Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026 Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026
Cloud & Infrastructure Networking & CDN Cloudflare

Cloudflare automates post-quantum TLS for 45bn daily origin links

New system eliminates retry round trips and enables PQ encryption without manual setup.

Cloudflare automates post-quantum TLS for 45bn daily origin links
Brett Sayles · Pexels

Cloudflare has rolled out Automatic Key Exchange, a feature that replaces static guesswork in TLS 1.3 handshakes with active measurement of each origin server’s capabilities. The system now negotiates the optimal key agreement algorithm on the first attempt, reducing failed handshakes and enabling post-quantum encryption without requiring manual intervention from site operators.

How the system works

TLS 1.3 requires the client to commit to a key agreement algorithm in the initial ClientHello message before receiving any response from the server. Cloudflare previously defaulted to X25519 for all origin connections, a widely supported but quantum-vulnerable algorithm. If the origin preferred a different algorithm—such as P-256, P-384, or the post-quantum hybrid X25519MLKEM768—the server would respond with a HelloRetryRequest (HRR), forcing a second round trip and adding latency.

Automatic Key Exchange eliminates this guesswork by scanning origin servers out-of-band. The system conducts lightweight TLS handshakes, each offering a single key agreement group (X25519, P-256, P-384, P-521, or X25519MLKEM768), to determine the full set of algorithms the origin supports. Results are weighted by actual traffic volume, ensuring high-traffic subdomains influence the domain-wide preference more than dormant ones. The system then selects the strongest supported algorithm, prioritizing post-quantum hybrids where available, and falls back to the fastest classical option otherwise.

Key facts
  • HRR rate dropped from 52% to 3.7% after rollout.
  • 99.2% of post-quantum TLS 1.3 connections now complete in one round trip.
  • 12.8% of origins support post-quantum key exchange (up from 0.5% in 2023).
  • Daily upgrades: ~9,000 domains shift to non-X25519 key agreement.
  • Latency reduction: >150 ms at p90 for scanned origins.

Impact on security and performance

The rollout has two primary effects: faster connections and broader adoption of post-quantum encryption. By avoiding HRRs, the system reduces handshake latency by over 150 ms at the 90th percentile, a benefit that compounds for dynamic requests and CDN cache misses requiring new TLS connections. For post-quantum security, the change is more significant. Before Automatic Key Exchange, nearly all post-quantum origin handshakes required an HRR because Cloudflare’s static default was classical X25519. Now, 99.2% of post-quantum TLS 1.3 connections complete in a single round trip.

The system also accelerates post-quantum adoption by uncovering origins whose support was previously invisible. Many servers accept multiple key agreement algorithms without actively preferring one, meaning passive observation could not detect their full capabilities. Active probing revealed thousands of origins that support X25519MLKEM768 but had never negotiated it in production traffic. Once the scanner updated their preferences, post-quantum connections quickly became the majority for those domains.

Configuration and limitations

Automatic Key Exchange is enabled by default for all domains using Cloudflare’s proxy, requiring no manual action for most setups. Operators can manage settings in the Cloudflare dashboard under SSL/TLS > Overview > Configure > Origin connection & post-quantum encryption. Two compliance-focused options are available:

  • Post-quantum hybrid: Restricts negotiation to X25519MLKEM768, removing classical algorithms entirely.
  • FIPS: Limits key agreements to FIPS-compliant algorithms.

Selecting both options requires an algorithm that satisfies both criteria; if none exists, the configuration is rejected. These settings are intended for strict policy environments, as enforcing post-quantum hybrid on an origin without X25519MLKEM768 support will cause TLS 1.3 connections to fail. Cloudflare recommends leaving both options unselected unless required by compliance obligations.

For professionals

For professionals: Origins that do not yet support post-quantum key exchange still benefit from reduced latency, as the system learns their preferred classical algorithm. For those upgrading, Cloudflare Tunnel provides an immediate post-quantum connection without modifying the origin’s TLS stack. Operators should audit all TLS-terminating devices—load balancers, WAFs, and middleboxes—to ensure X25519MLKEM768 is enabled.

What’s next

Cloudflare plans to extend the system’s granularity to the subdomain or origin level, allowing key agreement preferences to vary across multiple backends serving a single domain. An on-demand scan feature is also in development, enabling operators to trigger rescans after upgrading their TLS stack rather than waiting for the next scheduled scan. Longer-term, the company aims to automate post-quantum origin authentication, detecting support for ML-DSA certificates and disabling classical fallback for customers requiring strict post-quantum protection.

Companies mentioned

Cloudflare

Discussion · coming soon

Be the first to join the thread when community discussion launches.