EU Domain Security Survey 2026
We scanned 12,905 domains across 26 European countries to measure what organisations have actually deployed — not what standards recommend.
Published 3 August 2026 · Raw data and method below
Every measurement here is externally observable — published DNS records, TLS handshakes and HTTP response headers. No domain was probed beyond what a browser or mail server sees in ordinary use. Results are reported in aggregate only; no organisation is named.
Email authentication
SPF is nearly universal at 90.1%, but under half of those records use a hardfail (-all) policy — the rest use ~all, which asks receiving servers to flag unauthorised mail rather than reject it.
DMARC tells a more interesting story. Three quarters of domains publish a record, which sounds like broad adoption. But 40.1% of those records are set to p=none — monitoring only, taking no action against spoofed mail. A p=none policy is meant to be a temporary phase lasting weeks while you identify your senders. For a plurality of European domains it appears to be the permanent state.
| SPF record present | 90.1% | n=12,882 | |
| — of which hardfail (-all) | 44.3% | n=12,882 | |
| DKIM detected | 58.6% | n=12,899 | |
| DMARC record present | 75.2% | n=12,880 | |
| DMARC enforcing (quarantine or reject) | 43.9% | n=12,880 | |
| MTA-STS configured | 2.7% | n=12,905 |
MTA-STS, which forces TLS encryption between mail servers, sits at 2.7% — effectively unadopted eight years after publication as an IETF standard.
TLS and certificates
The headline finding: 24.5% of reachable domains still accept TLS 1.0, and 25.7% accept TLS 1.1. Both were deprecated in 2018 and neither is permitted for systems in PCI DSS scope.
This is invisible to most testing. A handshake negotiates the highest version both sides support, so a modern browser connecting to these domains gets TLS 1.3 and everything looks current. Whether an old client could still negotiate TLS 1.0 is a different question, and answering it requires probing each version separately.
| Valid, trusted certificate | 88.5% | n=12,905 | |
| TLS 1.3 supported | 84.6% | n=11,835 | |
| TLS 1.0 still enabled | 24.5% | n=11,835 | |
| TLS 1.1 still enabled | 25.7% | n=11,835 | |
| Incomplete certificate chain | 0.6% | n=11,835 | |
| CAA records published | 15.5% | n=12,905 | |
| Certificate expiring within 30 days | 3.6% | n=11,835 |
Security headers
Only 10.3% of domains set all five commonly recommended response headers. HSTS reaches 45.1% and Content-Security-Policy 28.2% — the latter being both the most effective against cross-site scripting and the most work to deploy.
Country ranking
Countries are ranked by a composite score weighting DMARC enforcement 35%, valid TLS 25%, absence of TLS 1.0 15%, HSTS 15% and SPF 10%. The weighting is a judgement call — the raw data is published below so you can weight it differently.
The spread is wide. Netherlands leads at 75.5; Greece sits last at 55.5. On TLS 1.0 specifically the gap is more than fourfold between the best and worst.
