Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
SaaS Developer Tools Cloudflare

Cloudflare adds task-based OAuth consent controls

Users can now deselect optional scopes during third-party app authorization.

Cloudflare adds task-based OAuth consent controls
Atlantic Ambience · Pexels

Cloudflare has introduced a granular consent model for its OAuth authorization flows, giving users the ability to selectively approve or deny individual permissions when connecting third-party applications. The update addresses a long-standing limitation in delegated access systems where users faced an all-or-nothing choice when granting permissions to apps acting on their behalf. Previously, if an application requested multiple scopes, users could either accept the full set or reject the entire request—no middle ground existed for narrowing access to only what was necessary for a specific task. This often led to overprivileged integrations, particularly for tools like multi-cloud provisioning (MCP) servers that might request broad permissions but only use a subset for routine operations.

How the new system works

The optional scopes feature allows developers to designate certain permissions as non-essential when configuring an OAuth client. During the authorization flow, users see a consent screen that clearly separates required scopes from optional ones, with the ability to deselect any optional permissions before approving the request. The system evaluates only the scopes requested in that specific authorization flow, not the full set configured for the client. For example, if an app is configured with four scopes but only requests two during a particular flow, the consent screen will only display those two—even if one of the unrequested scopes was marked as optional in the client configuration. This keeps the interface focused on the immediate task and prevents users from being overwhelmed by permissions not relevant to the current operation.

Background

Background: OAuth (Open Authorization) is an open standard for delegated access, allowing applications to act on a user’s behalf without handling passwords or long-lived credentials. Cloudflare’s implementation supports integrations for its CDN, Workers platform, and other services, with scopes defining the specific actions an app can perform (e.g., reading user details or modifying zone settings).

The change is backward-compatible: existing OAuth clients retain their current behavior unless developers explicitly opt into optional scopes. When a user deselects optional permissions, the resulting access token contains only the approved scopes, requiring developers to check the granted scope set after exchanging the authorization code rather than assuming the full requested set was approved. Cloudflare has also updated its API to allow developers to mark scopes as optional during client configuration, using a new optional_scopes parameter in the OAuth client creation or update requests.

Impact on developers and users

For developers, the update reduces the need to build custom pre-authorization screens to narrow scope requests. Instead, they can rely on Cloudflare’s consent flow to handle granular permission selection, simplifying the integration process for tools that require flexible access levels. The change also encourages better security practices by allowing apps to request only the minimum permissions needed for a task while marking the rest as optional—a signal to users that the app respects their access decisions. Users, particularly security-conscious ones, gain more control over what they approve without being forced into an all-or-nothing choice.

For professionals

For professionals: If you maintain Cloudflare OAuth integrations, audit your scope requests to identify permissions that can be marked as optional. Update your code to handle partial grants by checking the actual scopes returned in the access token, rather than assuming the full requested set was approved. This ensures your app remains functional even when users narrow permissions.

Cloudflare plans to expand its role-based access controls over the coming weeks, extending granular permissions to nearly all of its products. This will include additional API token roles, account membership options, and OAuth scopes, providing customers with more tools to secure workloads with precise access levels. The optional scopes feature is available now for all third-party OAuth apps, with no changes required for existing integrations unless developers choose to adopt the new model.

Sources

From all-or-nothing to task-based OAuth consentCloudflare Blog

Companies mentioned

Cloudflare

Discussion · coming soon

Be the first to join the thread when community discussion launches.