Skip to main content
All Benchmarks
821884 sites · July 2026

EU Website Security Benchmark — July 2026

Security posture snapshot for July 2026 across 821884 monitored European websites.

39.0/100

Average score

100%

Email spoofable

84%

No DNSSEC

17%

Missing security headers

How does your industry compare?

Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.

Industry Sites Score Unprotected Spoofable Insecure Grade distribution
Real Estate 12003
37.3
13% 100% 90%
D
F
NGO & Nonprofit 11901
38.3
14% 100% 89%
D
F
Automotive 36047
38.4
16% 100% 87%
D
F
Hospitality 110540
38.4
19% 100% 86%
D
F
Fashion 28353
38.5
15% 100% 87%
D
F
Logistics 2218
38.7
15% 100% 88%
D
F
Media 4120
38.8
15% 100% 86%
D
F
pets 3489
38.8
19% 100% 85%
D
F
Sports 46431
38.8
17% 100% 87%
D
F
construction 13384
38.9
16% 100% 89%
D
F
Education 97017
38.9
17% 100% 84%
D
F
home-garden 27148
38.9
18% 100% 86%
D
F
Travel 23327
39.0
18% 100% 86%
D
F
culture 29962
39.1
18% 100% 86%
D
F
Food & Delivery 231331
39.1
18% 100% 87%
D
F
beauty 30219
39.2
17% 100% 88%
D
F
Pharma 13752
39.2
13% 100% 88%
D
F
Adult 331
39.4
14% 100% 83%
D
F
Healthcare 51635
39.6
16% 100% 88%
D
F
professional-services 15522
39.6
16% 100% 89%
D
F
Technology 17869
39.8
17% 100% 86%
D
F
Insurance 2991
39.9
11% 100% 89%
D
F
Energy 1780
40.4
15% 100% 85%
D
F
Transport 490
40.6
11% 100% 87%
D
F
E-Commerce 4376
40.9
13% 100% 86%
D
F
Gambling 325
41.3
14% 100% 86%
D
F
Government 1618
41.8
8% 100% 89%
D
F
Regulatory 348
42.2
8% 100% 88%
D
F
Telecom 372
42.3
11% 100% 84%
D
F
Banking 2984
43.1
8% 100% 88%
D
F

Click a column header to sort. Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.

A B C D F

What we found

The most common security gaps across 821884 European websites — and the regulations they violate.

17%

Missing Security Headers

Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.

NIS2 Art. 21

100%

Weak Email Authentication

Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.

NIS2 Art. 21 / DORA Art. 9

84%

No DNSSEC

DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.

NIS2 Art. 21

Where does your website fit in this picture?

Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.

Scan your website now

This data is also available as JSON via the Benchmark API.