Skip to main content
New Monthly plans from $39/mo. No contracts, cancel anytime. See pricing →

SSL Certificate Statistics 2026: HTTPS Adoption, Let's Encrypt and CA Market Share

Let's Encrypt issues the certificate on 63.9% of websites whose certificate comes from a publicly trusted authority: 70,152,849 of 109,784,103. On many of the largest hosts and platforms, the host picks the authority. Squarespace, Vercel and Hostinger put Let's Encrypt, and GoDaddy's site builder puts GoDaddy's own certificate, on between 94.2% and 98.2% of their websites with a trusted certificate.

Published 29 September 2026 · Updated 1 October 2026 · 34 min read
Melanie Cohen
Melanie writes about web infrastructure measurement at StackScan, working from the crawl that reads the technology of every website on the internet.
On this page 13 sections
  1. 94.8% of websites present a trusted certificate, and 2.8% still answer only over HTTP
  2. Let's Encrypt issues 63.9% of trusted certificates
  3. Google Trust Services is mostly Cloudflare's choice
  4. Your web host chooses your SSL certificate
  5. At least 81.8% of trusted certificates are free, and the top of the web pays
  6. At least 97.4% of trusted certificates only prove control of the domain
  7. Country extensions follow their hosts: Actalis on .it, Sectigo on .de
  8. 379,202 websites serve a certificate that expired before the crawl
  9. 2,298,420 websites present a certificate no browser accepts
  10. 98.9% of Let's Encrypt websites crawled since 25 August 2026 carry its Generation Y chain
  11. 38.4% of websites with a trusted certificate send HSTS, most because their platform does
  12. Frequently asked questions
  13. Methodology and sources
Key findings
  1. Let's Encrypt issues the certificate on 63.9% of websites with a publicly trusted certificate, 70,152,849 of 109,784,103, and on 60.6% of all websites. With Google Trust Services on 17.7% and GoDaddy on 6.5%, the three largest authorities issue 88.2% of trusted certificates.
  2. 94.8% of websites present a certificate from a publicly trusted authority, 109,784,103 of 115,839,436. 2,298,420 websites, 2.0% of the web, present one no browser accepts, and 3,288,919, 2.8%, answer only over plain HTTP.
  3. Google Trust Services is the second largest certificate authority, issuing 17.7% of trusted certificates, 19,472,641 websites. 82.9% of those websites, 16,149,947, sit behind Cloudflare, which chooses the authority for the free certificates it issues.
  4. On 13 of the 30 largest hosts and platforms, one certificate authority issues 90% or more of the certificates on their websites with a trusted certificate. Those hosts hold 30,644,804 websites, 26.5% of the web.
  5. 81.8% of websites with a trusted certificate, 89,823,769, get it from an authority that charges nothing: Let's Encrypt, Google Trust Services, TrustAsia's LiteSSL or Fastly's Certainly.
  6. Busier websites pay for their certificate more often. Between Tranco ranks 1,001 and 10,000, 50.7% of the 4,919 websites with a trusted certificate use a free authority, and DigiCert issues 723 of them, 14.7%, against 1.7% of trusted certificates across the web.
  7. At least 97.4% of trusted certificates, 106,885,721, prove only that the owner controls the domain. An intermediate named for extended validation issued the certificate on 22,367 websites, 0.02% of those with a trusted certificate.
  8. 379,202 websites, 0.35% of those with a publicly trusted certificate, serve a certificate that had expired before the crawl began, because the intermediate behind it had expired or stopped issuing months earlier. 362,151 of them are Let's Encrypt certificates.
  9. 38.4% of websites with a trusted certificate send an HSTS header, 42,174,070 of them. Seven website platforms send 54.5% of those headers, and on every other website with a trusted certificate the rate is 22.1%.
  10. Only 0.65% of the 9,469,985 websites whose HSTS header meets the preload list's rules, 61,386, are on Chrome's preload list by name.
94.8%of websites present a certificate from a publicly trusted authority
63.9%of trusted certificates come from Let's Encrypt, the largest authority by far
81.8%of trusted certificates come from an authority that charges nothing
379,202websites still serve a certificate that had expired before the crawl began

94.8% of websites present a trusted certificate, and 2.8% still answer only over HTTP

What a website presents when a browser asks for HTTPS
Websites by what the certificate on the latest fetch showed, with their share of all websites in brackets
What a website presents when a browser asks for HTTPSTrusted and currentTrusted and current: 109,404,901 (94.4%)109,404,901 (94.4%)Plain HTTP onlyPlain HTTP only: 3,288,919 (2.8%)3,288,919 (2.8%)Rejected by browsersRejected by browsers: 2,298,420 (2.0%)2,298,420 (2.0%)Could not be readCould not be read: 467,994 (0.40%)467,994 (0.40%)Trusted issuer, already expiredTrusted issuer, already expired: 379,202 (0.33%)379,202 (0.33%)
What a website presents when a browser asks for HTTPSTrusted and current109,404,901 (94.4%)Plain HTTP only3,288,919 (2.8%)Rejected by browsers2,298,420 (2.0%)Could not be read467,994 (0.40%)Trusted issuer, already expired379,202 (0.33%)
What a website presents when a browser asks for HTTPSTrusted and current109,404,901 (94.4%)Plain HTTP only3,288,919 (2.8%)Rejected by browsers2,298,420 (2.0%)Could not be read467,994 (0.40%)Trusted issuer, already expired379,202 (0.33%)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-https"><img src="https://content.stackscan.com/charts/ssl-statistics-https.webp" alt="What a website presents when a browser asks for HTTPS" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-https">StackScan SSL analysis</a></p>

We record the certificate, or its absence, each time our crawl fetches a website, and this chart sorts the web by what the latest fetch showed. It adds two groups the headline figures leave out: 379,202 websites whose issuer is trusted but whose certificate had already expired, and 467,994, 0.40% of the web, whose answer the crawl could not read. Take the expired out and 94.4% of the web is left with a certificate that is trusted and, as far as the issuer can show, current.

The web, in this report, is 115,839,436 websites. The latest fetch of 183.7 million domains answered 200, 125.9 million of them with a page the crawl could read; 119.9 million of those sit at the apex of a registration, which leaves out subdomains, and 115.8 million remain once parked domains are removed. The 158.2 million domains in our robots.txt report also count parked, broken and silent domains, so a share of them would be lower.

Chrome 154, stable since 22 September 2026, asks before the first visit to any public website without HTTPS. That reaches at least the 3,288,919 websites that answer only over plain HTTP, and a website whose certificate is rejected or expired falls back to plain HTTP and meets the same warning. Google counts visits rather than websites: 95 to 99% of navigations in Chrome have used HTTPS since about 2020, and most of the rest go to private addresses on local networks.

HTTPS is the default on the web, and a website without a working certificate now meets its visitors with a warning page.

