Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities

Browsers may soon enforce HTTPS by default with HSTS-Enforced

A proposed standard flips the web’s security model from opt-in to opt-out encryption.

Browsers may soon enforce HTTPS by default with HSTS-Enforced
Ann H · Pexels

The web’s long-standing vulnerability to downgrade attacks may soon be addressed by a new security model called HSTS-Enforced. Currently, browsers default to unencrypted HTTP unless a website explicitly signals support for HTTPS, creating an opening for attackers to intercept or manipulate traffic. HSTS-Enforced proposes reversing this assumption, making encrypted connections the baseline and requiring operators to actively declare when HTTP is necessary for legitimate use cases. This shift could close a decades-old security gap without disrupting the majority of modern web services already using HTTPS by default.

How HSTS-Enforced works

Under the existing HTTP Strict Transport Security (HSTS) standard, websites must opt into encryption by sending a header that instructs browsers to use HTTPS for future visits. HSTS-Enforced builds on this concept but inverts the logic: browsers would assume HTTPS is required unless a trusted signal indicates otherwise. Two mechanisms would enable verifiable exceptions for services that genuinely cannot support encryption. First, DNS-based declarations protected by DNSSEC would allow domain operators to authenticate their need for HTTP at the infrastructure level. Second, a browser-managed preload list would maintain a curated set of services known to require unencrypted connections, similar to existing HSTS preload systems.

When a user attempts to access a site, the browser would first try HTTPS. If the connection fails, it would only fall back to HTTP if either the DNS record or the preload list confirms the destination intentionally operates without encryption. This approach shifts the burden of proof from users and browsers—who currently must detect and enforce security—to website operators, who would need to provide evidence that unencrypted transport is necessary. The change targets the weakest point in current defenses: the initial connection to a domain, where browsers lack prior knowledge of its security preferences.

Background

Background: HTTP Strict Transport Security (HSTS) is a web security policy that forces browsers to use HTTPS for all connections to a domain after the first visit. HSTS preload lists allow browsers to enforce this rule from the first request, but adoption remains optional. Downgrade attacks exploit the web’s legacy fallback to HTTP when HTTPS is unavailable or blocked, enabling interception without breaking encryption.

Compatibility and operational impact

The proposal acknowledges the web’s heterogeneity, where a small but persistent subset of systems—such as legacy industrial controls, diagnostic tools, or internal networks—still rely on HTTP. Forcing HTTPS universally could break these services, so HSTS-Enforced includes safeguards to accommodate legitimate exceptions. However, the model introduces new responsibilities for operators of such systems. They would need to configure DNSSEC-signed records or apply for inclusion in the preload list to signal their requirements, replacing the current passive reliance on browsers’ automatic fallback behavior.

For most website operators, the change would reduce configuration overhead. Instead of manually enabling HSTS or preload lists, secure transport would become the default, aligning with the reality that over 90% of web traffic already uses HTTPS. Performance impact is expected to be minimal, as the change affects connection logic rather than transport efficiency. The primary challenge lies in coordinating the rollout across browsers, DNS providers, and standards bodies to ensure consistent enforcement and exception handling.

What’s next

Implementation of HSTS-Enforced would require a staged approach. The first phase would focus on establishing robust, tamper-resistant mechanisms for signaling HTTP requirements, likely through DNSSEC and preload lists. Only after these systems are stable would browsers begin phasing out automatic fallbacks to HTTP, transitioning from an opt-in to an opt-out security model. The proposal’s authors have released open-source artifacts to support testing and development, but widespread adoption hinges on browser vendors and standards organizations integrating the changes into their roadmaps.

For now, operators can mitigate downgrade risks by enabling HTTPS-Only mode in browsers, keeping software updated, and avoiding certificate warnings. Website owners should implement HSTS with preload lists and DNSSEC where possible to prepare for a future where encryption is the default rather than an optional upgrade.

Discussion · coming soon

Be the first to join the thread when community discussion launches.