Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Cloud & Infrastructure Networking & CDN

RPKI adoption critical for quantum-safe internet routing

Routing security must precede post-quantum cryptography to prevent systemic risks

RPKI adoption critical for quantum-safe internet routing
Brett Sayles · Pexels

The internet’s foundational routing system remains exposed to daily hijacks and misconfigurations, creating a structural weakness that could undermine even quantum-resistant encryption, according to a recent technical assessment. While industry attention focuses on post-quantum cryptography (PQC) to counter future quantum computing threats, the Border Gateway Protocol (BGP) continues to operate without built-in authentication, leaving global traffic vulnerable to redirection and interception. This gap has prompted calls for immediate action on routing security as a prerequisite for any quantum-safe transition.

The routing security gap

BGP, the protocol that connects autonomous systems (ASes) across the internet, was designed in an era of mutual trust and lacks native mechanisms to verify route announcements. Any entity controlling an AS number can falsely claim ownership of IP address blocks, leading to traffic hijacking, service disruptions, or large-scale surveillance. The Resource Public Key Infrastructure (RPKI) was developed to address this flaw by allowing IP resource holders to cryptographically certify which ASes are authorized to announce specific address spaces. However, adoption remains uneven, with many operators treating RPKI as optional rather than essential infrastructure.

Background

Background: RPKI uses digital certificates and Route Origin Authorizations (ROAs) to validate BGP route announcements. Regional Internet Registries (RIRs) issue these certificates, but deployment depends on network operators implementing route validation. Without widespread adoption, the system’s effectiveness is limited.

Despite years of advocacy by RIRs and early adopters, global coverage of Validated ROA Payloads (VRPs) remains incomplete. Some operators resist deployment due to perceived complexity or a belief that existing systems are sufficient. This inertia leaves the internet’s routing layer exposed to both accidental misconfigurations and deliberate attacks, which could escalate as quantum computing advances.

Quantum threats to the trust chain

The impending arrival of large-scale quantum computers poses an existential risk to current cryptographic systems, including RSA and Elliptic Curve Cryptography (ECC). These algorithms underpin not only transport-layer security (e.g., TLS) but also the RPKI trust architecture itself. If quantum attackers compromise RIR certificates, they could forge Route Origin Authorizations (ROAs), enabling "lawful" BGP hijacks with catastrophic consequences. Such attacks could disrupt communications for entire nations or industries, bypassing even the strongest application-layer encryption.

The interplay between routing security and quantum readiness creates a dual challenge. Post-quantum cryptography alone cannot protect data if the underlying path is compromised. Conversely, RPKI’s reliance on traditional public-key cryptography means its trust chain is vulnerable to quantum attacks unless modernized. This interdependence demands a coordinated approach to both routing security and cryptographic agility.

Engineering and policy hurdles

Integrating post-quantum cryptography into RPKI presents technical trade-offs. Candidate PQC algorithms often require larger public keys and signatures, straining the limited memory and processing power of BGP routers. Hybrid modes—supporting both traditional and post-quantum signatures—are seen as a transitional solution, but their implementation requires standardization and hardware upgrades. The Internet Engineering Task Force (IETF) and equipment manufacturers must address these challenges to ensure smooth coexistence during the transition.

For professionals

For professionals: Network operators should prioritize RPKI deployment now to mitigate current routing risks while preparing for quantum threats. Enterprises reliant on secure communications should audit their providers’ RPKI adoption and advocate for hybrid cryptographic support in routing infrastructure.

Policy frameworks have historically overlooked routing security, focusing instead on endpoint protection and data encryption. Governments and international bodies are now urged to integrate RPKI and PQC roadmaps into national digital resilience strategies. Mandates, procurement policies, and regulatory incentives could accelerate adoption among internet service providers (ISPs) and enterprises, while R&D investments are needed to address technical bottlenecks.

A strategic imperative

The convergence of routing security and quantum defense represents a critical juncture for internet infrastructure. Delaying RPKI deployment until quantum threats materialize risks leaving the internet’s core vulnerable to both immediate and long-term attacks. Operators and policymakers must treat routing security as a foundational requirement, not an optional enhancement, to ensure the internet’s trustworthiness in an era of evolving threats.

Discussion · coming soon

Be the first to join the thread when community discussion launches.