Let's Encrypt issues 63.9% of trusted certificates

Certificate authorities by websites
Share of the websites whose certificate comes from a publicly trusted authority, each authority counted under the brand on the certificate
Certificate authorities by websitesLet's EncryptLet's Encrypt: 63.9% (70,152,849)63.9% (70,152,849)Google Trust ServicesGoogle Trust Services: 17.7% (19,472,641)17.7% (19,472,641)GoDaddyGoDaddy: 6.5% (7,173,334)6.5% (7,173,334)SectigoSectigo: 5.5% (6,014,739)5.5% (6,014,739)DigiCertDigiCert: 1.7% (1,890,899)1.7% (1,890,899)AmazonAmazon: 1.1% (1,161,608)1.1% (1,161,608)GlobalSignGlobalSign: 0.72% (787,190)0.72% (787,190)ZeroSSLZeroSSL: 0.70% (773,918)0.70% (773,918)ActalisActalis: 0.63% (692,839)0.63% (692,839)TrustAsiaTrustAsia: 0.28% (304,307)0.28% (304,307)CertumCertum: 0.15% (163,588)0.15% (163,588)SSL.comSSL.com: 0.13% (139,330)0.13% (139,330)Every other trusted CA (119)Every other trusted CA (119): 0.96% (1,056,861)0.96% (1,056,861)
Certificate authorities by websitesLet's Encrypt63.9% (70,152,849)Google Trust Services17.7% (19,472,641)GoDaddy6.5% (7,173,334)Sectigo5.5% (6,014,739)DigiCert1.7% (1,890,899)Amazon1.1% (1,161,608)GlobalSign0.72% (787,190)ZeroSSL0.70% (773,918)Actalis0.63% (692,839)TrustAsia0.28% (304,307)Certum0.15% (163,588)SSL.com0.13% (139,330)Every other trusted CA (119)0.96% (1,056,861)
Certificate authorities by websitesLet's Encrypt63.9% (70,152,849)Google Trust Services17.7% (19,472,641)GoDaddy6.5% (7,173,334)Sectigo5.5% (6,014,739)DigiCert1.7% (1,890,899)Amazon1.1% (1,161,608)GlobalSign0.72% (787,190)ZeroSSL0.70% (773,918)Actalis0.63% (692,839)TrustAsia0.28% (304,307)Certum0.15% (163,588)SSL.com0.13% (139,330)Every other trusted CA (119)0.96% (1,056,861)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-ca"><img src="https://content.stackscan.com/charts/ssl-statistics-ca.webp" alt="Certificate authorities by websites" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-ca">StackScan SSL analysis</a></p>

Let's Encrypt issues the certificate on 70,152,849 websites, 63.9% of those with a publicly trusted certificate and 60.6% of the whole web. Google Trust Services is second at 17.7% of trusted certificates, GoDaddy third at 6.5% and Sectigo fourth at 5.5%. The first three issue 88.2% between them, out of 131 issuing organisation names found on the web.

The chart counts each certificate under the brand printed on it. Several other brands issue from intermediates Sectigo certifies, ZeroSSL the largest: its intermediate is issued by one of Sectigo's roots. Counted by the company behind the intermediate, Sectigo closes to 6.3% of trusted certificates, against GoDaddy's 6.5%.

Published figures count differently. Let's Encrypt's own, more than 700 million websites, counts every hostname it certifies, and the HTTP Archive's Web Almanac puts it on 52.6% of the mobile pages it crawls, a share of pages from its own list. This report counts one website per registration.

One authority now holds nearly two thirds of the trusted web, and a root program change or an outage at Let's Encrypt would reach more websites than every other authority together.

Google Trust Services is mostly Cloudflare's choice

Who issues the certificates on Cloudflare's network
Share of the websites on Cloudflare's network that present a trusted certificate
Who issues the certificates on Cloudflare's networkGoogle Trust ServicesGoogle Trust Services: 78.6% (13,458,671)78.6% (13,458,671)Let's EncryptLet's Encrypt: 20.7% (3,540,432)20.7% (3,540,432)GoDaddyGoDaddy: 0.17% (29,665)0.17% (29,665)ZeroSSLZeroSSL: 0.11% (19,491)0.11% (19,491)SSL.comSSL.com: 0.10% (17,178)0.10% (17,178)SectigoSectigo: 0.10% (16,924)0.10% (16,924)Every other CAEvery other CA: 0.24% (40,240)0.24% (40,240)
Who issues the certificates on Cloudflare's networkGoogle Trust Services78.6% (13,458,671)Let's Encrypt20.7% (3,540,432)GoDaddy0.17% (29,665)ZeroSSL0.11% (19,491)SSL.com0.10% (17,178)Sectigo0.10% (16,924)Every other CA0.24% (40,240)
Who issues the certificates on Cloudflare's networkGoogle Trust Services78.6% (13,458,671)Let's Encrypt20.7% (3,540,432)GoDaddy0.17% (29,665)ZeroSSL0.11% (19,491)SSL.com0.10% (17,178)Sectigo0.10% (16,924)Every other CA0.24% (40,240)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-cloudflare"><img src="https://content.stackscan.com/charts/ssl-statistics-cloudflare.webp" alt="Who issues the certificates on Cloudflare's network" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-cloudflare">StackScan SSL analysis</a></p>

82.9% of the 19,472,641 websites with a Google Trust Services certificate sit behind Cloudflare, on its network or answering with its server header, and 69.1% on its network alone. Of the 17,379,961 websites on Cloudflare's network, 78.6% of those with a trusted certificate carry one from Google Trust Services and 20.7% one from Let's Encrypt.

Cloudflare gives every site on it a free certificate by default, and for those certificates it chooses the certificate authority itself, between Let's Encrypt, Google Trust Services and SSL.com. WE1, Google's largest intermediate with 15,146,023 websites, answers with a Cloudflare server header on 99.1% of them.

Away from Cloudflare, Google Trust Services is on 3,322,986 websites, and three hosts hold most of them: WordPress.com 28.9%, Wix 25.3% and Google 13.5%.

The second largest certificate authority on the web is, in practice, a setting inside Cloudflare, and its share moves whenever Cloudflare changes the mix.

Your web host chooses your SSL certificate

The certificate authority each host puts on its websites
The thirty hosts and platforms with the most websites, found by their address blocks; GoDaddy network is GoDaddy's address space outside its builder and hosting platform. The trusted share is of each host's websites, the authority shares of its websites with a trusted certificate, and Google Trust is Google Trust Services
Host or platformWebsitesTrusted shareWith a trusted certificateMost used CASecond
Cloudflare17,379,96198.5%17,122,601Google Trust78.6%Let's Encrypt20.7%
Squarespace6,403,92299.9%6,396,981Let's Encrypt94.2%Google Trust3.5%
AWS6,053,27398.4%5,957,893Let's Encrypt73.9%Amazon15.7%
Hostinger6,046,83699.7%6,028,970Let's Encrypt94.7%Google Trust5.0%
GoDaddy Website Builder5,559,01199.9%5,552,443GoDaddy98.2%Let's Encrypt0.99%
Wix4,428,51599.8%4,420,150Let's Encrypt69.7%Google Trust30.2%
Namecheap2,926,36894.1%2,752,297Let's Encrypt65.7%Sectigo28.3%
OVH2,376,88692.1%2,189,723Let's Encrypt93.7%Sectigo2.0%
Vercel2,340,79499.9%2,337,438Let's Encrypt98.0%Google Trust1.8%
IONOS2,191,50592.5%2,026,999Sectigo74.0%Let's Encrypt23.2%
Shopify2,185,56199.7%2,178,587Let's Encrypt94.1%Google Trust5.7%
Hetzner2,178,42394.7%2,063,204Let's Encrypt81.7%DigiCert13.1%
Google1,944,01997.8%1,902,182Let's Encrypt70.7%Google Trust25.0%
Oracle1,592,03497.9%1,559,343Let's Encrypt87.8%Sectigo5.2%
GoDaddy network1,237,94680.1%992,073Let's Encrypt54.8%GoDaddy34.3%
GoDaddy hosting1,127,61299.0%1,116,048GoDaddy73.6%Let's Encrypt11.6%
DigitalOcean1,022,88596.9%991,059Let's Encrypt92.8%Google Trust3.0%
WordPress.com1,012,09498.9%1,001,024Google Trust96.4%Let's Encrypt3.4%
Xserver924,00599.5%918,991Let's Encrypt90.7%CloudSecure8.7%
All-Inkl906,94799.3%900,417Let's Encrypt59.5%Sectigo40.0%
Fastly901,84299.6%898,404Let's Encrypt78.9%Google Trust19.5%
Aruba821,26897.7%802,369Actalis79.7%Let's Encrypt19.0%
Strato774,90598.0%759,355Sectigo91.5%Let's Encrypt7.3%
Alibaba750,29682.4%617,943Let's Encrypt50.9%DigiCert25.3%
GMO731,38899.2%725,188Let's Encrypt79.2%GlobalSign19.6%
Newfold Digital702,99085.1%598,301Let's Encrypt78.9%Sectigo16.1%
one.com687,03299.5%683,872Let's Encrypt94.2%Sectigo5.0%
DreamHost663,57862.6%415,206Let's Encrypt98.3%Google Trust0.84%
hosting.com647,29599.1%641,183Let's Encrypt97.1%Google Trust1.5%
Host Europe580,17269.2%401,450Let's Encrypt52.0%GoDaddy43.6%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-hosts"><img src="https://content.stackscan.com/charts/ssl-statistics-hosts.webp" alt="The certificate authority each host puts on its websites" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-hosts">StackScan SSL analysis</a></p>
A colored pencil drawing of a footbridge railing over a city river, its wire mesh covered in thousands of padlocks, most of them the same plain brass kind, patches of painted locks among them and a few rusted orange
Most of the locks on the railing are one plain kind, bought wherever the owner happened to be, and a few have rusted in place long after anyone last looked at them. Illustration: StackScan.

