Expect-CT

HTTP response header

The Expect-CT header allows sites to opt in to reporting and/or enforcement of Certificate Transparency requirements which prevents the use of misissued certificates for that site from going unnoticed

Header usage statistics

Expect-CT response header information and usage statistics.

Websites using header Expect-CT 825,856
Percentage of websites that use Expect-CT header 7.23%
Total discovered header values 2,235
Header uses directives Yes
Header values are unique or random No
Most popular in the country United States of America

Expect-CT Directives (3 total)

  • enforce
  • max-age
  • report-uri

Expect-CT Directives

Expect-CT directives value information and usage statistics

Directive Share Websites count Unique Values
max-age 64.18% 530,001 72
report-uri 63.45% 523,992 1,043
enforce 0.58% 4,781 43

Connected technologies

Technologies that utilize the header

CloudFlare, category Content Delivery Networks, total 848,328 websites

Distribution by websites popularity

Expect-CT detection in the top websites by popularity

Top 10k sites 2,458 websites
Top 100k sites 13,999 websites
Top 1m sites 111,479 websites

Websites utilizing Expect-CT

List of websites that use Expect-CT header

Domain Country Rank Contacts
github.com United States of America 23
cdnjs.cloudflare.com United States of America 33
creativecommons.org United States of America 34
medium.com United States of America 37
tinyurl.com United States of America 69
www.linkedin.com United States of America 30,270
See full domain list

Geographical Distribution

Header usage distribution by websites across the globe.






Common header values

List of top common Expect-CT header values

Header value Value prevalence
max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct" 97.80%
max-age=31536000, report-uri="http://csp.yahoo.com/beacon/csp?src=yahoocom-expect-ct-report-only" 0.32%
max-age=0 0.17%
max-age=86400 0.15%
max-age=0, report-uri="/report-expect-ct-violation" 0.15%
max-age=300, report-uri="https://report.enjin.com/expect-ct" 0.11%
report-uri="https://web-security-reports.services.atlassian.com/expect-ct-report/global-proxy", enforce, max-age=86400 0.08%
enforce, max-age=21600 0.08%
max-age=7776000, enforce 0.07%
max-age=31536000 0.07%
max-age=86400, enforce 0.05%
max-age=31536000, enforce 0.04%
enforce, max-age=30 0.04%
enforce, max-age=86400, report-uri="https://hpage-report.uriports.com/reports/enforce" 0.03%
enforce; max-age=2592000; 0.02%
enforce, max-age=31536000 0.02%
enforce, max-age=300 0.02%
enforce,max-age=86400 0.02%
enforce, max-age=86400 0.02%
max-age=86400, report-uri="https://www.linkedin.com/platform-telemetry/ct" 0.02%