Daily monitoring · 476 domains

The Fortune 500 Security Report

We continuously scan the public security configuration of the largest U.S. companies. This page tracks who's improving, who's slipping, and how the cohort as a whole is shifting on TLS, headers, and email auth.

Updated Sep 25, 2026 · 30-day rolling window

By the numbers

The cohort at a glance.

A snapshot across all 476 domains from each one's most recent scan.

Median grade

C

across the cohort

Behind a CDN/WAF

50%

237 of 476

Enforce HSTS

45%

216 domains

Ship a CSP

17%

80 domains

Prefer TLS 1.3

89%

423 domains

DNSSEC enabled

18%

85 domains

Grade distribution

How the whole cohort scores, A through F.

A
47 · 10%
B
161 · 34%
C
265 · 56%
D
3 · 1%
F
0 · 0%

Who's behind a CDN / WAF

Detected from response headers · 50% of domains show a known provider.

Cloudflare
78 · 16%
Fastly
47 · 10%
CloudFront
42 · 9%
Google
30 · 6%
Akamai
24 · 5%
Varnish
10 · 2%
Azure
6 · 1%

Header-based detection records one provider per domain, so this undercounts multi-CDN setups and sites that strip identifying headers.

Today's leaders

The best and worst graded right now.

Same grading formula we use on every individual scan: weighted across SSL, HSTS, CSP, headers, TLS strength, cookie security, DMARC, DKIM, DNSSEC, and more.

Top 5 · highest score

1 discord.com 98 A
2 gizmodo.com 98 A
3 m.me 98 A
4 archives.gov 96 A
5 linkedin.com 96 A

Bottom 5 · lowest score

1 abcnews.go.com 52 D
2 narod.ru 54 D
3 huawei.com 54 D
4 theglobeandmail.com 56 C
5 storage.googleapis.com 56 C

Where would your domain rank?

Run a free scan →

Last 30 days

Who moved?

Comparing each domain's current scan to its scan from ~30 days ago. 11 domains changed at least one security feature in that window.

Domains changed

11

Features added

+9

Features lost

−4

ap.org A
Sep 25
HSTS: off → on X-Frame-Options: off → on WAF detection: off → on
apnews.com A
Sep 25
HSTS: on → off X-Frame-Options: off → on
thetimes.co.uk C
Sep 25
WAF detection: off → on TLS version: TLSv1.2 → TLSv1.3
washingtonpost.com C
Sep 25
CSP: off → on WAF detection: on → off
interia.pl C
Sep 25
TLS version: TLSv1.2 → TLSv1.3
prezi.com B
Sep 25
X-Frame-Options: on → off
tripadvisor.com B
Sep 25
HSTS: off → on
ca.gov B
Sep 25
HSTS: off → on
weibo.com C
Sep 25
TLS version: TLSv1.2 → TLSv1.3
aliexpress.com C
Sep 25
HSTS: on → off
cnet.com B
Sep 25
WAF detection: off → on

Track your own domain

Get the same daily monitoring on your site.

Free scan, full report, no signup. Add scheduled monitoring to get alerted when your security config changes — the same way we caught every move on this page.

Scan your site free →