On 13 of the 30 largest hosts and platforms, one certificate authority issues 90% or more of the certificates on their websites with a trusted certificate. Hostinger puts Let's Encrypt on 94.7% of its websites with a trusted certificate, Vercel on 98.0%, Squarespace on 94.2% and OVH on 93.7%, and WordPress.com puts Google Trust Services on 96.4%.

Some hosts use a commercial authority instead. IONOS puts Sectigo on 74.0% of its websites with a trusted certificate and Strato on 91.5%. Aruba puts Actalis on 79.7%, and Actalis has been part of the Aruba Group since 2009. Namecheap splits between Let's Encrypt on 65.7% and Sectigo on 28.3%, and Wix between Let's Encrypt on 69.7% and Google Trust Services on 30.2%.

The GoDaddy Website Builder, counted by its address blocks in this table, puts GoDaddy's own certificate on 98.2% of its websites with a trusted certificate; counted by its fingerprint in the platform table below, the share is 91.9%. That builder is where GoDaddy's rank comes from: 76.0% of every website with a GoDaddy certificate, 5,450,226, sits on it, and another 11.5% on GoDaddy's hosting.

Four names in these tables have a low trusted share. DreamHost's is 62.6% because its servers' own default certificate sits on 240,373 websites. Host Europe's 69.2% comes mostly from its ispgateway default certificate and from certificates that name no organisation, and certificates that name no organisation also pull GoDaddy's network outside its builder and hosting down to 80.1%. Jimdo's 80.3% comes mostly from answers the crawl could not read.

The certificate authority behind each website platform
Platforms with at least a hundred thousand websites, found by their fingerprints, and a website on two platforms counts under both. The trusted share is of each platform's websites, the authority shares of its websites with a trusted certificate. Google Trust is Google Trust Services
CMS or site builderWebsitesTrusted shareWith a trusted certificateMost used CASecond
WordPress26,787,12198.3%26,337,153Let's Encrypt70.0%Google Trust17.0%
Squarespace6,375,61499.8%6,365,541Let's Encrypt95.8%DigiCert2.2%
GoDaddy Website Builder6,172,10399.4%6,135,094GoDaddy91.9%Let's Encrypt4.0%
Wix4,704,89699.7%4,690,198Let's Encrypt69.1%Google Trust30.0%
WooCommerce3,719,82998.9%3,680,213Let's Encrypt74.6%Google Trust14.5%
Shopify2,311,85399.4%2,298,499Let's Encrypt91.7%Google Trust6.6%
Hostinger Website Builder658,05299.9%657,124Let's Encrypt94.3%Google Trust5.4%
Joomla601,17896.5%580,052Let's Encrypt75.6%Sectigo10.4%
Zyro Website Builder525,32499.9%524,721Let's Encrypt94.1%Google Trust5.6%
Duda488,83599.0%484,125Let's Encrypt96.9%Google Trust1.8%
Webflow474,95798.9%469,933Google Trust69.5%Let's Encrypt23.4%
Tilda434,57297.3%422,710Let's Encrypt97.8%Google Trust1.5%
Weebly411,77099.4%409,294Google Trust61.8%Let's Encrypt34.6%
MyWebsite Creator336,33899.7%335,292Sectigo98.9%Let's Encrypt0.65%
Jimdo310,04080.3%248,875Google Trust97.8%Let's Encrypt1.3%
Drupal282,11796.3%271,578Let's Encrypt71.5%Google Trust10.8%
Blogger210,36499.1%208,500Google Trust84.4%Let's Encrypt11.2%
Framer177,35199.7%176,816Let's Encrypt90.9%Google Trust4.9%
TYPO3176,63996.4%170,217Let's Encrypt73.0%DigiCert10.1%
Magento163,63198.2%160,651Let's Encrypt72.1%Google Trust19.6%
Mobirise154,11797.8%150,763Let's Encrypt69.2%Google Trust17.0%
One.com Web Editor146,11499.6%145,579Let's Encrypt99.5%Google Trust0.27%
PrestaShop142,50898.2%139,920Let's Encrypt77.7%Google Trust8.7%
1C-Bitrix118,45298.0%116,094Let's Encrypt85.0%GlobalSign13.0%
Strato Website111,17398.6%109,638Sectigo80.6%Let's Encrypt18.2%
Webnode103,44099.2%102,604Let's Encrypt98.9%Google Trust0.53%
No CMS or builder detected63,435,83691.6%58,102,661Let's Encrypt62.2%Google Trust20.6%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-builders"><img src="https://content.stackscan.com/charts/ssl-statistics-builders.webp" alt="The certificate authority behind each website platform" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-builders">StackScan SSL analysis</a></p>

Content management systems that run on any host follow the host. WordPress websites with a trusted certificate carry Let's Encrypt on 70.0%, Google Trust Services on 17.0% and Sectigo on 6.9%, close to the mix across the whole web. Hosted builders look like their host: Jimdo puts Google Trust Services on 97.8% of its websites with a trusted certificate, and MyWebsite Creator, the IONOS builder, puts Sectigo on 98.9%.

A certificate authority's market share is mostly a hosting market share. A host that changes its default moves millions of websites to another authority in one renewal cycle, and none of their owners has to do anything.

At least 81.8% of trusted certificates are free, and the top of the web pays

Free and paid certificate authorities
Share of the websites with a trusted certificate, by what the issuing authority charges. Free by design is Let's Encrypt, Google Trust Services, TrustAsia LiteSSL and Fastly's Certainly; free from the host is cPanel AutoSSL and Cloudflare's certificates on SSL.com; ZeroSSL and Actalis DV run a free tier beside paid plans
Free and paid certificate authoritiesFree by designFree by design: 81.8% (89,823,769)81.8% (89,823,769)Amazon, free inside AWSAmazon, free inside AWS: 1.1% (1,161,608)1.1% (1,161,608)Free from the hostFree from the host: 0.04% (40,287)0.04% (40,287)Free tier or paid, cannot tellFree tier or paid, cannot tell: 1.3% (1,430,248)1.3% (1,430,248)Sold or bundled by a hostSold or bundled by a host: 15.8% (17,328,191)15.8% (17,328,191)
Free and paid certificate authoritiesFree by design81.8% (89,823,769)Amazon, free inside AWS1.1% (1,161,608)Free from the host0.04% (40,287)Free tier or paid, cannot tell1.3% (1,430,248)Sold or bundled by a host15.8% (17,328,191)
Free and paid certificate authoritiesFree by design81.8% (89,823,769)Amazon, free inside AWS1.1% (1,161,608)Free from the host0.04% (40,287)Free tier or paid, cannot tell1.3% (1,430,248)Sold or bundled by a host15.8% (17,328,191)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-free"><img src="https://content.stackscan.com/charts/ssl-statistics-free.webp" alt="Free and paid certificate authorities" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-free">StackScan SSL analysis</a></p>

81.8% of websites with a trusted certificate, 89,823,769, get it from an authority that charges nothing for it: Let's Encrypt, Google Trust Services, TrustAsia's LiteSSL or Fastly's Certainly, which Fastly issues to its customers at no extra cost. Counting Amazon, whose certificates cost nothing inside AWS services, the free share is 82.9%. Amazon is not wholly free: since June 2025 it also sells certificates that can be exported and used anywhere.

