Skip to main content
All Benchmarks
818920 sites · June 2026

EU Website Security Benchmark — June 2026

Security posture snapshot for June 2026 across 818920 monitored European websites.

41.3/100

Average score

100%

Email spoofable

84%

No DNSSEC

53%

Missing security headers

How does your industry compare?

Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.

Industry Sites Score Unprotected Spoofable Insecure Grade distribution
Real Estate 11975
39.5
47% 100% 75%
D
F
Hospitality 110109
40.1
54% 100% 73%
D
F
Automotive 35929
40.7
52% 100% 72%
D
F
NGO & Nonprofit 11819
40.7
51% 100% 76%
D
F
construction 13348
41.0
56% 100% 72%
D
F
Sports 46248
41.0
54% 100% 71%
D
F
pets 3478
41.1
51% 100% 73%
D
F
home-garden 27074
41.2
52% 100% 71%
D
F
Travel 23253
41.2
53% 100% 71%
D
F
Media 4111
41.3
40% 100% 76%
D
F
culture 29842
41.4
56% 100% 71%
D
F
Education 96785
41.4
47% 100% 72%
D
F
Food & Delivery 230277
41.4
57% 100% 70%
D
F
Logistics 2218
41.4
46% 100% 75%
D
F
beauty 30126
41.6
59% 100% 70%
D
F
Adult 328
41.8
44% 100% 81%
D
F
Fashion 28259
41.8
45% 100% 71%
D
F
Pharma 13710
41.8
46% 100% 72%
D
F
Healthcare 51492
41.9
54% 100% 72%
D
F
professional-services 15471
41.9
55% 100% 72%
D
F
Technology 17810
42.5
50% 100% 72%
D
F
Insurance 2987
42.9
40% 100% 76%
D
F
Energy 1777
43.0
38% 100% 77%
D
F
Transport 490
43.6
30% 99% 78%
D
F
E-Commerce 4365
44.1
33% 100% 74%
D
F
Gambling 325
44.3
31% 99% 81%
D
F
Telecom 371
44.5
24% 100% 78%
D
F
Government 1616
44.8
25% 99% 83%
D
F
Regulatory 346
45.7
25% 100% 79%
D
F
Banking 2980
45.9
20% 100% 79%
D
F

Click a column header to sort. Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.

A B C D F

What we found

The most common security gaps across 818920 European websites — and the regulations they violate.

53%

Missing Security Headers

Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.

NIS2 Art. 21

100%

Weak Email Authentication

Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.

NIS2 Art. 21 / DORA Art. 9

84%

No DNSSEC

DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.

NIS2 Art. 21

Where does your website fit in this picture?

Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.

Scan your website now

This data is also available as JSON via the Benchmark API.