Daily monitoring · 476 domains

The Fortune 500 Security Report

We continuously scan the public security configuration of the largest U.S. companies. This page tracks who's improving, who's slipping, and how the cohort as a whole is shifting on TLS, headers, and email auth.

Updated May 29, 2026 · 30-day rolling window

Today's leaders

The best and worst graded right now.

Same grading formula we use on every individual scan: weighted across SSL, HSTS, CSP, headers, TLS strength, cookie security, DMARC, DKIM, DNSSEC, and more.

Top 5 · highest score

1 detik.com 98 A
2 discord.com 98 A
3 gizmodo.com 98 A
4 m.me 98 A
5 archives.gov 96 A

Bottom 5 · lowest score

1 abcnews.go.com 52 D
2 narod.ru 54 D
3 huawei.com 54 D
4 theglobeandmail.com 56 C
5 storage.googleapis.com 56 C

Where would your domain rank?

Run a free scan →

Last 30 days

Who moved?

Comparing each domain's current scan to its scan from ~30 days ago. 11 domains changed at least one security feature in that window.

Domains changed

11

Features added

+8

Features lost

−13

engadget.com C
May 29
HSTS: on off CSP: on off X-Frame-Options: on off WAF detection: off on
aol.com C
May 29
HSTS: on off CSP: on off X-Frame-Options: on off
dreamstime.com C
May 29
HSTS: on off CSP: on off X-Frame-Options: on off
ft.com C
May 29
HSTS: on off CSP: on off WAF detection: off on
justjared.com C
May 29
WAF detection: off on TLS version: TLSv1.2 TLSv1.3
people.com A
May 29
CSP: off on X-Frame-Options: off on
detik.com A
May 29
TLS version: TLSv1.2 TLSv1.3 TLS strength: Medium Strong
washingtonpost.com C
May 29
CSP: on off WAF detection: off on
weather.com C
May 29
WAF detection: on off
standard.co.uk B
May 29
HSTS: off on
imageshack.us B
May 29
HSTS: off on

Track your own domain

Get the same daily monitoring on your site.

Free scan, full report, no signup. Add scheduled monitoring to get alerted when your security config changes — the same way we caught every move on this page.

Scan your site free →