Loading…
Loading…
Each day we measure fixed panels of public hosts for hybrid key exchange (X25519MLKEM768) and certificate posture, then publish the trend. Read-only handshakes, a restrained probing policy, and an open methodology.
Web panel · hybrid KEX adoption · 2026-08-20
64.3%
45 of 70 reachable hosts negotiated X25519MLKEM768
Updated 2026-08-20
45
Migrated
24
Classical
1
Regressed
0
Unreachable
Adoption over time
Adoption by category
Regression detected
1 host regressed: they spoke post-quantum and stopped. Use the “Regressed” filter below.
70 of 70 hosts
| Host | Status | Group | TLS | Cert | Why |
|---|---|---|---|---|---|
| cloudflare.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| akamai.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| fastly.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| cloudflare-dns.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| amazonaws.comCloud / SaaS | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| cloud.google.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| azure.microsoft.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | sha384WithRSAEncryption | |
| digitalocean.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| heroku.comCloud / SaaS | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| vercel.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| netlify.comCloud / SaaS | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| wordpress.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| shopify.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| salesforce.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| oracle.comCloud / SaaS | Classical | - | TLSv1.2 | sha256WithRSAEncryption | |
| ibm.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| adobe.comCloud / SaaS | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| dropbox.comCloud / SaaS | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| slack.comCloud / SaaS | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| zoom.usCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| letsencrypt.orgSecurity / PKI | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| digicert.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| sectigo.comSecurity / PKI | Classical | - | TLSv1.2 | sha256WithRSAEncryption | |
| globalsign.comSecurity / PKI | Regressed | - | TLSv1.2 | sha256WithRSAEncryption | |
| okta.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| auth0.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| crowdstrike.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| paloaltonetworks.comSecurity / PKI | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| fortinet.comSecurity / PKI | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| signal.orgMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| proton.meMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| telegram.orgMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| discord.comMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| stripe.comPayments | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| paypal.comPayments | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| github.comDeveloper platform | Classical | - | TLSv1.3 | ecdsa-with-SHA256 | |
| gitlab.comDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| stackoverflow.comDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| npmjs.comDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| nodejs.orgDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| python.orgDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| kernel.orgDeveloper platform | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| debian.orgDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| ubuntu.comDeveloper platform | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| mozilla.orgDeveloper platform | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| censys.ioMeasurement / research | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| shodan.ioMeasurement / research | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| ssllabs.comMeasurement / research | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| google.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| youtube.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| facebook.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| instagram.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| x.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| linkedin.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| wikipedia.orgConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| reddit.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| amazon.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| apple.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | |
| microsoft.comConsumer web | Classical | - | TLSv1.3 | sha384WithRSAEncryption | |
| netflix.comConsumer web | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | |
| ebay.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| yahoo.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| bing.comConsumer web | Classical | - | TLSv1.3 | sha384WithRSAEncryption | |
| duckduckgo.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| spotify.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | |
| twitch.tvConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| cnn.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | |
| bbc.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| nytimes.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | |
| theguardian.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption |
Once a day we perform a single read-only TLS handshake to each host in a fixed public panel and record whether the server selects the hybrid group X25519MLKEM768, the negotiated TLS version, and the leaf certificate’s signature algorithm and expiry. We never send more than one connection per host per run, we honor connection refusals, and we do not attempt any exploitation. This is the same class of measurement public scanners such as SSL Labs and Censys perform.
The panel and the probing policy live in the open-source pqc-observatory repository, where anyone can propose a host. To have a host removed from the panel, open a pull request or contact [email protected] and we will drop it within one measurement cycle.