Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Certificates & TLS Cloudflare

Cloudflare adds post-quantum authentication for origin servers

CDN provider enables ML-DSA signatures for mutual TLS between its edge and customer origins.

Cloudflare adds post-quantum authentication for origin servers
panumas nikhomkhai · Pexels

Cloudflare has introduced post-quantum authentication for traffic between its edge network and customer origin servers. The update allows operators to secure mutual TLS (mTLS) connections using Module-Lattice-Based Digital Signature Algorithm (ML-DSA) signatures, addressing risks from quantum computing advancements that could compromise classical cryptographic credentials.

How the feature works

The implementation targets the second leg of a typical Cloudflare-proxied request: the connection from Cloudflare’s edge to the customer’s origin server. While the visitor-to-Cloudflare connection has relied on post-quantum encryption since 2022, authentication for the origin leg now supports ML-DSA via two existing products. Authenticated Origin Pulls (AOP) lets customers require Cloudflare to present a client certificate, while Custom Origin Trust Store (COTS) allows replacement of the default certificate authority (CA) trust store with customer-controlled CAs. Both now accept ML-DSA certificates, enabling fully post-quantum-secure mTLS when used together.

Cloudflare recommends ML-DSA-44 for most use cases, citing its balance of performance and NIST category 2 security strength. The company has also updated its control plane and data plane services to parse and validate ML-DSA certificates, though an internal dependency on an older BoringSSL fork initially caused compatibility issues with some customer certificates during testing.

Configuration and requirements

To deploy the feature, customers must generate ML-DSA certificate chains using OpenSSL 3.5.0 or later, with private keys in FIPS 204 seed-only encoding. The process involves creating separate certificate authorities for the origin server and Cloudflare client certificates, then uploading them via Cloudflare’s API. Origins must run TLS 1.3 and be configured to reject non-post-quantum authentication methods to prevent downgrade attacks. Cloudflare provides NGINX configuration examples for both COTS and AOP setups, as well as verification steps to confirm the handshake uses ML-DSA.

Background

Background: Post-quantum cryptography refers to algorithms designed to resist attacks from quantum computers, which could break widely used classical encryption like RSA and ECC. ML-DSA is a NIST-standardized digital signature algorithm based on lattice cryptography, offering security against quantum decryption threats. Cloudflare’s 2029 target for full post-quantum security reflects industry-wide urgency to migrate before large-scale quantum computers become viable.

Limitations and roadmap

The feature currently excludes the global configuration level for Authenticated Origin Pulls, which remains under development. Cloudflare also plans to add support for Merkle Tree Certificates (MTC) on the origin connection, aligning with its collaboration with Google and the IETF to standardize fast post-quantum certificates for the public web. Native ML-DSA support in Go 1.27, expected in August 2026, is expected to simplify adoption for Go-based services.

An incident in June 2026 highlighted the challenges of migrating legacy systems: a BoringSSL update enforcing stricter KeyUsage validation temporarily invalidated some customer certificates, prompting a rollback and patch to maintain compatibility with non-compliant RSA certificates.

Companies mentioned

Cloudflare

Discussion · coming soon

Be the first to join the thread when community discussion launches.