{
  "meta": {
    "startedAt": "2026-08-20T18:49:08.582Z",
    "finishedAt": "2026-08-20T18:53:02.650Z",
    "day": "2026-08-20",
    "source": {
      "name": "tranco",
      "label": "Tranco daily list JZ8PY (2026-08-19) — a 30-day rank aggregation over Chrome UX Report, Farsight, Majestic, Cloudflare Radar and Cisco Umbrella",
      "url": "https://tranco-list.eu/list/JZ8PY",
      "listId": "JZ8PY",
      "listDate": "2026-08-19",
      "sha256": "753e75309d7f6a98e6d6203955923a1e24cc6c000badf970ddb1840929e07b26"
    },
    "requested": 500,
    "attempted": 500,
    "concurrency": 8,
    "handshakeTimeoutMs": 8000,
    "watchdogMs": 25000,
    "waveDelayMs": 400,
    "durationSeconds": 234
  },
  "totals": {
    "attempted": 500,
    "ok": 349,
    "failed": 151,
    "okShare": 69.8
  },
  "errors": [
    {
      "key": "dns-error",
      "label": "No public DNS answer",
      "count": 122,
      "share": 80.8
    },
    {
      "key": "timeout",
      "label": "No handshake before the timeout",
      "count": 23,
      "share": 15.2
    },
    {
      "key": "private-address",
      "label": "Resolves to reserved address space",
      "count": 3,
      "share": 2
    },
    {
      "key": "tls-error",
      "label": "Handshake or certificate error",
      "count": 2,
      "share": 1.3
    },
    {
      "key": "unreachable",
      "label": "Port 443 refused or reset",
      "count": 1,
      "share": 0.7
    }
  ],
  "keyFamilies": [
    {
      "key": "rsa",
      "label": "RSA",
      "count": 215,
      "share": 61.6
    },
    {
      "key": "ecdsa",
      "label": "ECDSA",
      "count": 134,
      "share": 38.4
    }
  ],
  "keyTypes": [
    {
      "key": "RSA-2048",
      "label": "RSA-2048",
      "count": 210,
      "share": 60.2
    },
    {
      "key": "ECDSA P-256",
      "label": "ECDSA P-256",
      "count": 132,
      "share": 37.8
    },
    {
      "key": "RSA-4096",
      "label": "RSA-4096",
      "count": 5,
      "share": 1.4
    },
    {
      "key": "ECDSA P-384",
      "label": "ECDSA P-384",
      "count": 2,
      "share": 0.6
    }
  ],
  "protocols": [
    {
      "key": "TLSv1.3",
      "label": "TLS 1.3",
      "count": 296,
      "share": 84.8
    },
    {
      "key": "TLSv1.2",
      "label": "TLS 1.2",
      "count": 53,
      "share": 15.2
    }
  ],
  "legacyTls": [
    {
      "key": "refused",
      "label": "Refused TLS 1.0 and 1.1",
      "count": 251,
      "share": 71.9
    },
    {
      "key": "accepted:TLSv1.1,TLSv1",
      "label": "Accepted TLS 1.0 and TLS 1.1",
      "count": 91,
      "share": 26.1
    },
    {
      "key": "accepted:TLSv1.1",
      "label": "Accepted TLS 1.1",
      "count": 7,
      "share": 2
    }
  ],
  "lifetimeHistogram": [
    {
      "key": "<=47",
      "label": "≤ 47 days",
      "count": 4,
      "share": 1.1
    },
    {
      "key": "48-100",
      "label": "48–100 days",
      "count": 161,
      "share": 46.1
    },
    {
      "key": "101-200",
      "label": "101–200 days",
      "count": 105,
      "share": 30.1
    },
    {
      "key": "201-398",
      "label": "201–398 days",
      "count": 79,
      "share": 22.6
    },
    {
      "key": ">398",
      "label": "> 398 days",
      "count": 0,
      "share": 0
    }
  ],
  "lifetimeStats": {
    "min": 30,
    "median": 181,
    "mean": 187.9,
    "max": 397,
    "within47": 4,
    "within47Share": 1.1,
    "within100": 165,
    "within100Share": 47.3,
    "within200": 270,
    "within200Share": 77.4,
    "over200": 79,
    "over200Share": 22.6
  },
  "lifetimeModes": [
    {
      "key": "90",
      "label": "90 days",
      "count": 113,
      "share": 32.4
    },
    {
      "key": "199",
      "label": "199 days",
      "count": 58,
      "share": 16.6
    },
    {
      "key": "198",
      "label": "198 days",
      "count": 32,
      "share": 9.2
    },
    {
      "key": "397",
      "label": "397 days",
      "count": 30,
      "share": 8.6
    },
    {
      "key": "84",
      "label": "84 days",
      "count": 29,
      "share": 8.3
    },
    {
      "key": "395",
      "label": "395 days",
      "count": 12,
      "share": 3.4
    },
    {
      "key": "366",
      "label": "366 days",
      "count": 9,
      "share": 2.6
    },
    {
      "key": "91",
      "label": "91 days",
      "count": 8,
      "share": 2.3
