Summary

  • Let’s Encrypt accounts for 99.21% of a July certificate-stream sample, but 84% of matched endpoint observations in the published analysis.
  • The second count distinguishes certificate serial number, IP address, port and issuer. It is not a count of unique customers or websites.
  • The collector retrieves certificates without validating their chain or hostname. Observation is not proof of successful client authentication.

A supplier can dominate the flow of new credentials without supplying the same proportion of distinct services. That distinction matters in Yevheniya Nosyk’s September 8 analysis for Internet Society’s Pulse, which examines publicly trusted certificates containing IP addresses rather than only domain names.

The striking result is Let’s Encrypt’s 99.21% share of a 72-hour stream collected in July 2026. Read as a census of deployed services, that number would carry much more authority than the method gives it.

Two denominators, not two dates

The published deployment notebook reduces the stream to 371,980 distinct serial numbers, of which 369,031 are attributed to Let’s Encrypt. This is the basis of 99.21%.

Its matched deployment observations are a different set: 42,755 unique combinations of serial number, IP address, port and issuer. Let’s Encrypt appears in 35,915, or 84%. Those combinations cover 37,867 addresses across 21 ports. One address may contribute more than one observation.

Published measure Unit counted Let’s Encrypt share
Certificate-stream sample Distinct certificate serials 99.21%
Matched endpoint observations Serial, address, port and issuer combinations 84%

Neither row measures revenue, customers or all services on the Internet. Moving between them is not evidence that Let’s Encrypt lost share. Both the counting unit and the selection of observations change.

Issuance intensity can also obscure the number of addresses involved. The 2025 analysis records 176,865 certificate occurrences associated with just two IP addresses. That does not establish two customers or explain their workloads.

Let’s Encrypt’s January availability announcement specifies 160-hour IP certificates. Shorter lifetimes can produce more issuance per continuing service. They do not, by themselves, explain the exceptional two-address total.

What the probe did not certify

The collection code selects targets using certificates already valid and with more than 24 hours remaining. It retrieves certificates over TCP with hostname and chain verification disabled. The notebook then matches serial numbers, not complete certificate fingerprints.

Those choices permit collection; they are not evidence of a security failure. But the result cannot be promoted into proof that a normal client trusted the connection, reached a working application or represented a paying user.

This report examined the published code and recorded outputs, not a fresh reconstruction of the raw dataset, and performed no network probing. The useful finding is bounded: the study exposes concentrated issuance and observed deployment, while leaving the relationship between them to be measured.