Security posture snapshot for April 2026 across 812023 monitored European websites.
38.5/100
Average score
91%
Email spoofable
84%
No DNSSEC
63%
Missing security headers
Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.
| Industry | Sites | Score ▲ | Unprotected | Spoofable | Insecure | Grade distribution |
|---|---|---|---|---|---|---|
| Hospitality | 109011 |
37.2
|
65% | 92% | 55% | |
| beauty | 29902 |
37.7
|
67% | 93% | 55% | |
| Food & Delivery | 227992 |
37.7
|
67% | 93% | 54% | |
| home-garden | 26867 |
38.1
|
60% | 91% | 55% | |
| pets | 3446 |
38.1
|
63% | 91% | 54% | |
| Travel | 23053 |
38.1
|
63% | 90% | 56% | |
| culture | 29613 |
38.2
|
65% | 91% | 54% | |
| Sports | 45850 |
38.4
|
64% | 91% | 53% | |
| Education | 96269 |
38.5
|
57% | 90% | 55% | |
| Real Estate | 11899 |
38.5
|
63% | 92% | 47% | |
| Automotive | 35564 |
38.7
|
62% | 90% | 54% | |
| professional-services | 15345 |
39.6
|
64% | 88% | 53% | |
| construction | 13282 |
39.7
|
69% | 90% | 49% | |
| Fashion | 28027 |
39.7
|
53% | 91% | 51% | |
| Healthcare | 51098 |
40.1
|
65% | 90% | 49% | |
| NGO & Nonprofit | 11737 |
40.2
|
65% | 90% | 46% | |
| Technology | 17667 |
40.7
|
59% | 84% | 52% | |
| Media | 4081 |
42.2
|
66% | 90% | 32% | |
| Logistics | 2208 |
42.3
|
60% | 82% | 46% | |
| E-Commerce | 4342 |
42.5
|
46% | 95% | 46% | |
| Adult | 326 |
42.9
|
67% | 88% | 21% | |
| Pharma | 13636 |
43.0
|
60% | 85% | 40% | |
| Gambling | 319 |
43.3
|
59% | 86% | 31% | |
| Energy | 1758 |
44.5
|
50% | 81% | 44% | |
| Insurance | 2970 |
44.6
|
54% | 85% | 41% | |
| Telecom | 370 |
45.3
|
40% | 86% | 38% | |
| Transport | 487 |
46.5
|
52% | 84% | 27% | |
| Regulatory | 345 |
49.3
|
47% | 71% | 20% | |
| Banking | 2961 |
51.2
|
25% | 80% | 40% | |
| Government | 1597 |
51.3
|
49% | 81% | 22% |
Click a column header to sort. Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.
The most common security gaps across 812023 European websites — and the regulations they violate.
63%
Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.
91%
Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.
84%
DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.
Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.
Scan your website nowThis data is also available as JSON via the Benchmark API.