    }
  ],
  "lifetimeByKeyFamily": [
    {
      "key": "ecdsa",
      "label": "ECDSA",
      "median": 90,
      "count": 134
    },
    {
      "key": "rsa",
      "label": "RSA",
      "median": 199,
      "count": 215
    }
  ],
  "grades": [
    {
      "key": "A+",
      "label": "A+",
      "count": 35,
      "share": 10
    },
    {
      "key": "A",
      "label": "A",
      "count": 174,
      "share": 49.9
    },
    {
      "key": "B",
      "label": "B",
      "count": 44,
      "share": 12.6
    },
    {
      "key": "C",
      "label": "C",
      "count": 79,
      "share": 22.6
    },
    {
      "key": "D",
      "label": "D",
      "count": 14,
      "share": 4
    },
    {
      "key": "F",
      "label": "F",
      "count": 3,
      "share": 0.9
    }
  ],
  "signatureAlgorithms": [
    {
      "key": "sha256WithRSAEncryption",
      "label": "sha256WithRSAEncryption",
      "count": 228,
      "share": 65.3
    },
    {
      "key": "ecdsa-with-SHA256",
      "label": "ecdsa-with-SHA256",
      "count": 58,
      "share": 16.6
    },
    {
      "key": "ecdsa-with-SHA384",
      "label": "ecdsa-with-SHA384",
      "count": 48,
      "share": 13.8
    },
    {
      "key": "sha384WithRSAEncryption",
      "label": "sha384WithRSAEncryption",
      "count": 15,
      "share": 4.3
    }
  ],
  "issuers": [
    {
      "key": "DigiCert Global G2 TLS RSA SHA256 2020 CA1",
      "label": "DigiCert Global G2 TLS RSA SHA256 2020 CA1",
      "count": 36,
      "share": 10.3
    },
    {
      "key": "WE1",
      "label": "WE1",
      "count": 35,
      "share": 10
    },
    {
      "key": "Amazon RSA 2048 M04",
      "label": "Amazon RSA 2048 M04",
      "count": 20,
      "share": 5.7
    },
    {
      "key": "YE2",
      "label": "YE2",
      "count": 18,
      "share": 5.2
    },
    {
      "key": "YR1",
      "label": "YR1",
      "count": 18,
      "share": 5.2
    },
    {
      "key": "Amazon RSA 2048 M01",
      "label": "Amazon RSA 2048 M01",
      "count": 17,
      "share": 4.9
    },
    {
      "key": "WE2",
      "label": "WE2",
      "count": 16,
      "share": 4.6
    },
    {
      "key": "YE1",
      "label": "YE1",
      "count": 15,
      "share": 4.3
    },
    {
      "key": "YR2",
      "label": "YR2",
      "count": 15,
      "share": 4.3
    },
    {
      "key": "WR2",
      "label": "WR2",
      "count": 12,
      "share": 3.4
    },
    {
      "key": "Sectigo Public Server Authentication CA OV R36",
      "label": "Sectigo Public Server Authentication CA OV R36",
      "count": 10,
      "share": 2.9
    },
    {
      "key": "DigiCert Global G3 TLS ECC SHA384 2020 CA1",
      "label": "DigiCert Global G3 TLS ECC SHA384 2020 CA1",
      "count": 8,
      "share": 2.3
    },
    {
      "key": "GlobalSign RSA OV SSL CA 2018",
      "label": "GlobalSign RSA OV SSL CA 2018",
      "count": 8,
      "share": 2.3
    },
    {
      "key": "Sectigo Public Server Authentication CA DV R36",
      "label": "Sectigo Public Server Authentication CA DV R36",
      "count": 8,
      "share": 2.3
    },
    {
      "key": "GlobalSign GCC R3 DV TLS CA 2020",
      "label": "GlobalSign GCC R3 DV TLS CA 2020",
      "count": 7,
      "share": 2
    }
  ],
  "caGroups": [
    {
      "key": "Google Trust Services",
      "label": "Google Trust Services",
      "count": 137,
      "share": 39.3,
      "ecdsa": 96,
      "rsa": 41
    },
    {
      "key": "DigiCert",
      "label": "DigiCert",
      "count": 68,
      "share": 19.5,
      "ecdsa": 20,
      "rsa": 48
    },
    {
      "key": "GlobalSign",
      "label": "GlobalSign",
      "count": 38,
      "share": 10.9,
      "ecdsa": 11,
      "rsa": 27
    },
    {
      "key": "Amazon",
      "label": "Amazon",
      "count": 37,
      "share": 10.6,
      "ecdsa": 0,
      "rsa": 37
    },
    {
      "key": "Other / smaller CAs",
      "label": "Other / smaller CAs",
      "count": 23,
      "share": 6.6,
      "ecdsa": 4,
      "rsa": 19
    },
    {
      "key": "Sectigo",
      "label": "Sectigo",
      "count": 22,
      "share": 6.3,
      "ecdsa": 1,
      "rsa": 21
    },
    {
      "key": "Microsoft",
      "label": "Microsoft",
      "count": 15,
      "share": 4.3,
      "ecdsa": 0,
      "rsa": 15
    },
    {
      "key": "Apple",
      "label": "Apple",
