We scanned the 500 busiest domains on the internet (Tranco list JZ8PY) in the first week of October 2026. Of the 351 that answered, 186 (53%) negotiate post-quantum key exchange with a modern client. Three-fifths of those do so because a content delivery network answers for them; among sites that serve their own traffic, the share is a third. A quarter of all measured sites still complete a TLS 1.0 handshake, and half still accept RSA key exchange, which leaves any session that negotiates it open to a later break of the server’s RSA key, however early its signatures move.
What was measured
Tranco list JZ8PY, ranks 1 to 500, taking the most recent scan of each name on port 443 between 29 September and 6 October 2026, from a single vantage point; which network answers for a name was read from DNS and published address ranges. 351 names answered a TLS handshake. Of the rest, 121 returned no public DNS answer for the name, 19 did not answer in time, and 9 refused the connection, resolved to reserved address space or failed the handshake. For the first IPv4 and the first IPv6 address of each name, the scanner sent a default hello, then each protocol version from SSL 3.0 to TLS 1.3 on its own, each TLS 1.2 cipher suite on its own, each key-exchange group on its own over TLS 1.3, a hello offering only finite-field Diffie-Hellman, and a browser-shaped hello; further addresses were offered TLS 1.3, TLS 1.2 and X25519MLKEM768 on their own. A probe that met a closed connection or no answer was sent again before it counted as a refusal, and one that never got a definite answer is recorded as unknown: the host is marked incomplete, and no finding rests on that probe.
Key exchange
186 of 351 hosts negotiate X25519MLKEM768. 164 negotiate a classical group only, most of them x25519, and one host negotiates no key-exchange group and accepts only RSA key exchange. The split is not even. 119 of the 351 are answered by a content delivery network, and 110 of those negotiate the hybrid group. Of the 231 hosts that serve their own traffic, 75 do. Seven networks are involved, led by Cloudflare (43 hosts, all hybrid), CloudFront (28, all hybrid), Fastly (26, 20 hybrid) and Akamai (18, 15 hybrid); edge networks together account for 59% of the post-quantum capable hosts in the sample. On the busiest part of the web, a site’s post-quantum posture is to a first approximation a statement about which network sits in front of it.
Legacy protocols
90 hosts (26%) complete a TLS 1.0 handshake when offered nothing newer, and 6 more accept TLS 1.1 only. 77 of the 90 serve their own traffic; 13 are behind a content delivery network, where the minimum version is a per-customer setting. 300 hosts negotiate TLS 1.3 with a modern client. The floor has moved for clients that choose, and not for clients that can be pushed.
RSA key exchange
186 hosts (53%) accept RSA key exchange when it is the only option offered, 132 of them self-served. A session that negotiates it has its secret encrypted to the server’s RSA key, so the argument that signature migration can wait, because a signature only has to hold when it is verified, does not apply to that key: such sessions, recorded today, are open to whoever breaks it later. On 104 of these hosts the RSA key is the one in the certificate every client sees; the other 82 show an ECDSA certificate to modern clients and keep an RSA one for clients that ask. One host accepts nothing but RSA key exchange: a hello that does not offer it is refused.
Hybrid key exchange beside older configurations
124 of the 186 hosts that negotiate post-quantum key exchange also offer CBC-mode cipher suites. 55 hosts accept X25519Kyber768Draft00, the pre-standard group Chrome replaced with X25519MLKEM768 in version 131 in November 2024 (Google Online Security Blog, “A new path for Kyber on the web”, 13 September 2024); 42 of them are behind Cloudflare, and one self-served host accepts the draft group and nothing newer. Two hosts, both self-served, accept Diffie-Hellman at 1024 bits or below.
Certificates
216 hosts present an RSA key and 135 an ECDSA key. 166 certificates have a lifetime of 100 days or less, 119 between 101 and 200 days, and 66 longer. 27 were within 30 days of expiry when scanned.
Grades
Under [PQ]probe scoring, where a host without post-quantum key exchange is capped at C and a host accepting TLS 1.0 or 1.1 scores F, the 351 hosts grade A 62, B 26, C 75, D 85, F 103. The worst address of a multi-address host sets its grade.
Data
The list is pinned by its Tranco identifier and the SHA-256 of its first 500 lines, so the same 500 names can be scanned again by anyone. The same list is rescanned weekly and this report is updated quarterly.