That share is a floor. 1.3% of trusted certificates come from authorities that run a free tier beside paid plans, ZeroSSL's free plan and Actalis's free domain certificates among them, and the certificate does not say which one a site used. The remaining 15.8% are sold outright or bundled into a hosting plan.

The busier the website, the less likely a free certificate
Share of each Tranco rank band's websites with a trusted certificate that use a free authority, with the band's trusted websites in brackets
The busier the website, the less likely a free certificateTop 1,000Top 1,000: 35.3% (456)35.3% (456)1,001 to 10,0001,001 to 10,000: 50.7% (4,919)50.7% (4,919)10,001 to 100,00010,001 to 100,000: 59.7% (52,007)59.7% (52,007)100,001 to 1 million100,001 to 1 million: 77.0% (567,932)77.0% (567,932)1,000,001 to 4,360,3051,000,001 to 4,360,305: 85.8% (1,789,259)85.8% (1,789,259)Not in the listNot in the list: 81.8% (107,369,530)81.8% (107,369,530)
The busier the website, the less likely a free certificateTop 1,00035.3% (456)1,001 to 10,00050.7% (4,919)10,001 to 100,00059.7% (52,007)100,001 to 1 million77.0% (567,932)1,000,001 to 4,360,30585.8% (1,789,259)Not in the list81.8% (107,369,530)
The busier the website, the less likely a free certificateTop 1,00035.3% (456)1,001 to 10,00050.7% (4,919)10,001 to 100,00059.7% (52,007)100,001 to 1 million77.0% (567,932)1,000,001 to 4,360,30585.8% (1,789,259)Not in the list81.8% (107,369,530)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-free-bands"><img src="https://content.stackscan.com/charts/ssl-statistics-free-bands.webp" alt="The busier the website, the less likely a free certificate" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-free-bands">StackScan SSL analysis</a></p>

Busier websites pay more often. Between Tranco ranks 1,001 and 10,000, 50.7% of the 4,919 websites with a trusted certificate use a free authority, against 85.8% between rank one million and the end of the list, and DigiCert issues 14.7% of them against 1.7% across the web. The top 1,000 goes further, 35.3% free and DigiCert on 114 of its 456 websites with a trusted certificate, but on a base that small the direction is clear and the size is not, and it counts only the top sites that let a crawler in.

Websites outside the list use free certificates less often than the ranked tail, 81.8% against 85.8%, and rank does not explain it. Bundled certificates do: GoDaddy issues 6.7% of the unranked websites' trusted certificates against 1.3% of the ranked tail's, and Sectigo 5.5% against 3.6%.

Free certificates won wherever a host makes the choice. The paid market that remains is the busiest websites and the hosts that put a commercial authority on every site they sell.

At least 97.4% of trusted certificates only prove control of the domain

Domain, organisation and extended validation
Share of the websites with a trusted certificate, by what the issuing intermediate declares it validates. Not stated means the intermediate issues more than one kind
Domain, organisation and extended validationDomain validatedDomain validated: 97.4% (106,885,721)97.4% (106,885,721)Organisation validatedOrganisation validated: 0.46% (507,518)0.46% (507,518)Extended validationExtended validation: 0.02% (22,367)0.02% (22,367)Not statedNot stated: 2.2% (2,368,497)2.2% (2,368,497)
Domain, organisation and extended validationDomain validated97.4% (106,885,721)Organisation validated0.46% (507,518)Extended validation0.02% (22,367)Not stated2.2% (2,368,497)
Domain, organisation and extended validationDomain validated97.4% (106,885,721)Organisation validated0.46% (507,518)Extended validation0.02% (22,367)Not stated2.2% (2,368,497)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-validation"><img src="https://content.stackscan.com/charts/ssl-statistics-validation.webp" alt="Domain, organisation and extended validation" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-validation">StackScan SSL analysis</a></p>

At least 97.4% of websites with a trusted certificate, 106,885,721, carry a domain validated certificate. Under the Baseline Requirements such a certificate names no organisation: it proves that whoever asked for it controls the domain, and nothing about who they are.

An intermediate named for organisation validation issued the certificate on 507,518 websites, 0.46% of those with a trusted certificate, and one named for extended validation on 22,367, 0.02%. Both are floors, because 2.2% come from intermediates that issue more than one kind, so organisation and extended validation together cover between 0.48% and 2.6% of trusted certificates.

Certificates by Tranco rank
Websites in each rank band and those with a trusted certificate. Every share is of the band's websites with a trusted certificate
Tranco rankWebsitesWith a trusted certificateFree CALet's EncryptDigiCertEV namedOV named
Top 1,00046745635.3%18.9%25.0%2.4%9.0%
1,001 to 10,0005,0364,91950.7%22.9%14.7%2.1%7.1%
10,001 to 100,00053,37852,00759.7%30.8%10.8%1.5%4.7%
100,001 to 1 million582,728567,93277.0%48.0%5.1%0.54%1.9%
1,000,001 to 4,360,3051,855,5901,789,25985.8%58.9%2.4%0.16%0.74%
Not in the list113,342,237107,369,53081.8%64.1%1.7%0.01%0.45%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-bands"><img src="https://content.stackscan.com/charts/ssl-statistics-bands.webp" alt="Certificates by Tranco rank" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-bands">StackScan SSL analysis</a></p>

The busiest websites still buy identity. Between Tranco ranks 1,001 and 10,000, extended validation is named on at least 2.1% and organisation validation on at least 7.1% of the 4,919 websites with a trusted certificate. In the top 1,000 the counts are 11 and 41 of 456, where the direction is clear and the size is not. Browsers stopped rewarding it years ago: Chrome 77 moved the extended validation badge out of the address bar into the page information panel.

The padlock on nearly every website says the connection reaches the domain in the address bar. Who runs that domain is a question the certificate no longer answers for almost anyone.

Country extensions follow their hosts: Actalis on .it, Sectigo on .de

HTTPS by kind of domain extension
Every extension in the base, grouped into three kinds. The trusted and plain HTTP shares are of each kind's websites; the authority shares are of its websites with a trusted certificate, and Google Trust is Google Trust Services
Kind of extensionWebsitesTrusted sharePlain HTTP shareWith a trusted certificateMost used CASecond
Legacy generic, such as .com70,927,04995.4%2.6%67,667,031Let's Encrypt62.5%Google Trust19.0%
New generic, such as .xyz12,338,88794.5%3.2%11,657,304Let's Encrypt60.0%Google Trust27.7%
Country code32,569,12793.5%3.2%30,456,641Let's Encrypt68.5%Google Trust11.2%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-tld-classes"><img src="https://content.stackscan.com/charts/ssl-statistics-tld-classes.webp" alt="HTTPS by kind of domain extension" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-tld-classes">StackScan SSL analysis</a></p>

Every share in this section is of the websites on the domain extension named, and every authority share of those with a trusted certificate. Legacy generic extensions such as .com hold 61.2% of the web's websites, and 95.4% of them present a trusted certificate. Country code extensions hold 28.1% at 93.5%, and the new generic extensions released since 2013 hold 10.7% at 94.5%.

New generic extensions lean on Google Trust Services, at 27.7% of their trusted certificates, and Cloudflare is the largest host on 9 of the ten largest. Country codes carry the most Sectigo, 9.3%, and 51.7% of that Sectigo is on .de.