      "count": 3,
      "share": 0.9,
      "ecdsa": 2,
      "rsa": 1
    },
    {
      "key": "Certainly (Fastly)",
      "label": "Certainly (Fastly)",
      "count": 2,
      "share": 0.6,
      "ecdsa": 0,
      "rsa": 2
    },
    {
      "key": "Entrust",
      "label": "Entrust",
      "count": 2,
      "share": 0.6,
      "ecdsa": 0,
      "rsa": 2
    },
    {
      "key": "GoDaddy",
      "label": "GoDaddy",
      "count": 1,
      "share": 0.3,
      "ecdsa": 0,
      "rsa": 1
    },
    {
      "key": "Let's Encrypt",
      "label": "Let's Encrypt",
      "count": 1,
      "share": 0.3,
      "ecdsa": 0,
      "rsa": 1
    }
  ],
  "findings": [
    {
      "key": "pqc-migration-ahead",
      "label": "Classical algorithm — migration ahead",
      "title": "Classical algorithm — migration ahead",
      "severity": "info",
      "count": 349,
      "share": 100
    },
    {
      "key": "chain-complete",
      "label": "Chain complete as served",
      "title": "Chain complete as served",
      "severity": "ok",
      "count": 348,
      "share": 99.7
    },
    {
      "key": "cert-valid",
      "label": "Within validity period",
      "title": "Within validity period",
      "severity": "ok",
      "count": 326,
      "share": 93.4
    },
    {
      "key": "tls13",
      "label": "TLS 1.3 negotiated",
      "title": "TLS 1.3 negotiated",
      "severity": "ok",
      "count": 296,
      "share": 84.8
    },
    {
      "key": "legacy-tls-refused",
      "label": "Legacy TLS refused",
      "title": "Legacy TLS refused",
      "severity": "ok",
      "count": 251,
      "share": 71.9
    },
    {
      "key": "key-rsa-2048",
      "label": "RSA-2048 — fine, but not compact",
      "title": "RSA-2048 — fine, but not compact",
      "severity": "info",
      "count": 210,
      "share": 60.2
    },
    {
      "key": "cert-short-lifetime",
      "label": "Lifetime of 90 days or less",
      "title": "Lifetime of 90 days or less",
      "severity": "ok",
      "count": 149,
      "share": 42.7
    },
    {
      "key": "key-modern",
      "label": "Modern key (ECDSA / EdDSA)",
      "title": "Modern key (ECDSA / EdDSA)",
      "severity": "ok",
      "count": 134,
      "share": 38.4
    },
    {
      "key": "chain-weak-signature-hash",
      "label": "SHA-1 signature above the leaf",
      "title": "SHA-1 signature above the leaf",
      "severity": "warn",
      "count": 103,
      "share": 29.5
    },
    {
      "key": "tls10-accepted",
      "label": "TLS 1.0 accepted",
      "title": "TLS 1.0 accepted",
      "severity": "critical",
      "count": 91,
      "share": 26.1
    },
    {
      "key": "no-tls13",
      "label": "TLS 1.3 not offered",
      "title": "TLS 1.3 not offered",
      "severity": "warn",
      "count": 53,
      "share": 15.2
    },
    {
      "key": "cert-renewal-window",
      "label": "In the renewal window (< 30 days)",
      "title": "In the renewal window (< 30 days)",
      "severity": "info",
      "count": 13,
      "share": 3.7
    },
    {
      "key": "cert-expiring-soon",
      "label": "Expires within 14 days",
      "title": "Expires within 14 days",
      "severity": "warn",
      "count": 7,
      "share": 2
    },
    {
      "key": "tls11-accepted",
      "label": "TLS 1.1 accepted",
      "title": "TLS 1.1 accepted",
      "severity": "warn",
      "count": 7,
      "share": 2
    },
    {
      "key": "key-rsa-large",
      "label": "RSA above 2048 bits",
      "title": "RSA above 2048 bits",
      "severity": "ok",
      "count": 5,
      "share": 1.4
    },
    {
      "key": "cert-expired",
      "label": "Certificate expired",
      "title": "Certificate expired",
      "severity": "critical",
      "count": 3,
      "share": 0.9
    },
    {
      "key": "chain-incomplete",
      "label": "Chain incomplete as served",
      "title": "Chain incomplete as served",
      "severity": "warn",
      "count": 1,
      "share": 0.3
    }
  ],
  "flags": {
    "sha1AnywhereInChain": 103,
    "sha1AnywhereShare": 29.5,
    "sha1Leaf": 0,
    "sha1LeafShare": 0,
    "pqcKeyOrSignature": 0,
    "pqcShare": 0,
    "chainComplete": 348,
    "chainCompleteShare": 99.7,
    "tls13": 296,
    "tls13Share": 84.8,
    "legacyAccepted": 98,
    "legacyAcceptedShare": 28.1,
    "rsaBelow2048": 0,
    "expired": 3
  }
}