| # | Country | n | Score | DMARC enf. | TLS 1.0 | HSTS | Valid TLS |
|---|---|---|---|---|---|---|---|
| 1 | Netherlands | 495 | 75.5 | 63% | 13.9% | 59.2% | 90.3% |
| 2 | United Kingdom | 432 | 74.4 | 67.7% | 13.3% | 52.3% | 83.8% |
| 3 | Denmark | 496 | 74 | 62.1% | 17.8% | 53.4% | 90.9% |
| 4 | Germany | 500 | 70.6 | 46.5% | 10.3% | 59.2% | 91.2% |
| 5 | Sweden | 498 | 70.3 | 55.9% | 25.7% | 55.6% | 89.4% |
| 6 | France | 497 | 68.5 | 50.1% | 17.8% | 50.1% | 87.1% |
| 7 | Ireland | 497 | 67.8 | 48.3% | 22.9% | 51.3% | 91.8% |
| 8 | Belgium | 496 | 67.8 | 48.7% | 16.5% | 48.6% | 87.9% |
| 9 | Poland | 500 | 66.9 | 47.6% | 21.4% | 40% | 92% |
| 10 | Estonia | 500 | 66.1 | 45.3% | 22.8% | 43.8% | 92.4% |
| 11 | Austria | 496 | 65.1 | 39.3% | 15% | 50.8% | 88.3% |
| 12 | Czechia | 499 | 64.6 | 41.5% | 24.8% | 46.3% | 92% |
| 13 | Luxembourg | 250 | 64.2 | 49.2% | 22.9% | 42.4% | 82.8% |
| 14 | Spain | 498 | 63.8 | 49.7% | 18.9% | 41.2% | 76.7% |
| 15 | Portugal | 499 | 63.8 | 46.1% | 26.1% | 46.9% | 82.2% |
| 16 | Italy | 499 | 63.7 | 40.5% | 18.3% | 44.5% | 85.8% |
| 17 | Finland | 496 | 63.5 | 39% | 22% | 54.4% | 85.3% |
| 18 | Latvia | 499 | 62.4 | 44.3% | 32.3% | 39.7% | 88.4% |
| 19 | Romania | 498 | 62.3 | 40.3% | 32.5% | 38.4% | 92.2% |
| 20 | Slovakia | 500 | 61.5 | 37.1% | 26% | 37.8% | 90% |
| 21 | Bulgaria | 500 | 60.7 | 38% | 37.5% | 40.4% | 91.2% |
| 22 | Lithuania | 499 | 60.3 | 36.9% | 36.5% | 38.9% | 91.6% |
| 23 | Slovenia | 498 | 59.6 | 35.3% | 27% | 37% | 87.6% |
| 24 | Croatia | 499 | 58.3 | 32.9% | 37.6% | 36.7% | 90.6% |
| 25 | Hungary | 499 | 58.1 | 28.5% | 24.7% | 36.7% | 89.2% |
| 26 | Greece | 500 | 55.5 | 31.4% | 44.3% | 32% | 89% |
Providers and certificate authorities
Microsoft 365 leads Google Workspace roughly two to one among domains where a provider could be identified. Let's Encrypt and Google Trust Services together account for around 60% of observed certificates.
The fifth-largest certificate issuer in this dataset is the Hellenic Academic and Research Institutions CA — and only 4% of its certificates are in Greece. The rest are spread across all 26 countries, with France and Germany the largest users. Every domain we sampled was a university, research institute or academic repository.
This reflects European research networking rather than anything national: HARICA supplies certificates to research and education institutions across Europe. Roughly one in twenty certificates observed in this survey traces back to that single arrangement.
Method
- Domains sourced from the Tranco top-1M and attributed to a country by ccTLD.
- Organisations using generic TLDs such as .com are not captured.
- Domain existence determined by SOA record, so mail-only domains are included.
- Every percentage is computed over domains where the fact was determined; unknowns are excluded from both numerator and denominator, and the denominator (n) is reported alongside each figure.
- Scanned sequentially over IPv4 from a single European host; IPv6-only hosts are recorded as unreachable.
- DKIM figures are a lower bound — selectors are not publicly enumerable, so undetected selectors read as absent.
- Composite score weights DMARC enforcement 35%, valid TLS 25%, absence of TLS 1.0 15%, HSTS 15%, SPF 10%.
Collection ran sequentially over roughly five hours. Four control domains known to have SPF, DMARC and valid TLS were re-tested every 200 scans; all 66 checks passed, and the run was configured to abort if any failed. The audit log is published with the data.
Known limitations. ccTLD attribution misses organisations using generic TLDs — an Irish company on a .com is not counted under Ireland. DKIM figures are a lower bound, because selectors are not publicly enumerable and an undetected selector reads as absent. Scanning from a single European location means latency-sensitive results may differ elsewhere. IPv6-only hosts are recorded as unreachable.
Tranco ranks by traffic, which over-represents universities, research institutions and large media relative to their share of organisations. Those tend to have better email authentication than small businesses, so the figures here are more likely to flatter European security posture than to understate it. A survey weighted towards SMEs would almost certainly report worse numbers.
Raw data
The complete per-domain results are published so the figures above can be verified or recomputed. We ask that you cite this page if you use them.