Security posture snapshot for May 2026 across 816171 monitored European websites.
42.9/100
Average score
99%
Email spoofable
84%
No DNSSEC
58%
Missing security headers
Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.
| Industry | Sites | Score ▲ | Unprotected | Spoofable | Insecure | Grade distribution |
|---|---|---|---|---|---|---|
| Real Estate | 11949 |
41.5
|
55% | 99% | 55% | |
| Hospitality | 109659 |
41.6
|
59% | 99% | 58% | |
| Automotive | 35824 |
42.4
|
56% | 99% | 56% | |
| NGO & Nonprofit | 11774 |
42.6
|
57% | 98% | 55% | |
| construction | 13325 |
42.7
|
62% | 98% | 54% | |
| pets | 3462 |
42.7
|
59% | 99% | 54% | |
| Sports | 46087 |
42.7
|
60% | 99% | 53% | |
| Travel | 23178 |
42.7
|
59% | 99% | 55% | |
| Food & Delivery | 229346 |
42.8
|
62% | 99% | 55% | |
| culture | 29759 |
42.9
|
61% | 99% | 54% | |
| home-garden | 26993 |
42.9
|
57% | 99% | 53% | |
| beauty | 30041 |
43.1
|
63% | 99% | 53% | |
| Education | 96592 |
43.3
|
53% | 99% | 53% | |
| Fashion | 28157 |
43.6
|
50% | 99% | 53% | |
| Logistics | 2215 |
43.6
|
51% | 98% | 53% | |
| Healthcare | 51308 |
43.7
|
59% | 98% | 51% | |
| professional-services | 15420 |
43.7
|
60% | 98% | 52% | |
| Pharma | 13692 |
44.1
|
49% | 98% | 57% | |
| Technology | 17755 |
44.6
|
55% | 97% | 53% | |
| Media | 4101 |
44.8
|
59% | 98% | 46% | |
| Energy | 1770 |
45.5
|
44% | 97% | 57% | |
| Insurance | 2979 |
45.6
|
45% | 98% | 54% | |
| Adult | 327 |
46.4
|
64% | 98% | 38% | |
| E-Commerce | 4352 |
46.9
|
40% | 96% | 56% | |
| Transport | 488 |
48.3
|
45% | 95% | 47% | |
| Government | 1608 |
49.1
|
36% | 96% | 58% | |
| Telecom | 370 |
49.2
|
39% | 97% | 48% | |
| Gambling | 322 |
49.4
|
56% | 97% | 41% | |
| Banking | 2972 |
50.0
|
24% | 96% | 59% | |
| Regulatory | 345 |
51.4
|
42% | 96% | 40% |
Click a column header to sort. Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.
The most common security gaps across 816171 European websites — and the regulations they violate.
58%
Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.
99%
Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.
84%
DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.
Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.
Scan your website nowThis data is also available as JSON via the Benchmark API.