HTTPS and certificate authorities on the forty largest extensions
Extensions with at least a hundred thousand websites, a second level such as co.uk as its own row. The trusted and plain HTTP shares are of each extension's websites; the authority shares are of its websites with a trusted certificate, and Google Trust is Google Trust Services
ExtensionWebsitesTrusted sharePlain HTTP shareWith a trusted certificateMost used CASecond
.com60,767,12595.6%2.5%58,064,743Let's Encrypt62.8%Google Trust18.7%
.de4,975,67093.0%2.0%4,627,533Let's Encrypt52.3%Sectigo31.7%
.org4,483,03095.7%2.2%4,291,977Let's Encrypt61.3%Google Trust21.4%
.net3,763,31394.0%3.3%3,538,387Let's Encrypt60.8%Google Trust18.6%
.ru2,156,75988.0%5.8%1,898,208Let's Encrypt84.2%GlobalSign9.0%
.co.uk1,900,50593.3%4.3%1,773,707Let's Encrypt65.3%Google Trust18.0%
.nl1,552,03994.5%1.4%1,467,425Let's Encrypt74.8%Sectigo13.5%
.fr1,255,27796.1%2.4%1,205,806Let's Encrypt77.9%Google Trust11.9%
.com.br1,152,31698.2%0.74%1,131,851Let's Encrypt73.7%Google Trust18.6%
.ch1,150,85196.7%1.1%1,112,734Let's Encrypt67.8%Sectigo20.7%
.it1,106,77597.1%1.1%1,075,134Let's Encrypt58.0%Actalis28.6%
.online1,099,47289.4%5.5%983,386Let's Encrypt61.1%Google Trust19.5%
.shop1,017,92395.7%1.9%974,396Let's Encrypt65.6%Google Trust22.3%
.info935,68291.6%5.6%857,304Let's Encrypt56.0%Google Trust21.4%
.top927,06093.7%2.8%868,340Let's Encrypt72.1%Google Trust21.5%
.xyz885,64891.8%6.0%813,106Let's Encrypt58.2%Google Trust27.8%
.com.au827,83497.4%1.4%806,000Let's Encrypt68.5%Google Trust16.5%
.pl760,94896.5%0.93%734,512Let's Encrypt63.9%Google Trust9.6%
.ca752,28197.1%0.91%730,696Let's Encrypt63.9%Google Trust18.8%
.se731,76396.3%1.7%704,652Let's Encrypt87.1%Google Trust8.1%
.eu715,56291.1%3.8%651,786Let's Encrypt64.5%Sectigo11.8%
.app687,78598.1%1.3%674,569Let's Encrypt56.6%Google Trust33.8%
.site632,48795.5%2.4%604,143Let's Encrypt58.9%Google Trust31.2%
.cn587,59061.5%29.9%361,592Let's Encrypt52.3%Google Trust13.0%
.cz577,52692.3%2.6%532,947Let's Encrypt78.9%Google Trust5.5%
.store535,84391.7%6.1%491,521Let's Encrypt63.0%Google Trust22.0%
.in505,52197.3%0.90%491,770Let's Encrypt72.6%Google Trust13.9%
.es502,56795.3%2.4%478,764Let's Encrypt67.8%Sectigo14.9%
.jp498,87195.9%2.7%478,229Let's Encrypt69.0%GlobalSign8.6%
.be485,72795.3%1.9%462,794Let's Encrypt83.3%Google Trust9.5%
.at468,46792.8%3.2%434,926Let's Encrypt68.8%Sectigo11.0%
.co.za438,43695.8%1.1%419,971Let's Encrypt88.3%Google Trust6.8%
.us424,64695.8%1.7%406,867Let's Encrypt40.9%Amazon23.8%
.dk392,11395.9%2.4%376,156Let's Encrypt78.6%Sectigo9.5%
.pro353,16395.8%2.4%338,257Let's Encrypt54.4%Google Trust37.8%
.vip347,37791.6%5.2%318,176Let's Encrypt50.1%Google Trust33.3%
.co345,77496.6%1.7%334,017Let's Encrypt61.4%Google Trust20.9%
.biz303,35093.4%3.8%283,254Let's Encrypt52.5%Google Trust24.2%
.hu302,20093.9%1.7%283,765Let's Encrypt84.7%Google Trust5.6%
.рф300,45676.6%17.8%230,228Let's Encrypt90.6%GlobalSign8.8%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-tld"><img src="https://content.stackscan.com/charts/ssl-statistics-tld.webp" alt="HTTPS and certificate authorities on the forty largest extensions" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-tld">StackScan SSL analysis</a></p>

On .it, Actalis issues 28.6% of trusted certificates, and Aruba, which owns Actalis, hosts 37.4% of .it websites. On .de, Sectigo issues 31.7%, the certificate IONOS and Strato put on their customers' sites. On .us, Amazon issues 23.8% and AWS hosts 27.7% of the websites. On .jp, counting second levels such as co.jp, GlobalSign issues 9.8% of trusted certificates and JPRS, Japan's registry, 7.3%.

Poland's own authority, Certum, is the clearest case of a national authority. The Certum family, Certum itself and the sub-authorities Polish hosts such as home.pl and nazwa.pl run under it, issues 22.6% of the trusted certificates on .pl, counting its second levels such as com.pl. HARICA, the Greek academic authority, issues 15,144 websites' certificates, but only 80 on .gr. Its largest extension is .de, at 18.6% of its websites: Germany's research network, DFN, gets its certificates through GÉANT's certificate service, supplied by HARICA since 2025.

Two extensions stand apart. 29.9% of .cn websites answer only over plain HTTP and 61.5% present a trusted certificate; on .рф the figures are 17.8% and 76.6%. On both, a few hosts hold most of the plain HTTP: the five largest hold 63.1% of the plain HTTP websites on .cn, RAKsmart alone 42.3%, and 92.5% on .рф, REG.RU alone 56.8%. A national habit is possible, but the concentration points at those hosts first.

A national certificate authority wins where a national host bundles it, and nowhere else. The extension a website is registered on predicts its certificate only as far as it predicts its host.

379,202 websites serve a certificate that expired before the crawl

Certificates that had expired before the crawl, by intermediate
Websites serving a certificate from an intermediate that had expired or stopped issuing, with their share of the websites with a trusted certificate in brackets
Certificates that had expired before the crawl, by intermediateLet's Encrypt R3Let's Encrypt R3: 135,025 (0.12%)135,025 (0.12%)Let's Encrypt R11Let's Encrypt R11: 83,035 (0.08%)83,035 (0.08%)Let's Encrypt R10Let's Encrypt R10: 73,993 (0.07%)73,993 (0.07%)Let's Encrypt X3Let's Encrypt X3: 40,249 (0.04%)40,249 (0.04%)Let's Encrypt E5Let's Encrypt E5: 18,797 (0.02%)18,797 (0.02%)Let's Encrypt E6Let's Encrypt E6: 10,974 (0.01%)10,974 (0.01%)AlphaSSL SHA256 G2AlphaSSL SHA256 G2: 5,674 (0.01%)5,674 (0.01%)GlobalSign DV SHA256 G2GlobalSign DV SHA256 G2: 5,477 (under 0.01%)5,477 (under 0.01%)GlobalSign OV SHA256 G2GlobalSign OV SHA256 G2: 4,119 (under 0.01%)4,119 (under 0.01%)Other expired intermediatesOther expired intermediates: 1,781 (under 0.01%)1,781 (under 0.01%)Older Let's EncryptOlder Let's Encrypt: 78 (under 0.01%)78 (under 0.01%)
Certificates that had expired before the crawl, by intermediateLet's Encrypt R3135,025 (0.12%)Let's Encrypt R1183,035 (0.08%)Let's Encrypt R1073,993 (0.07%)Let's Encrypt X340,249 (0.04%)Let's Encrypt E518,797 (0.02%)Let's Encrypt E610,974 (0.01%)AlphaSSL SHA256 G25,674 (0.01%)GlobalSign DV SHA256 G25,477 (under 0.01%)GlobalSign OV SHA256 G24,119 (under 0.01%)Other expired intermediates1,781 (under 0.01%)Older Let's Encrypt78 (under 0.01%)
Certificates that had expired before the crawl, by intermediateLet's Encrypt R3135,025 (0.12%)Let's Encrypt R1183,035 (0.08%)Let's Encrypt R1073,993 (0.07%)Let's Encrypt X340,249 (0.04%)Let's Encrypt E518,797 (0.02%)Let's Encrypt E610,974 (0.01%)AlphaSSL SHA256 G25,674 (0.01%)GlobalSign DV SHA256 G25,477 (under 0.01%)GlobalSign OV SHA256 G24,119 (under 0.01%)Other expired intermediates1,781 (under 0.01%)Older Let's Encrypt78 (under 0.01%)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-expired"><img src="https://content.stackscan.com/charts/ssl-statistics-expired.webp" alt="Certificates that had expired before the crawl, by intermediate" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-expired">StackScan SSL analysis</a></p>

379,202 websites, 0.35% of those with a publicly trusted certificate, serve a certificate that had expired before the crawl began. 362,151 are Let's Encrypt certificates, 0.52% of its websites, and 17,051 come from GlobalSign, Google, Gandi and Network Solutions. Their intermediates prove it without an expiry date: R3 expired on 15 September 2025, Let's Encrypt Authority X3 in 2021, and GlobalSign's AlphaSSL, DV and OV SHA256 G2 intermediates on 20 February 2024.

