Modern servers prefer ECDHE for forward secrecy, but many still accept RSA key exchange when an attacker manipulates the handshake. These domains are downgrade-attackable: a MITM forces RSA, harvested traffic from that session is decryptable with one stolen cert key. This finding is independent of quantum risk — it's a present-day exposure too.
| # | Domain | Score | Grade | Sector | Freshness |
|---|---|---|---|---|---|
| 1 | energy.gov | 6.2 | D | — | verified 13h ago |
| 2 | subaru.com | 5.9 | C | Global Automakers | stale (3d old) |
| 3 | cedars-sinai.org | 5.9 | C | — | verified 13h ago |
| 4 | stripe.com | 5.9 | C | — | verified 2h ago |
| 5 | gm.com | 5.9 | C | — | stale (2d old) |
| 6 | epirus.com | 5.8 | C | — | stale (2d old) |
| 7 | github.com | 5.8 | C | — | verified 42m ago |
| 8 | propublica.org | 5.4 | C | Global News & Media | stale (3d old) |
| 9 | volkswagen.com | 5.4 | C | — | stale (2d old) |
| 10 | politico.com | 5.4 | C | Global News & Media | stale (2d old) |
| 11 | netlify.com | 5.4 | C | — | verified 2h ago |
| 12 | uclahealth.org | 5.4 | C | — | verified 13h ago |
| 13 | monday.com | 5.3 | C | — | verified 2h ago |
| 14 | gitlab.com | 5.2 | C | — | verified 13h ago |
| 15 | honda.com | 5.2 | C | Global Automakers | stale (2d old) |
| 16 | met.police.uk | 5.2 | C | — | verified 13h ago |
| 17 | amazon.com | 5.2 | C | — | verified 2h ago |
| 18 | hyundai.com | 5.1 | C | Global Automakers | stale (3d old) |
| 19 | ford.com | 5.0 | C | — | stale (2d old) |
| 20 | santander.com | 5.0 | C | — | verified 13h ago |
| 21 | reuters.com | 5.0 | C | Global News & Media | stale (3d old) |
| 22 | bloomberg.com | 5.0 | C | Global News & Media | stale (2d old) |
| 23 | usbank.com | 5.0 | C | — | verified 13h ago |
| 24 | saic.com | 5.0 | C | — | verified 13h ago |
| 25 | stellantis.com | 5.0 | C | Global Automakers | stale (2d old) |
Run the same scan we use for this ranking. See your specific findings, get the migration steps, and track the domain so you know when your score improves.