UnveilTech

UnveilScan Blog

← All articles

Try UnveilScan free

We scanned the Cloudflare Top 1000 — here's what we found

Posted 2026-04-29 · 6 min read · datastats

In April 2026 we ran an automated Basic scan against the Cloudflare Radar Top 1000 domains — the most popular sites on the internet by direct DNS query volume. 999 returned a complete result (one timed out and was excluded). Below is what the data says, not what we wished it said.

Score distribution

The mean score across the 999 successful scans is 68.7 / 100 — a low C. Median is similar. Spread:

GradeScore rangeCount%
A+95–100242.4%
A85–9439239.2%
B75–841193—*
C65–741811—*
D50–641376—*
F< 50417—*

*Numbers above 1000 because we re-scanned the same domains across runs. Distribution roughly: A 39%, B 22%, C 18%, D 14%, F 7%.

Reading: only 41.6% of the world's most popular domains earn an A or better when graded against PCI-DSS 4.0 / ANSSI / RFC 8996 (the strict bar we use, see our methodology article). About 7% are strictly broken — failing on multiple critical findings.

The top 5 are not who you'd expect

RankDomainScore
1icloud.com.cn90 (A)
2stripe.network87 (A)
3fontawesome.com86 (A)
4ui.com (Ubiquiti)84 (B)
5cloudflare.com83 (B)

Apple's Chinese iCloud mirror beating Stripe is the kind of result that makes you triple-check the methodology. We did. The reason: icloud.com.cn serves a minimal landing page (no JS, no ads, no analytics, no third-party widgets) so the WEB category gets only one or two LOW findings. stripe.network is also a minimal landing but ships a few non-trivial scripts. Fontawesome is a CDN — flat surface, easy to score high on.

cloudflare.com at 83 is interesting: their own dogfooding scores B, not A+. The drag is the same TLS 1.0/1.1 enablement we documented in the Google article. Cloudflare publicly markets WAF + DDoS protection but their own apex still negotiates TLS 1.0. Compatibility over compliance, again.

The bottom 5: Big Tech is not safe

RankDomainScore
996fbsbx.com (Facebook CDN)23 (F)
997baidu.com20 (F)
998instagram.com20 (F)
999no-ip.com18 (F)

A surprising chunk of the bottom-50 belongs to Meta and Chinese Big Tech. Reasons differ:

Most common CRITICAL findings (across all 5 200+ Basic scans we've run)

  1. 1 500dns.ip_on_reputation_list: domain's IP appears on AbuseIPDB / Spamhaus / Barracuda. (See our reputation feed analysis.)
  2. 1 058tls.legacy_protocol_enabled: TLS 1.0 or 1.1 still negotiable.
  3. 127web.shodan_cve_exposure: Shodan reports a known CVE on the IP.
  4. 19tls.weak_cipher_suite: 3DES, RC4, or other cipher in the "weak" PCI list.
  5. 6web.leak.wp_config_bak: a wp-config.php.bak served at root. WordPress credentials in cleartext.

Detail in our dedicated post.

What it tells us

Methodology note. All scans Basic profile only (17 checkers, 100% passive, same surface a normal browser sees). No login, no probes, no ownership assumed. The Top 1000 source is Cloudflare Radar export cloudflare-radar_top-1000-domains_20260413-20260420.csv. Full per-domain results in our public dataset as `top1000-ranked.csv`.

What does YOUR domain score?

Free Basic scan, no signup needed for unverified domains. Median time-to-result is around 60 seconds. If you get a C or worse, our remediation walkthrough shows how to climb to A in about two hours of work.

Score your domain in 60 seconds

Free Basic scan, 17 checkers, no signup needed.

Scan a domain