Defaults.Exposed

Defaults.ExposedReports

TLS 1.3 by Country: Which TLDs Win on Defaults (2026)

Published

Figures as of 16 August 2026 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.

The headline: encryption quality now maps to when a country’s hosting was built, not how rich it is

Of the 231,455,163 domains that completed a TLS handshake, 94.9% negotiated TLS 1.3 with our scanner — and the league table turns the usual geography of technology upside down. Vanuatu’s .vu tops our measured TLDs at 99.6%. Nigeria’s .ng (98.7%), Kenya’s .ke (98.5%) and Bangladesh’s .bd (98.4%) all beat .com (95.0%) and Germany’s .de (94.8%). At the bottom sit South Korea’s .kr at 73.3% and — awkwardly — the US government’s own .gov at 77.0%.

The pattern is not wealth. It is infrastructure age. Where a country’s hosting stack was built recently, TLS 1.3 came in the box. Where a domain has been sitting on the same server since 2015, someone has to touch it — and mostly, nobody has.

Key numbers

What we measured, in one paragraph

For every domain in the August 2026 census that completed a TLS handshake — 231,455,163 of them — we recorded the protocol version the server actually negotiated with a modern client. That is the whole metric. It is deliberately simple: negotiated version is what a real visitor with a current browser gets, and it is the one TLS number a non-specialist can act on. Our published TLS 1.3 adoption report covers the global trend line, and weak and outdated TLS covers cipher-level failures; this edition is the geographic cut — the same handshake data, sliced by TLD.

One honest limitation up front, because the rest of the article leans on it: negotiated version is not offered version. A server that still accepts TLS 1.0 from an ancient client, but negotiates 1.3 with ours, shows up here as a 1.3 domain. The legacy long tail is real; it is just invisible at this vantage. More in “How we measured this” below.

Which countries lead TLS 1.3 adoption?

Here is the part that surprises people. Sort the world’s TLDs by TLS 1.3 share and the top of the table is not Silicon Valley’s neighbourhood.

TLDRegion / marketHTTPS domainsTLS 1.3 share
.vuVanuatu30,42599.6%
.ngNigeria111,45098.7%
.aiAnguilla (tech branding)730,79298.6%
.keKenya85,13298.5%
.devGoogle gTLD392,77698.5%
.tzTanzania28,86798.5%
.bdBangladesh33,56998.4%
.ioBr. Indian Ocean Terr. (tech branding)735,31698.0%
.usUnited States826,55197.8%
.plPoland1,590,09397.5%
.seSweden998,10997.3%
.auAustralia2,071,68197.2%
.ukUnited Kingdom4,908,49796.6%
.irIran422,39696.5%
.comglobal gTLD106,465,44495.0%
.deGermany6,982,82494.8%

Nigeria beats Germany. Tanzania beats .com. Iran, under sanctions, beats the global baseline. This is not because Lagos webmasters care more about handshakes than Frankfurt ones. It is a cohort effect: domains in fast-growing internet economies overwhelmingly live on hosting platforms and CDNs built after 2018, when TLS 1.3 was already the shipping default. A .ng site never had a legacy config to migrate away from. A .de site registered in 2009 very possibly did, and a config nobody touches is a config that never improves.

The two tech-branded ccTLDs make the same point from the other direction. .ai and .dev score 98%+ not because their owners tuned anything but because startups deploy on modern platforms by default. The best security decision most of these domains ever made was being born late.

Which TLDs are still stuck on TLS 1.2?

The bottom of the table is where it gets interesting, because the laggards are not poor and not obscure.

TLDRegion / marketHTTPS domainsTLS 1.3 shareStill on 1.2
.krSouth Korea362,51373.3%96,655
.buzzbudget gTLD136,97973.8%35,931
.govUS government11,28577.0%2,600
.ruRussia2,789,02279.8%563,678
.рф (xn—p1ai)Russia (Cyrillic)339,28282.8%58,386
.jpJapan918,07684.9%138,364
.vnVietnam278,54785.3%40,862
.czCzechia744,91086.6%99,498
.twTaiwan181,33586.8%23,980
.huHungary523,38889.8%53,537

South Korea is the finding that deserves a double-take. This is one of the most connected countries on earth, with world-class consumer broadband, and its national TLD has the weakest negotiated-TLS profile of any major ccTLD we measured: 96,655 Korean HTTPS domains cap out at a protocol from 2008. Japan (84.9%) and Taiwan (86.8%) show a milder version of the same shape. East Asia’s early-adopter economies built vast domestic hosting estates in the 2000s and 2010s — and that installed base now ages in place. The head start became the anchor.