The 186,799 Let's Encrypt certificates from R10, R11, E5 and E6 had expired too. Let's Encrypt moved issuance off those four on 20 August 2025 and issued 90-day certificates, so the last of them had lapsed by November 2025, six months before the crawl's first day.

This is a floor. The certificate's own expiry date is not stored, so a lapsed certificate from an intermediate still in use cannot be seen, and the true number is higher. Expired certificates gather in the long tail: 0.35% of unranked websites with a trusted certificate serve one, against 0.13% in the Tranco top million.

A certificate renews itself only as long as someone keeps the machinery that renews it running, and on these sites nobody has for months.

2,298,420 websites present a certificate no browser accepts

Certificates browsers reject
Websites whose certificate no browser accepts, by kind, with their share of all websites in brackets
Certificates browsers rejectServer default or test certificateServer default or test certificate: 1,175,312 (1.0%)1,175,312 (1.0%)No organisation namedNo organisation named: 632,428 (0.55%)632,428 (0.55%)Other untrusted issuerOther untrusted issuer: 283,499 (0.24%)283,499 (0.24%)Failed verification in MayFailed verification in May: 163,318 (0.14%)163,318 (0.14%)Cloudflare Origin CA certificateCloudflare Origin CA certificate: 33,755 (0.03%)33,755 (0.03%)Distrusted CA, Symantec eraDistrusted CA, Symantec era: 7,470 (0.01%)7,470 (0.01%)Let's Encrypt staging certificateLet's Encrypt staging certificate: 2,580 (under 0.01%)2,580 (under 0.01%)Fake Let's Encrypt or Google issuerFake Let's Encrypt or Google issuer: 58 (under 0.01%)58 (under 0.01%)
Certificates browsers rejectServer default or test certificate1,175,312 (1.0%)No organisation named632,428 (0.55%)Other untrusted issuer283,499 (0.24%)Failed verification in May163,318 (0.14%)Cloudflare Origin CA certificate33,755 (0.03%)Distrusted CA, Symantec era7,470 (0.01%)Let's Encrypt staging certificate2,580 (under 0.01%)Fake Let's Encrypt or Google issuer58 (under 0.01%)
Certificates browsers rejectServer default or test certificate1,175,312 (1.0%)No organisation named632,428 (0.55%)Other untrusted issuer283,499 (0.24%)Failed verification in May163,318 (0.14%)Cloudflare Origin CA certificate33,755 (0.03%)Distrusted CA, Symantec era7,470 (0.01%)Let's Encrypt staging certificate2,580 (under 0.01%)Fake Let's Encrypt or Google issuer58 (under 0.01%)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-rejected"><img src="https://content.stackscan.com/charts/ssl-statistics-rejected.webp" alt="Certificates browsers reject" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-rejected">StackScan SSL analysis</a></p>

2,298,420 websites, 2.0% of the web, present a certificate no browser accepts. 1,175,312 carry a server default or test certificate and 632,428 one whose issuer names no organisation; the largest named defaults are DreamHost's, on 240,373 websites, and the Plesk control panel's, on 214,494. Another 283,499 come from other untrusted issuers, which may include newer legitimate names the verifying pass never met, such as a newer Certum sub-authority.

163,318 failed verification in May, a group that may include incomplete chains a browser repairs by itself. 33,755 websites serve a Cloudflare Origin CA certificate straight to visitors, which Cloudflare warns produces untrusted certificate errors once its proxy is off. 7,470 still serve a certificate from an authority browsers have distrusted, Symantec's brands among them, and 2,580 a Let's Encrypt staging certificate, which exists for testing. Apart from all of these, 467,994 websites answered without the crawl recording an issuer at all, after a timeout or a failed handshake.

A website with a rejected certificate shows a full-page warning to anyone who visits over HTTPS, and most of these are servers that were never given a real certificate.

98.9% of Let's Encrypt websites crawled since 25 August 2026 carry its Generation Y chain

Let's Encrypt's move to its Generation Y intermediates
Share of the Let's Encrypt websites crawled each week, by the generation of the intermediate on their certificate: Generation Y is YR1, YR2, YE1 and YE2, the previous generation R12, R13, E7 and E8. Each week crawled different websites, and a week with too few Let's Encrypt websites is blank in the table and missing from the chart
Let's Encrypt's move to its Generation Y intermediatesGeneration YPrevious generationRetiredOther0%25%50%75%100%Generation YGeneration YGeneration YPrevious generationPrevious generationPrevious generationRetiredRetiredRetiredOtherOtherOtherGeneration Y 98.9%15 Jun29 Jun13 Jul27 Jul10 Aug24 Aug7 Sep28 Sep
Let's Encrypt's move to its Generation Y intermediatesGeneration YPrevious generationRetiredOther0%25%50%75%100%15 Jun6 Jul27 Jul17 Aug7 Sep28 Sep
Let's Encrypt's move to its Generation Y intermediatesGeneration YPrevious generationRetiredOther0%50%100%15 Jun20 Jul24 Aug28 Sep
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-le-weekly"><img src="https://content.stackscan.com/charts/ssl-statistics-le-weekly.webp" alt="Let's Encrypt's move to its Generation Y intermediates" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-le-weekly">StackScan SSL analysis</a></p>

Let's Encrypt switched its default profile to a new set of intermediates, which it calls Generation Y, on 27 May 2026, after a delay announced on its community forum. 98.9% of the Let's Encrypt websites crawled since 25 August 2026, 37,769,318 of 38,194,363, carry a certificate from one of them.

Key type is still mostly RSA: 66.2% of Let's Encrypt websites whose intermediate was recorded use an RSA key and 33.8% an ECDSA key.

38.4% of websites with a trusted certificate send HSTS, most because their platform does

The seven platforms that send HSTS on almost every site
Websites with a trusted certificate on each platform, found by the response headers it sends, and the share that send HSTS, send a policy longer than zero, and meet the preload list's header rules
PlatformWebsites with a trusted certificateSend HSTSEffective policyMeet the preload rules
Squarespace6,264,13599.9%81.5%0.01%
GoDaddy Website Builder5,604,145100.0%100.0%100.0%
Wix4,639,579100.0%100.0%under 0.01%
Vercel2,830,223100.0%100.0%7.4%
Shopify2,358,282100.0%100.0%0.01%
Netlify1,131,71598.4%98.4%3.2%
Framer177,889100.0%100.0%0.05%
Every other website86,778,13522.1%21.7%4.2%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-hsts-platforms"><img src="https://content.stackscan.com/charts/ssl-statistics-hsts-platforms.webp" alt="The seven platforms that send HSTS on almost every site" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-hsts-platforms">StackScan SSL analysis</a></p>

38.4% of websites with a trusted certificate, 42,174,070, send a Strict-Transport-Security header, which tells a browser to use HTTPS for that site from then on (RFC 6797), and 37.0% send a policy that lasts longer than zero. The Web Almanac finds the header on 36% of mobile pages, a share of pages rather than of websites.

