Top 1 Million Analysis – June 2026: The State of Crypto

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A data-driven analysis of the cryptographic state of the top 1 million websites as of June 2026, based on a crawl of 819,002 sites. Key findings: Let's Encrypt and Google Trust Services dominate certificate issuance with 90-day automated certificates now representing 77% of all certs. ECDSA has overtaken RSA as the most common authentication key type. TLS 1.3 is now the dominant protocol at 70%+ of sites. Most strikingly, X25519MLKEM768 — a post-quantum hybrid key exchange — is now the single most common key exchange group at 44% of responding sites, driven by Cloudflare and Google enabling it by default. ECH adoption has also reached nearly 200,000 sites. The analysis highlights how infrastructure defaults from a handful of CDN and CA providers are driving massive cryptographic improvements across the web with little action required from individual site owners.

11m read timeFrom scotthelme.ghost.io
Post cover image
Table of contents
IntroductionCertificatesHow long do certificates live?A tale of two CA modelsCertificate Authority AuthorisationTLS versionsCipher SuitesKey Exchange and the arrival of post-quantumAuthentication KeysOCSP staplingEncrypted Client Hello (ECH)Closing thoughtsGet the data
145 Impressions