.gov is the other eyebrow-raiser. The TLD that exists purely for the US government negotiates TLS 1.3 on 77.0% of its HTTPS domains — a lower rate than .com, .us, .uk, and for that matter .ng and .ke. As industry context rather than census data: US federal policy has required TLS 1.2 as a floor for years and encourages 1.3, and 1.2 remains a compliant, secure choice when configured well. But the gap between the government TLD and the commercial web it regulates is a measurement, not an opinion. Nearly one in four .gov HTTPS domains hasn’t picked up a protocol that has been final since 2018.

Russia’s numbers (79.8% on .ru, with 563,678 domains on 1.2 — the largest single national block of legacy negotiation we measured among ccTLDs) read like the sanctions era in protocol form: a hosting market cut off from the global CDN ecosystem upgrades on its own clock.

What happened to the TLS 1.0 and 1.1 holdouts?

We went looking for them. At this vantage, they do not exist.

Across all 231,455,163 TLS-completing domains, the number that negotiated TLS 1.0 with our modern client is zero. TLS 1.1: also zero. Not “rounds to zero” — zero recorded negotiations, in every TLD, in the whole census round.

Read that carefully, because it is two findings wearing one number. The first is genuinely good news: a visitor with a current browser essentially cannot end up on a 1990s-era TLS session anywhere on the measured web. The ecosystem work that deprecated 1.0/1.1 — labelled as industry context: both were formally deprecated by RFC 8996 in March 2021, and the major browsers dropped them in 2020 — actually landed. When client and server both speak anything modern, the modern version wins, every time.

The second finding is about what this measurement cannot see, and it is the caveat this article is obliged to carry. Version negotiation picks the best protocol both sides support. Our client supports current protocols, so any server that also does will never reveal whether it would still accept a 1.0 handshake from an old client. Servers offering legacy TLS are therefore not enumerable from negotiated-version data — a scan that deliberately offered only 1.0 would find a nonzero holdout population, and that is a different (and noisier) experiment than this one. What we can say precisely: the legacy holdouts, whatever their number, are unreachable by any current mainstream browser and invisible at negotiation. The live battleground in 2026 is not 1.0 versus 1.3. It is 1.2 versus 1.3 — and that is a battle about defaults, not danger.

Which matters for how you read the tables above. A domain on TLS 1.2 is not broken; 1.2 with strong ciphers remains acceptable in every mainstream guideline (industry context again). What the 1.2 share measures is staleness — the fraction of a TLD’s infrastructure that nobody has touched since before 2018. That is why it tracks so cleanly with infrastructure age, and why we treat it as a leading indicator: estates that don’t pick up free protocol upgrades tend not to pick up anything else either.

Why do defaults decide this?

Because almost nobody chooses a TLS version. It arrives with the stack.

Enable TLS 1.3 by hand and you edit one line in a server config. Almost no one does this at web scale. What actually moves the number is platform churn: a host upgrades its load balancers, a site moves behind a CDN, a distro ships a new OpenSSL, and a million domains silently improve overnight. The owner never knows. The reverse also holds: a self-managed box that has been quietly serving the same site since 2016 keeps its 2016 handshake until the hardware dies.

That is why this map is worth publishing at all. Per-TLD TLS 1.3 share is a proxy for how much of a country’s web runs on infrastructure someone still maintains. Vanuatu at 99.6% means essentially all of .vu’s small web estate lives on modern managed platforms. Korea at 73.3% means a quarter of a large, sophisticated web estate is running on configurations old enough that a free upgrade from 2018 has still not reached them. Neither number is about effort. Both are about defaults — which is the recurring finding of this whole census: most of what separates an A-grade domain from an F-grade one is not spending, it is whether anyone ever looked.

How we measured this

What this means for IT and security teams

If your organisation operates domains across multiple country-code TLDs — through subsidiaries, regional presences, or acquired properties — TLS version is not a safe assumption. This data shows that an organisation’s European subsidiary on .de could have a meaningfully different TLS profile than its .ng or .au properties, purely because of when those domains were last touched. A security posture review that checks the headquarter domain but ignores regional ccTLD properties is leaving a blind spot that census data makes visible at scale.

For government and regulated-sector organisations, the .gov finding is particularly pointed: 77.0% TLS 1.3 on a TLD that exists exclusively for US federal use, sitting below commercial TLDs including .com, .uk, and several African ccTLDs. If your agency’s HTTPS properties haven’t been reviewed since before 2018, there is a meaningful chance you are on the wrong side of that 23%. The fix is not a procurement: it is a server configuration review and, in most cases, a single line change or a CDN that does it automatically.

