/C-graded hosts and broke the score down by component:

Where points are lost.ru (42 hosts).com (45 hosts)
No HSTS83%87%
Key below the scale’s maximum90%89%
No TLS 1.3 (only 1.2 supported)60%38%
Cipher not among the strongest45%76%
Certificate expiring or invalid4%15%

The protocol difference is not old versions left on, but the new one left off. Six in ten of the under-configured Russian hosts speak only TLS 1.2, against fewer than four in ten for .com. TLS 1.0 and 1.1 are off everywhere, as the measurement above shows.

Second: missing HSTS is not a Russian trait — 83–87% lack it in both zones, the common gap and the cheapest to close.

On sample size: 42 and 45 hosts is small. The 22-point spread on TLS 1.3 support is large and matches the direction of the independent survey; the cipher difference we do not consider established.

What a site owner should do

  1. Turn TLS 1.3 on. What separates the under-configured Russian hosts is not old protocol left enabled but the new one never enabled. See TLS 1.3 vs TLS 1.2.
  2. Turn HSTS on. The most common gap in both zones, one header — HSTS and HSTS Preload.
  3. Confirm 1.0 and 1.1 really are off. No host in our sample supported them, but the sample does not cover the whole web — check your own domain.
  4. Drop weak cipher suitesweak cipher suites.
  5. Automate certificate issuance. 77.4% of top-million certificates live 48–90 days — the short lifetime is safe because renewal is not manual: free SSL with Let’s Encrypt.
CertificateExpiry, issuer, domains (SAN)
ChainIntermediate and root CA validation
TLS ProtocolTLS version and cipher suite
VulnerabilitiesHeartbleed, POODLE, weak ciphers

Why teams trust us

TLS 1.3
supported
Full
CA chain check
1,761
checks in 30 days
30/14/7
days-to-expiry alerts

How it works

1

Enter domain

2

TLS chain verified

3

Expiry date & vulnerabilities

What Does the SSL Check Cover?

SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.

Certificate Details

Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).

Chain of Trust

Full chain verification: from leaf certificate through intermediates to root CA.

TLS Analysis

Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.

Expiry Alerts

Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.

DV vs OV vs EV Certificates

DV (Domain Validation)
  • Confirms domain ownership only
  • Issued in minutes automatically
  • Free via Let's Encrypt
  • Suitable for most websites
  • Most common certificate type
OV / EV
  • Organization (OV) or Extended Validation (EV)
  • Issued in 1-5 business days
  • Costs $50 to $500/year
  • For finance, e-commerce, government sites
  • Increases user trust

Who uses this

DevOps

SSL certificate monitoring

Security

TLS config audit

SEO

HTTPS as ranking factor

E-commerce

customer trust

Common Mistakes

Expired certificateBrowsers block sites with expired SSL. Set up auto-renewal or monitoring.
Incomplete certificate chainWithout intermediate CA, some browsers and bots cannot verify the certificate.
Mixed content on HTTPS siteHTTP resources on an HTTPS page — the browser lock icon disappears, reducing trust.
Using TLS 1.0/1.1Legacy TLS versions have known vulnerabilities. Use TLS 1.2+ or 1.3.
Domain mismatch in certificateThe certificate must cover all site domains, including www and subdomains.

Best Practices

Set up auto-renewalLet's Encrypt + certbot with cron — certificate renews automatically every 60-90 days.
Enable HSTSStrict-Transport-Security header forces browsers to always use HTTPS.
Use TLS 1.3TLS 1.3 is faster (1-RTT handshake) and safer — legacy ciphers removed.
Monitor expiration datesCreate a monitor on Enterno.io — get notified well before expiration.
Verify chain after renewalAfter certificate renewal, confirm that intermediate certificates are installed.

Get more with a free account

SSL certificate monitoring, check history and alerts 30 days before expiry.

Sign up free

Learn more

Frequently Asked Questions

Is the data current?

Data collected in Q1 2026. Updated quarterly.

Can I cite this?

Yes, with attribution to Enterno.io.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.