More and more Dutch organizations are building their online services with stronger security. That emerges from CBS research into how businesses use internet standards. Progress is especially visible in the areas of HTTPS and email authentication. With Internet.nl and TLS, you can also specifically check how your web and mail configuration scores and where improvements bring the most benefit.
In this article, we summarize the key findings and translate them into practical steps for website administrators, IT teams, and providers of hosting and email services.
Progress in standards for websites and email
According to CBS data, the average score for companies on Internet.nl for websites rises from 60.4% in 2020 to 74.7% in 2026. Growth is also visible for email domains: from 58.9% in 2023 to 73.2% in 2026. Between 2025 and 2026, growth was relatively large, at 6.7 percentage points for websites and 7.5 percentage points for email.
The core of this improvement is that modern standards contribute to a safer, more reliable and more accessible internet. Correct configurations, for example, help limit risks related to eavesdropping and phishing. In addition, they make it easier for security researchers to report vulnerabilities.
At the same time, the research shows that companies still do not meet the standards in every area. There is therefore room for further optimization.
Which standards are applied well in practice?
In the research, websites and mail servers are tested with Internet.nl. The tool checks the correct configuration of, among other things, IPv6, DNSSEC, RPKI, STARTTLS and DANE. It also involves standards that directly affect the security of web traffic and email delivery.
It stands out that companies more often comply with standards such as HTTPS (for a secure connection between visitor and website), DNSSEC (for protection around domain name assignment) and email authentication. For email, measures that help against phishing and spoofing are applied particularly often.
Email authentication: less room for abuse
The improvement for email domains is linked to the more frequent deployment of standards designed to prevent malicious actors from sending emails on behalf of an organization. The research mentions, among others, DKIM, DMARC and SPC. When they are properly configured, it becomes less likely that messages look legitimate while they are not.
RPKI stands out for routing authorization
In 2026, more than 80% of businesses comply with the standard for routing authorization (RPKI) for both websites and mail servers. RPKI is intended to help prevent internet traffic from being redirected via untrusted routes.
This is an important signal: organizations are therefore not only choosing standards that are visible directly in the browser or mail client, but also measures that sit deeper in the network.
Differences between small and large companies: less than you think
The research does not only look at the total end score, but also at differences by company type. The differences turn out to be limited. In some areas, small businesses even perform relatively better than larger organizations.
For example, smaller organizations support IPv6 relatively more often. Larger companies, in turn, score higher on components such as HTTPS and email authentication.
The CBS offers possible explanations for why small companies sometimes score well. Smaller organizations can more often engage external ICT specialists who work with newer standards. In addition, maintenance of legacy systems at larger companies may play a role, which can delay the timely implementation of standards introduced later. How systems are managed—internally or outsourced—can also affect the timing and quality of configurations.
Internet.nl and TLS: check your up-to-date guidelines
Alongside the general adoption of internet standards, there is a concrete development around TLS. In mid 2025, the NCSC published an update of the ICT security guidelines for Transport Layer Security (TLS). These guidelines help organizations to configure TLS securely while remaining compatible with other systems.
With Internet.nl, you can, according to the source information, also test whether the TLS configuration of web servers and incoming mail servers meets these updated guidelines. That makes Internet.nl and TLS practical: you don’t just see whether you’re “roughly right”, you can also check whether your configuration aligns with the latest recommendations.
How to get started yourself
- Test your website and email domain with Internet.nl. Enter your web address and email domain and review your score.
- Address the biggest deviations first. If you’re not at 100%, choose improvements that directly contribute to safer connections and better email authentication.
- Coordinate with your provider if you don’t manage everything in-house. Your access, hosting and email provider can often help with configuration changes.
- Get support if you have questions. The source states that you can reach out at vraag@internet.nl.
Conclusion: more security, but there’s still work to do
The figures show that Dutch companies are taking clear steps toward modern internet standards. Progress is especially noticeable in the areas of HTTPS, DNSSEC and email authentication. However, not every organization has the complete set of correct configurations.
By using Internet.nl and TLS to test your web and mail configuration, you can make targeted improvements. This makes your environment more resistant to misuse and helps build a more reliable internet for customers and partners.
Source: https://www.ncsc.nl/nieuws/bedrijven-verbeteren-beveiliging-van-websites-en-e-mail