For anyone running self-managed infrastructure — bare metal, VMs, on-premise hosting — the lesson from this map is that time is the enemy. A domain on the right protocol in 2018 is still on the right protocol today only if someone maintained the stack underneath it. South Korea’s 96,655 domains stuck on TLS 1.2 are not there because Korean engineers are less capable; they are there because infrastructure ages silently and the only way to know where you stand is to check.

Data to cite

FAQ

Is TLS 1.2 still safe in 2026? Yes, when configured with modern ciphers — that statement is industry consensus, not census data. What our data adds: 11,861,583 domains (5.1% of the TLS-completing web) negotiate at most 1.2 as of 16 August 2026, and that share is better read as an infrastructure-age signal than a vulnerability count. The cipher-level failures that actually break security are a different, smaller cohort, covered in weak and outdated TLS.

Which country has the best TLS 1.3 adoption? Among TLDs with a meaningful population, Vanuatu’s .vu leads our measurement at 99.6% of 30,425 HTTPS domains, with Nigeria’s .ng (98.7%) and Kenya’s .ke (98.5%) close behind — all ahead of .com at 95.0%. The common thread is recently built hosting estates where TLS 1.3 was the default from day one.

Why is South Korea’s TLS adoption so low? Our census measures the what, not the why: 73.3% of .kr’s 362,513 HTTPS domains negotiate TLS 1.3, the lowest major-ccTLD figure we recorded, with 96,655 domains on 1.2. The pattern across .kr, .jp (84.9%) and .tw (86.8%) is consistent with large, early-built domestic hosting estates aging in place — an interpretation, and labelled as one.

Does anyone still use TLS 1.0 or 1.1? No modern visitor does. Across all 231.5 million TLS-completing domains in the August 2026 round, zero negotiated 1.0 or 1.1 with our current-protocol client. Servers quietly still offering those versions to ancient clients can exist but are invisible to negotiated-version measurement — that is the method’s stated blind spot.

How do I check and fix my own domain’s TLS version? Negotiating TLS 1.3 is a server-software property, not a purchase: current versions of every mainstream web server and every major CDN enable it by default, so the fix is usually “update, or front the site with a modern proxy” at zero licence cost. You can see what your domain negotiates, along with 33 other externally observable checks, in our free scan.

What should I do if my domain is still on TLS 1.2? First, check whether you are on managed hosting or self-managed infrastructure. On managed hosting (a CDN, cloud platform, or shared host), a support ticket or a settings change is usually all that is needed. On self-managed servers, update your web server software and OpenSSL to current releases — TLS 1.3 is enabled by default in every major server package from 2019 onwards. The upgrade itself costs nothing; the barrier is knowing which of your domains are affected, which is exactly what a census-based scan tells you.

How does TLS 1.3 adoption compare to the July 2026 census? This is the August 2026 round, and the July 2026 census is the prior measurement. The August round scanned 432 million domains and graded 376.9 million, with 231,455,163 completing a TLS handshake. Direct comparison to July figures would require the prior round’s TLD-level breakdown; what we can say is that the global 94.9% TLS 1.3 share reflects steady platform-driven improvement — the kind that happens without individual operators acting.

Why does this TLS map matter for procurement and vendor selection? If your organisation is evaluating hosting providers or cloud regions, per-TLD TLS adoption is a proxy for how aggressively a platform pushes its customers to current defaults. A platform serving a TLD with 99%+ TLS 1.3 adoption has made the upgrade invisible; one serving a TLD at 73% has left it as homework. That difference shows up in every protocol and security control, not just TLS version.

Where your own domain stands

Check your domain free at defaults.exposed — see exactly how your domain scores on TLS version negotiation along with 33 other security checks. Takes 30 seconds. No account needed. Read the flagship State of Domain Security 2026 report.

Also in this series: TLS 1.3 adoption report · Weak and outdated TLS · The most and least secure TLDs


How to cite this report

Press / blog: defaults.exposed (2026). TLS 1.3 by Country: Which TLDs Win on Defaults (2026). defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/tls-13-by-country-tld-map

Academic: defaults.exposed. (2026, August 18). TLS 1.3 by Country: Which TLDs Win on Defaults (2026). In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/tls-13-by-country-tld-map

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=231,455,163 TLS-completing domains)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026

Aggregate data only. Data stored and processed in the EU.

Aggregate data only. Data stored and processed in the EU.