Research

EU Domain Security Survey 2026

We scanned 12,905 domains across 26 European countries to measure what organisations have actually deployed — not what standards recommend.

Published 3 August 2026 · Raw data and method below

24.5%
still accept TLS 1.0
Deprecated since 2018 and prohibited under PCI DSS.
43.9%
enforce DMARC
75.2% publish a record, but 40.1% of those sit at p=none.
10.3%
have all five security headers
HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy.

Every measurement here is externally observable — published DNS records, TLS handshakes and HTTP response headers. No domain was probed beyond what a browser or mail server sees in ordinary use. Results are reported in aggregate only; no organisation is named.

Email authentication

SPF is nearly universal at 90.1%, but under half of those records use a hardfail (-all) policy — the rest use ~all, which asks receiving servers to flag unauthorised mail rather than reject it.

DMARC tells a more interesting story. Three quarters of domains publish a record, which sounds like broad adoption. But 40.1% of those records are set to p=none — monitoring only, taking no action against spoofed mail. A p=none policy is meant to be a temporary phase lasting weeks while you identify your senders. For a plurality of European domains it appears to be the permanent state.

SPF record present
90.1%n=12,882
— of which hardfail (-all)
44.3%n=12,882
DKIM detected
58.6%n=12,899
DMARC record present
75.2%n=12,880
DMARC enforcing (quarantine or reject)
43.9%n=12,880
MTA-STS configured
2.7%n=12,905

MTA-STS, which forces TLS encryption between mail servers, sits at 2.7% — effectively unadopted eight years after publication as an IETF standard.

TLS and certificates

The headline finding: 24.5% of reachable domains still accept TLS 1.0, and 25.7% accept TLS 1.1. Both were deprecated in 2018 and neither is permitted for systems in PCI DSS scope.

This is invisible to most testing. A handshake negotiates the highest version both sides support, so a modern browser connecting to these domains gets TLS 1.3 and everything looks current. Whether an old client could still negotiate TLS 1.0 is a different question, and answering it requires probing each version separately.

Valid, trusted certificate
88.5%n=12,905
TLS 1.3 supported
84.6%n=11,835
TLS 1.0 still enabled
24.5%n=11,835
TLS 1.1 still enabled
25.7%n=11,835
Incomplete certificate chain
0.6%n=11,835
CAA records published
15.5%n=12,905
Certificate expiring within 30 days
3.6%n=11,835

Security headers

Only 10.3% of domains set all five commonly recommended response headers. HSTS reaches 45.1% and Content-Security-Policy 28.2% — the latter being both the most effective against cross-site scripting and the most work to deploy.

Country ranking

Countries are ranked by a composite score weighting DMARC enforcement 35%, valid TLS 25%, absence of TLS 1.0 15%, HSTS 15% and SPF 10%. The weighting is a judgement call — the raw data is published below so you can weight it differently.

The spread is wide. Netherlands leads at 75.5; Greece sits last at 55.5. On TLS 1.0 specifically the gap is more than fourfold between the best and worst.

#CountrynScoreDMARC enf.TLS 1.0HSTSValid TLS
1Netherlands49575.563%13.9%59.2%90.3%
2United Kingdom43274.467.7%13.3%52.3%83.8%
3Denmark4967462.1%17.8%53.4%90.9%
4Germany50070.646.5%10.3%59.2%91.2%
5Sweden49870.355.9%25.7%55.6%89.4%
6France49768.550.1%17.8%50.1%87.1%
7Ireland49767.848.3%22.9%51.3%91.8%
8Belgium49667.848.7%16.5%48.6%87.9%
9Poland50066.947.6%21.4%40%92%
10Estonia50066.145.3%22.8%43.8%92.4%
11Austria49665.139.3%15%50.8%88.3%
12Czechia49964.641.5%24.8%46.3%92%
13Luxembourg25064.249.2%22.9%42.4%82.8%
14Spain49863.849.7%18.9%41.2%76.7%
15Portugal49963.846.1%26.1%46.9%82.2%
16Italy49963.740.5%18.3%44.5%85.8%
17Finland49663.539%22%54.4%85.3%
18Latvia49962.444.3%32.3%39.7%88.4%
19Romania49862.340.3%32.5%38.4%92.2%
20Slovakia50061.537.1%26%37.8%90%
21Bulgaria50060.738%37.5%40.4%91.2%
22Lithuania49960.336.9%36.5%38.9%91.6%
23Slovenia49859.635.3%27%37%87.6%
24Croatia49958.332.9%37.6%36.7%90.6%
25Hungary49958.128.5%24.7%36.7%89.2%
26Greece50055.531.4%44.3%32%89%

Providers and certificate authorities

Email providers detected
Microsoft 3653,466
Google Workspace1,680
Mailchimp / Mandrill356
SendGrid350
Mimecast89
Mailjet76
Zoho Mail32
Fastmail15
Certificate authorities
Let's Encrypt3,955
Google Trust Services2,976
DigiCert Inc1,216
Sectigo Limited1,066
Amazon802
Hellenic Academic and Research Institutions CA555
GlobalSign nv-sa356
Asseco Data Systems S.A.93

Microsoft 365 leads Google Workspace roughly two to one among domains where a provider could be identified. Let's Encrypt and Google Trust Services together account for around 60% of observed certificates.

An unexpected result

The fifth-largest certificate issuer in this dataset is the Hellenic Academic and Research Institutions CA — and only 4% of its certificates are in Greece. The rest are spread across all 26 countries, with France and Germany the largest users. Every domain we sampled was a university, research institute or academic repository.

This reflects European research networking rather than anything national: HARICA supplies certificates to research and education institutions across Europe. Roughly one in twenty certificates observed in this survey traces back to that single arrangement.

Method

  • Domains sourced from the Tranco top-1M and attributed to a country by ccTLD.
  • Organisations using generic TLDs such as .com are not captured.
  • Domain existence determined by SOA record, so mail-only domains are included.
  • Every percentage is computed over domains where the fact was determined; unknowns are excluded from both numerator and denominator, and the denominator (n) is reported alongside each figure.
  • Scanned sequentially over IPv4 from a single European host; IPv6-only hosts are recorded as unreachable.
  • DKIM figures are a lower bound — selectors are not publicly enumerable, so undetected selectors read as absent.
  • Composite score weights DMARC enforcement 35%, valid TLS 25%, absence of TLS 1.0 15%, HSTS 15%, SPF 10%.

Collection ran sequentially over roughly five hours. Four control domains known to have SPF, DMARC and valid TLS were re-tested every 200 scans; all 66 checks passed, and the run was configured to abort if any failed. The audit log is published with the data.

Known limitations. ccTLD attribution misses organisations using generic TLDs — an Irish company on a .com is not counted under Ireland. DKIM figures are a lower bound, because selectors are not publicly enumerable and an undetected selector reads as absent. Scanning from a single European location means latency-sensitive results may differ elsewhere. IPv6-only hosts are recorded as unreachable.

Tranco ranks by traffic, which over-represents universities, research institutions and large media relative to their share of organisations. Those tend to have better email authentication than small businesses, so the figures here are more likely to flatter European security posture than to understate it. A survey weighted towards SMEs would almost certainly report worse numbers.

Raw data

The complete per-domain results are published so the figures above can be verified or recomputed. We ask that you cite this page if you use them.

rankings.json ↓per-domain results.csv ↓

Check your own domain

Same checks · Free · No sign-up · Results never published

Run a Scan →