Seven platforms send 54.5% of the HSTS headers sent by websites with a trusted certificate, because they put one on effectively every site they host; Squarespace documents it as part of its default setting. On every other website with a trusted certificate, 22.1% send the header. The ten most common header values account for 88.1% of every website that sends one.

HSTS by Tranco rank, with and without the seven platforms
Share of each band's websites with a trusted certificate that send HSTS, first counting every website, then with the seven platforms left out
HSTS by Tranco rank, with and without the seven platformsSend HSTSSend HSTS, the seven platforms left outTop 1,000Top 1,000, Send HSTS: 71.7%71.7%Top 1,000, Send HSTS, the seven platforms left out: 70.4%70.4%1,001 to 10,0001,001 to 10,000, Send HSTS: 60.4%60.4%1,001 to 10,000, Send HSTS, the seven platforms left out: 59.1%59.1%10,001 to 100,00010,001 to 100,000, Send HSTS: 50.1%50.1%10,001 to 100,000, Send HSTS, the seven platforms left out: 47.8%47.8%100,001 to 1 million100,001 to 1 million, Send HSTS: 38.6%38.6%100,001 to 1 million, Send HSTS, the seven platforms left out: 33.5%33.5%1,000,001 to 4,360,3051,000,001 to 4,360,305, Send HSTS: 30.8%30.8%1,000,001 to 4,360,305, Send HSTS, the seven platforms left out: 25.8%25.8%Not in the listNot in the list, Send HSTS: 38.5%38.5%Not in the list, Send HSTS, the seven platforms left out: 22.0%22.0%
HSTS by Tranco rank, with and without the seven platformsSend HSTSSend HSTS, the seven platforms left outTop 1,00071.7%70.4%1,001 to 10,00060.4%59.1%10,001 to 100,00050.1%47.8%100,001 to 1 million38.6%33.5%1,000,001 to 4,360,30530.8%25.8%Not in the list38.5%22.0%
HSTS by Tranco rank, with and without the seven platformsSend HSTSSend HSTS, the seven platforms left outTop 1,00071.7%70.4%1,001 to 10,00060.4%59.1%10,001 to 100,00050.1%47.8%100,001 to 1 million38.6%33.5%1,000,001 to 4,360,30530.8%25.8%Not in the list38.5%22.0%
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-hsts-bands"><img src="https://content.stackscan.com/charts/ssl-statistics-hsts-bands.webp" alt="HSTS by Tranco rank, with and without the seven platforms" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-hsts-bands">StackScan SSL analysis</a></p>

HSTS falls down the rank list, from 71.7% of the top 1,000 websites with a trusted certificate to 30.8% between rank one million and the end of the list. Websites outside the list break the pattern at 38.5%, above the ranked tail, and the platforms explain it: leave the seven out and the unranked share falls to 22.0%, below the tail's 25.8%.

How long HSTS policies last
Share of the websites with a trusted certificate that send a valid HSTS header, by the max-age it sets
How long HSTS policies lastmax-age=0 (switch HSTS off)max-age=0 (switch HSTS off): 3.6% (1,498,077)3.6% (1,498,077)Under a dayUnder a day: 0.44% (184,970)0.44% (184,970)A day to under six monthsA day to under six months: 21.7% (9,141,382)21.7% (9,141,382)Six months to under a yearSix months to under a year: 3.0% (1,247,281)3.0% (1,247,281)A year to under twoA year to under two: 45.5% (19,171,010)45.5% (19,171,010)Two years or moreTwo years or more: 25.9% (10,902,512)25.9% (10,902,512)
How long HSTS policies lastmax-age=0 (switch HSTS off)3.6% (1,498,077)Under a day0.44% (184,970)A day to under six months21.7% (9,141,382)Six months to under a year3.0% (1,247,281)A year to under two45.5% (19,171,010)Two years or more25.9% (10,902,512)
How long HSTS policies lastmax-age=0 (switch HSTS off)3.6% (1,498,077)Under a day0.44% (184,970)A day to under six months21.7% (9,141,382)Six months to under a year3.0% (1,247,281)A year to under two45.5% (19,171,010)Two years or more25.9% (10,902,512)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-hsts-maxage"><img src="https://content.stackscan.com/charts/ssl-statistics-hsts-maxage.webp" alt="How long HSTS policies last" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-hsts-maxage">StackScan SSL analysis</a></p>

71.4% of valid policies last a year or more. 1,498,077 websites send max-age=0, which under RFC 6797 tells a browser to forget the site's HSTS policy, and 77.1% of them are on Squarespace: it sends the header on 99.9% of its websites with a trusted certificate but a policy longer than zero on only 81.5%.

From HSTS to the preload list
Share of the websites with a trusted certificate at each step toward Chrome's HSTS preload list; the last row also counts parent and whole-extension entries
From HSTS to the preload listA trusted certificateA trusted certificate: 100.0% (109,784,103)100.0% (109,784,103)Send HSTSSend HSTS: 38.4% (42,174,070)38.4% (42,174,070)Valid policy above zeroValid policy above zero: 37.0% (40,647,155)37.0% (40,647,155)At least a yearAt least a year: 27.4% (30,073,522)27.4% (30,073,522)And includeSubDomainsAnd includeSubDomains: 12.2% (13,376,134)12.2% (13,376,134)And preload: readyAnd preload: ready: 8.6% (9,469,985)8.6% (9,469,985)On the list by nameOn the list by name: 0.06% (61,386)0.06% (61,386)Covered by the listCovered by the list: 0.13% (145,506)0.13% (145,506)
From HSTS to the preload listA trusted certificate100.0% (109,784,103)Send HSTS38.4% (42,174,070)Valid policy above zero37.0% (40,647,155)At least a year27.4% (30,073,522)And includeSubDomains12.2% (13,376,134)And preload: ready8.6% (9,469,985)On the list by name0.06% (61,386)Covered by the list0.13% (145,506)
From HSTS to the preload listA trusted certificate100.0% (109,784,103)Send HSTS38.4% (42,174,070)Valid policy above zero37.0% (40,647,155)At least a year27.4% (30,073,522)And includeSubDomains12.2% (13,376,134)And preload: ready8.6% (9,469,985)On the list by name0.06% (61,386)Covered by the list0.13% (145,506)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-preload"><img src="https://content.stackscan.com/charts/ssl-statistics-preload.webp" alt="From HSTS to the preload list" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-preload">StackScan SSL analysis</a></p>

8.6% of websites with a trusted certificate, 9,469,985, send a header that meets the preload list's rules: a year or more, includeSubDomains and the preload directive. 59.2% of them are GoDaddy Website Builder sites, whose header meets those rules on 5,602,567 of the builder's 5,604,145 websites with a trusted certificate, although hstspreload.org asks projects not to switch the preload directive on by default; the Web Almanac finds HSTS on 95.97% of the builder's pages. Only 61,386 of the ready websites, 0.65%, are on Chrome's preload list by name, and 1.5% counting parent and whole-extension entries.

HSTS is a platform setting that happens to live in a header. Where a platform switches it on, nearly every site has it; where the owner has to, about one in five does, and almost nobody finishes the step that puts a site on the list browsers ship with.

Frequently asked questions

How many websites use HTTPS in 2026? 94.8% of websites present a certificate from a publicly trusted authority, 109,784,103 of 115,839,436, and 96.8% complete an HTTPS connection of any kind. Counted by visits rather than websites, Google measures 95 to 99% of Chrome navigations over HTTPS.

What percentage of websites use Let's Encrypt? Let's Encrypt issues the certificate on 63.9% of websites whose certificate comes from a trusted authority, 70,152,849 websites. That is 60.6% of all websites, counting those without HTTPS.

Which certificate authority is the most popular? Let's Encrypt, at 63.9% of trusted certificates, ahead of Google Trust Services at 17.7% and GoDaddy at 6.5%. The three issue 88.2% of trusted certificates between them.

