We scan 822307 European websites every week — banking, pharma, e-commerce, government, tech. No individual sites are named. The question isn't who failed. It's which industries are exposed.
40.1/100
Average score
100%
Email spoofable
84%
No DNSSEC
31%
Missing security headers
Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.
| Industry | Sites | Score ▲ | Unprotected | Spoofable | Pre-Consent | Grade distribution |
|---|---|---|---|---|---|---|
| Real Estate | 12006 |
|
27% | 100% | 22% |
D
F
|
| Hospitality | 110591 |
|
32% | 100% | 17% |
D
F
|
| Automotive | 36073 |
|
30% | 100% | 16% |
D
F
|
| NGO & Nonprofit | 11915 |
|
28% | 100% | 19% |
D
F
|
| Fashion | 28371 |
|
27% | 100% | 18% |
D
F
|
| pets | 3492 |
|
31% | 100% | 15% |
D
F
|
| Sports | 46457 |
|
31% | 100% | 16% |
D
F
|
| construction | 13398 |
|
30% | 100% | 13% |
D
F
|
| Food & Delivery | 231427 |
|
32% | 100% | 13% |
D
F
|
| home-garden | 27165 |
|
31% | 100% | 15% |
D
F
|
| culture | 29977 |
|
31% | 100% | 17% |
D
F
|
| Travel | 23343 |
|
32% | 100% | 17% |
D
F
|
| beauty | 30236 |
|
32% | 100% | 12% |
D
F
|
| Education | 97056 |
|
29% | 100% | 20% |
D
F
|
| Logistics | 2221 |
|
31% | 100% | 16% |
D
F
|
| Pharma | 13767 |
|
26% | 100% | 14% |
D
F
|
| professional-services | 15529 |
|
30% | 100% | 16% |
D
F
|
| Healthcare | 51656 |
|
30% | 100% | 14% |
D
F
|
| Media | 4119 |
|
33% | 100% | 24% |
D
F
|
| Technology | 17882 |
|
31% | 100% | 16% |
D
F
|
| Insurance | 2990 |
|
25% | 100% | 13% |
D
F
|
| Energy | 1782 |
|
28% | 100% | 16% |
D
F
|
| Adult | 330 |
|
59% | 100% | 11% |
D
F
|
| Government | 1623 |
|
24% | 99% | 24% |
C
D
F
|
| E-Commerce | 4378 |
|
39% | 100% | 17% |
D
F
|
| Transport | 490 |
|
36% | 100% | 19% |
C
D
F
|
| Banking | 2985 |
|
16% | 100% | 14% |
C
D
F
|
| Gambling | 327 |
|
50% | 99% | 12% |
C
D
F
|
| Telecom | 372 |
|
36% | 100% | 21% |
C
D
F
|
| Regulatory | 348 |
|
35% | 100% | 33% |
C
D
F
|
Click a column header to sort. Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC.
Average security score by country — hover for details, click to explore.
/100 · sites
Security posture by country — click a country to see its detailed breakdown.
Austria
33731 sites
Belgium
23430 sites
Bulgaria
3949 sites
Croatia
5732 sites
Cyprus
1271 sites
Czech Republic
17565 sites
Denmark
15440 sites
Estonia
3292 sites
European Union
193 sites
Finland
12529 sites
France
87830 sites
Germany
226969 sites
Greece
7760 sites
Hungary
7490 sites
Iceland
1227 sites
Ireland
10259 sites
Italy
53284 sites
Latvia
2146 sites
Liechtenstein
179 sites
Lithuania
3704 sites
Luxembourg
1656 sites
Malta
768 sites
Netherlands
57621 sites
Norway
9452 sites
Poland
42561 sites
Portugal
7276 sites
Romania
6269 sites
Slovakia
10674 sites
Slovenia
3101 sites
Spain
36384 sites
Sweden
11058 sites
Switzerland
28591 sites
United Kingdom
88915 sites
Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.
Scan your website nowThe most common security gaps across 822307 European websites — and the regulations they violate.
31%
Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.
100%
Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.
84%
DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.
Explore specific dimensions of Europe's web landscape in detail.
How we scan, what we measure, how scores are computed.
Every site is scanned weekly across these security dimensions. Scores are computed on a 100-point scale.
HSTS, CSP, X-Frame-Options, X-Content-Type, Referrer-Policy, Permissions-Policy
Key strength, signature algorithm, chain depth, TLS version, forward secrecy
HTTP-to-HTTPS redirect for all visitors
SPF, DKIM (key strength), DMARC (policy enforcement)
DNSSEC signing, CAA records, DoH consistency, DANE/TLSA
Vulnerability disclosure contact per RFC 9116
Inbound email TLS enforcement (enforce vs. testing mode)
SMTP TLS failure reporting endpoint
No server version disclosure, no X-Powered-By, restricted CORS
Data based on automated weekly scans of publicly accessible websites.
No individual site names are disclosed. All statistics are anonymised by industry.
Regulatory references indicate which requirements relate to each finding. They do not assert non-compliance of any specific organisation.
Run a free security scan and see your score, your grade, and how you compare — in 30 seconds, no account needed.
This data is also available as JSON via the Benchmark API.