The independent top-million survey of June 2026 puts TLS 1.3 support at 70.4%. In our own check of 27 August the zones run level: .ru at 83.9%, .com at 80.7%, and not one host in either supports legacy 1.0 or 1.1.
The Russian web only trails inside the under-configured part of the sample: among hosts graded B or C, six in ten Russian ones cannot speak TLS 1.3 against fewer than four in ten for .com.
Free online tool — SSL certificate checker: instant results, no signup.
Comparing the world and the Russian web on TLS 1.3 support is possible. Speaking of adoption velocity is not: that needs a series of observations over time, and we have a single point. So this page reports the state at the end of August 2026 and nothing about a rate of change.
The independent survey is cited with its date and coverage. Our own measurement was taken on 27 August 2026: 80 domains per zone drawn from those users brought to our tools, of which 56 answered in .ru and 57 in .com. This is not a sample of the Russian web and its level does not transfer to "all websites"; comparing the zones to each other is sound.
Scott Helme’s Top 1 Million Analysis — The State of Crypto of 13 June 2026, 819,002 responding sites from Tranco Top 1 Million:
| Version | Sites | Share |
|---|---|---|
| TLS 1.3 | 576,464 | 70.4% |
| TLS 1.2 only | 70,395 | 8.6% |
| TLS 1.1 | 0 | 0% |
| TLS 1.0 | 106 | 0.01% |
| Zone | Answered | TLS 1.3 | TLS 1.2 only | TLS 1.0 / 1.1 |
|---|---|---|---|---|
| .ru | 56 | 83.9% | 16.1% | 0% |
| .com | 57 | 80.7% | 19.3% | 0% |
The common expectation — that the Russian web trails — does not hold on this data. The zones run level, and .ru is marginally ahead, though a three-point difference across fifty-odd hosts establishes nothing.
Not one host in either zone supports legacy TLS 1.0 or 1.1 — exactly as in the top million, where they appear on zero and a hundred and six sites out of 819,000.
Our level sits above the top million (over 80% against 70.4%), which is expected: domains reach us when someone is already working on them, while the Tranco list includes long-abandoned sites. Compare the direction here, not the levels.
The gap lives not in the general sample but in its under-configured part. Separately we broke down 87 hosts graded B or C and looked at what keeps them from full marks on protocol:
| .ru (42 hosts) | .com (45 hosts) | |
|---|---|---|
| Support only TLS 1.2, without 1.3 | 60% | 38% |
Among hosts whose configuration is imperfect anyway, six in ten Russian ones cannot speak TLS 1.3, against fewer than four in ten for .com. That is the real difference: not old protocol left enabled, but the new one never enabled.
Caveat: 42 and 45 hosts is few, but a 22-point spread is large and matches the direction of the independent survey, where "1.2 only" also remains a visible share.
SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freenginx 1.13+ with OpenSSL 1.1.1+ — TLS 1.3 default. You only need ssl_protocols TLSv1.2 TLSv1.3; (drop 1.0/1.1).
Replay attacks possible on idempotent requests. Enable only if you accept POST replay (GET is fine). Cloudflare enables it by default for GET.
Industry moves slowly. PCI DSS 4.0 requires 1.3 minimum since 2025. Browser deprecation not before 2027.
Enterno SSL Checker shows supported protocols. openssl s_client -tls1_3 — manual test.
Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.