How many websites still use HTTP only? 3,288,919 websites, 2.8% of the web, answer only over plain HTTP. Since Chrome 154, released on 22 September 2026, Chrome asks users before their first visit to any of them.

Are free SSL certificates as secure as paid ones? A free domain validated certificate proves the same thing as a paid domain validated one, control of the domain, and encrypts the connection the same way; organisation and extended validation certificates also name the company, after checks on its legal existence. 81.8% of trusted certificates come from a free authority, and at least 97.4% of all trusted certificates, paid ones included, are domain validated.

How long do SSL certificates last in 2026? Under the CA/Browser Forum's ballot SC-081, now part of the Baseline Requirements, a publicly trusted certificate may last at most 200 days from 15 March 2026, falling to 100 days in March 2027 and 47 days in March 2029. Let's Encrypt's default classic profile issues 90-day certificates and its opt-in tlsserver profile 45-day ones since 13 May 2026, and the default moves to 64 days in February 2027 and 45 days in February 2028.

How many websites have an expired SSL certificate? At least 379,202 websites, 0.35% of those with a publicly trusted certificate, serve a certificate that had expired before the crawl began. The true number is higher, because only certificates from an intermediate that had itself expired or stopped issuing can be counted.

What percentage of websites use HSTS? 38.4% of websites with a trusted certificate send an HSTS header, 42,174,070 websites, which is 36.4% of all websites. Seven hosted platforms send 54.5% of those headers.

Methodology and sources

From every fetch to the websites in this report
Domains at each step, with their share of the domains whose latest fetch answered 200
From every fetch to the websites in this reportLatest fetch answered 200Latest fetch answered 200: 183,672,331 (100.0%)183,672,331 (100.0%)Returned a readable pageReturned a readable page: 125,945,084 (68.6%)125,945,084 (68.6%)At the apex of a registrationAt the apex of a registration: 119,918,539 (65.3%)119,918,539 (65.3%)Parked domains removedParked domains removed: 115,839,436 (63.1%)115,839,436 (63.1%)
From every fetch to the websites in this reportLatest fetch answered 200183,672,331 (100.0%)Returned a readable page125,945,084 (68.6%)At the apex of a registration119,918,539 (65.3%)Parked domains removed115,839,436 (63.1%)
From every fetch to the websites in this reportLatest fetch answered 200183,672,331 (100.0%)Returned a readable page125,945,084 (68.6%)At the apex of a registration119,918,539 (65.3%)Parked domains removed115,839,436 (63.1%)
Embed this figure
<a href="https://www.stackscan.com/blog/ssl-statistics#fig-funnel"><img src="https://content.stackscan.com/charts/ssl-statistics-funnel.webp" alt="From every fetch to the websites in this report" width="880" style="max-width:100%"></a> <p>Source: <a href="https://www.stackscan.com/blog/ssl-statistics#fig-funnel">StackScan SSL analysis</a></p>

The population. Every share is of the 115,839,436 websites whose latest fetch answered 200 with a readable page, at the apex of a registration, with parked domains removed, or of a part of them the sentence names. The apex is a registrable domain as the Public Suffix List defines it. Parked domains come out on four signals: the crawl's parking pass (2,743,795), known parking networks (1,170,557) and the address blocks of GoDaddy's parking and aftermarket services and HugeDomains (163,839). The fourth, the fetch-time parking verdict, removes nothing, because the pages it marks never reach the readable step.

What a stored issuer can show. The crawl keeps the issuer of the certificate each website presented: country, organisation and common name of the intermediate. It does not keep the expiry date, the subject, the names the certificate covers, the TLS version or the rest of the chain. The fetch does not verify the certificate, so trust is judged from the issuer: a certificate counts as trusted when its issuing organisation is one the crawler accepted under full verification in its May pass, or one of three names added by hand, Cloudflare, Inc., Comodo CA Limited and Google Trust Services LLC. Let's Encrypt staging certificates, Cloudflare origin certificates, Symantec-era and other distrusted issuers, and certificates that imitate a trusted issuer's name are rejected even under a trusted organisation name. 1,207,329 Let's Encrypt websites have no recorded intermediate; they count toward Let's Encrypt and not toward the intermediate figures.

The host the certificate comes from. The certificate is the one on the host the fetch finished on. Where that host was recorded, for 50.9% of websites, it was the www address on 60.3% of them, partly because a fetch that fails over HTTPS is tried again at the www address over HTTP.

Hosts, platforms and headers. A host is found by its address blocks, a platform in the platform table by its fingerprints, and the seven HSTS platforms by the response headers they send, so one name can carry three counts: Vercel has 2,337,438 websites with a trusted certificate by address and 2,830,223 by its x-vercel-id header. A CA is counted under the brand on the certificate; the operated view folds white-label brands into the company that runs their intermediate. A website on two platforms counts under both.

Crawl window and plain HTTP. Websites were crawled on 84 days between 23 May 2026 and 29 September 2026, one row per domain at its latest fetch. The May fetches stored no intermediate for Let's Encrypt, so the weekly chart starts in June, and the Generation Y figures use websites crawled since 25 August 2026, by when every certificate issued before the switch had expired or been renewed. On 7 crawl days more than 5% of websites answered only over plain HTTP, and those days hold 33.0% of all plain HTTP websites. To test them, a random sample of 200 plain HTTP websites from the worst day, 4 August 2026, and a control of 200 from the ordinary days were fetched again on 29 September 2026, once over each scheme. Of those, 6 from the worst day and 8 from the control now answer over HTTPS with a trusted certificate, so the busy days crawled real plain HTTP websites. Squarespace, Wix and Shopify issue a certificate for every site they host, so a plain HTTP result from one of them would be a crawl error; it happened on 5,803 of their 13,018,701 websites.

Popularity. Rank bands use the Tranco list 38LNL, generated on 24 August 2026, 4,360,305 entries, each band excluding the ones above it. Only 467 of the top 1,000 names are websites in this base. Of the other 533, 258 never answered, 141 blocked or challenged the crawler with a status such as 403, 429 or 202, 66 answered 200 without a readable page, 44 answered 404, and 24 redirected, failed on the server, were parked or are not at the apex. Many of the names that block crawlers are large commercial sites, so the top 1,000 figures describe the websites that let a crawler in.

HSTS and the preload list. HSTS figures come from the same pass as every other figure, reading the header value of the 109,784,103 websites with a trusted certificate; a policy is effective when max-age is above zero. The preload list is Chromium's transport_security_state_static.json at commit d5e6fd5, dated 11 September 2026, with 94,778 entries.

Why subdomains have no figure. The crawl holds 5,962,579 subdomain hosts under 3,228,280 registered domains, but they are not a sample of subdomains. 69.9% entered from a ranked host list and 20.9% from links on crawled pages, so they were selected for being linked, and no zone file lists subdomains to measure them against. Hosting platforms fill the top by how often they are linked, wordpress.com with 69,478 hosts, and single parents skew the plain HTTP rate: free.fr alone holds 12.1% of the 169,210 plain HTTP subdomains.

Technology pages. The Let's Encrypt technology page counts 97,541,342 domains against 70,152,849 websites here, and GoDaddy SSL's counts 13,923,026 against 7,173,334: both count every domain the detection reads, and every domain whose CAA record names the authority. The Google Trust Services page counts 2,023,618 against 19,472,641, because its rule matches the issuer name Google Trust Services LLC, which only 1,049 of the certificates here carry; Google's current intermediates name Google Trust Services alone.

Not measured here. Certificate lifetimes and expiry dates, which the crawl does not store; the rules are moving fast, from ballot SC-081's limit of 200 days to 47 days by 2029, to Let's Encrypt's 64 and then 45 day default. TLS versions and cipher suites. Whether HTTP redirects to HTTPS. Wildcard and multi-name certificates, and whether the certificate matches the name. Revocation and certificate transparency. Mixed content on HTTPS pages. A year-on-year trend: this is the first crawl of its kind, and the next will be compared with it.

Figures may be reproduced with attribution to StackScan and a link to this page.