ZIMBABWE WEB SECURITY INDEX

How secure are Zimbabwe's biggest websites?

We ran a passive, external security check on 17 prominent organisations across 6 sectors — and graded each one A–F. The results are sobering.

Last scanned 2026-06-30

7/17

scored an F

D

national average (53/100)

13/17

don't force HTTPS (no HSTS)

5/17

can be email-spoofed (no DMARC)

The grade spread

A

3

sites

B

2

sites

C

4

sites

D

1

sites

F

7

sites

Only 3 of 17 organisations reached an A. The rest leave visitors — and their own brand — exposed to entirely preventable attacks.

By sector

Banking

5 sites · avg 78/100

B

Telecom

3 sites · avg 54/100

D

Government

2 sites · avg 53/100

D

Media

3 sites · avg 48/100

D

Retail

2 sites · avg 30/100

F

Insurance

2 sites · avg 23/100

F

The full leaderboard

Anonymised to sector level. Each organisation can claim its named, detailed breakdown — free.

#OrganisationGradeScoreHTTPSHSTSCSPXFOXCTORefSPFDMARC
1Bank AA100
2Bank BA94
3Government AA90
4Bank CB84
5Bank DB84
6Telecom AC73
7Telecom BC60
8Media AC60
9Retailer AC60
10Media BD54
11Bank EF30
12Telecom CF30
13Insurer AF30
14Media CF30
15Government BF15
16Insurer BF15
17Retailer BF0

Is your organisation on this list?

We'll send you the named, full breakdown of where you sit — every check, every gap, and exactly how to fix it. No cost, no obligation.

Scan your own site now

How we scored — and what we didn't do

Every grade comes from a passive, external check of public signals only: whether the site serves a working HTTPS response, which security headers it sends (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), and whether the domain publishes SPF and DMARC records to stop email spoofing. We did not log in, probe aggressively, scan for vulnerabilities, or touch anything private. It is the same read-only methodology any visitor's browser already performs.

Scores are out of 100, weighted toward the highest-impact protections (working HTTPS and email anti-spoofing carry the most weight). Grades: A 90+, B 75–89, C 60–74, D 40–59, F below 40.

Results reflect what was observable on 2026-06-30. A site that did not return a response within the scan window is recorded as unreachable over HTTPS at that moment, which affects its score. Organisations are anonymised to sector level by design — this index is about the national picture, not singling anyone out. Any organisation can claim its entry to receive the named detail and have it re-checked.

Methodology and tooling are the same passive checks available free in our security tools.