Security headers · South Africa (domains)

What share of domains in South Africa have no HSTS or Content-Security-Policy header?

88.56%

88.56% of domains in South Africa (95% CI 84.22–91.82%), measured across 271 domains on 2026-08-13.

strong: 11.44%partial: 12.92%missing: 75.65%
strong · 11.44%partial · 12.92%missing · 75.65%
Trend

Measured every Thursday since 2026-08-01 — 6 observations to date. Last measured 2026-08-13.

How this is measured

Tier 3a; check Strict-Transport-Security, Content-Security-Policy, X-Frame-Options on the homepage response. Denominator: has_web.

Passive measurement: a single DNS lookup, TLS handshake, or homepage GET per domain. Aggregate-only; no individual company is named. 95% Wilson confidence intervals. Population: domains sampled from the Common Crawl web graph, filtered to those that do email. Parked domains excluded. Snapshot: common-crawl-domain-stratified-c400-g2500-seed20260729.

Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.

Why it matters

HSTS is what stops the first, downgradeable request; CSP is what limits the damage of injected script. Both are one-line changes, and both are commonly switched off silently by a framework upgrade or a proxy change.

The same check, other segments

Show the remaining 65 segments

Share or cite this figure

Reuse is free under CC BY 4.0 — attribution to Quiet Failures is all we ask.

Post on X

Embed this stat

Free to reuse under CC BY 4.0 — the card links back and updates as the data does.

<iframe src="https://quietfailures.com/embed/security-headers/za" width="380" height="210" style="border:0;max-width:100%" loading="lazy" title="What share of domains in South Africa have no HSTS or Content-Security-Policy header?"></iframe>