Daily monitoring · 476 domains

The Fortune 500 Security Report

We continuously scan the public security configuration of the largest U.S. companies. This page tracks who's improving, who's slipping, and how the cohort as a whole is shifting on TLS, headers, and email auth.

Updated Sep 27, 2026 · 30-day rolling window

By the numbers

The cohort at a glance.

A snapshot across all 476 domains from each one's most recent scan.

Median grade

C

across the cohort

Behind a CDN/WAF

50%

236 of 476

Enforce HSTS

45%

216 domains

Ship a CSP

17%

80 domains

Prefer TLS 1.3

89%

423 domains

DNSSEC enabled

18%

85 domains

Grade distribution

How the whole cohort scores, A through F.

A
47 · 10%
B
161 · 34%
C
265 · 56%
D
3 · 1%
F
0 · 0%

Who's behind a CDN / WAF

Detected from response headers · 50% of domains show a known provider.

Cloudflare
78 · 16%
Fastly
46 · 10%
CloudFront
42 · 9%
Google
30 · 6%
Akamai
24 · 5%
Varnish
10 · 2%
Azure
6 · 1%

Header-based detection records one provider per domain, so this undercounts multi-CDN setups and sites that strip identifying headers.

Today's leaders

The best and worst graded right now.

Same grading formula we use on every individual scan: weighted across SSL, HSTS, CSP, headers, TLS strength, cookie security, DMARC, DKIM, DNSSEC, and more.

Top 5 · highest score

1 discord.com 98 A
2 gizmodo.com 98 A
3 m.me 98 A
4 archives.gov 96 A
5 linkedin.com 96 A

Bottom 5 · lowest score

1 abcnews.go.com 52 D
2 narod.ru 54 D
3 huawei.com 54 D
4 theglobeandmail.com 56 C
5 storage.googleapis.com 56 C

Where would your domain rank?

Run a free scan →

Last 30 days

Who moved?

Comparing each domain's current scan to its scan from ~30 days ago. 10 domains changed at least one security feature in that window.

Domains changed

10

Features added

+8

Features lost

−4

ap.org A
Sep 27
HSTS: off → on X-Frame-Options: off → on WAF detection: off → on
apnews.com A
Sep 27
HSTS: on → off X-Frame-Options: off → on
thetimes.co.uk C
Sep 27
WAF detection: off → on TLS version: TLSv1.2 → TLSv1.3
washingtonpost.com C
Sep 27
CSP: off → on WAF detection: on → off
interia.pl C
Sep 27
TLS version: TLSv1.2 → TLSv1.3
prezi.com B
Sep 27
X-Frame-Options: on → off
ca.gov B
Sep 27
HSTS: off → on
weibo.com C
Sep 27
TLS version: TLSv1.2 → TLSv1.3
cnet.com B
Sep 27
WAF detection: off → on
aliexpress.com C
Sep 27
HSTS: on → off

Track your own domain

Get the same daily monitoring on your site.

Free scan, full report, no signup. Add scheduled monitoring to get alerted when your security config changes — the same way we caught every move on this page.

Scan your site free →