How this was measured
On 2026-10-04 we requested the homepage of each of the 78 hand-picked domains our other surveys use, then followed every favicon declaration we found and downloaded the file behind it. Each request identified itself with a survey user agent and was attempted directly first, then through a local proxy; 55 domains answered on the direct path and 23 needed the proxy. We fetched 293 icon URLs in total.
61 of 78 produced a readable homepage (78.2%). The other 17: 10 answered with a bot wall — 403 from ebay.com, stackoverflow.com, npmjs.com, searchengineland.com, doordash.com, yelp.com and nih.gov, 429 from uber.com, and 202 from amazon.com and booking.com — and 7 never answered (nytimes.com, reuters.com, washingtonpost.com, etsy.com, quora.com, vimeo.com, coinbase.com).
Three rules shaped the parsing, and each one was learned the hard way. Attribute values are not always quoted — kubernetes.io writes <link rel=icon type=image/png href=/icons/favicon-64.png>, and a parser that only reads quoted attributes misses all fourteen of its declarations and concludes the site has no favicon at all. That is exactly what our first run reported, and printing the raw tags is what caught it. Every request writes its own temporary file, because concurrent downloads sharing one filename read each other's bytes. And a fetch failure is not a finding: a 403 from a WAF means we could not see the file, not that the site does not have one.
Finding 1: declaring an icon is the norm, and three is the median
57 of 61 homepages (93.4%) declare at least one icon link. Across those 61 pages we parsed 248 <link> tags with an icon role. The per-site count runs from 0 to 14: median 3, 75th percentile 6, and six sites declare eight or more — coursera.org 14, ahrefs.com 13, figma.com 12, vercel.com 12, asana.com 10, airbnb.com 9.
By role: icon 120, apple-touch-icon 97, manifest 21, mask-icon 9, fluid-icon 1. The apple-touch-icon count is the surprising one — it is not a search feature and not a browser-tab feature, and it is still declared almost as often as the icon itself. The 21 manifests matter for a different reason: on a site that ships a PWA, the manifest is often where the large icons actually live, which is why a page can look icon-poor in its <head> and be perfectly fine in practice.
Finding 2: /favicon.ico is still maintained, but it is not a safe assumption
53 of 61 sites (86.9%) serve a real image at /favicon.ico, even though 93.4% of them also declare their icons explicitly. The default path is still doing work.
But eight do not serve one. Six return 404 — notion.so, kubernetes.io, rust-lang.org, wikimedia.org, wise.com and digitalocean.com — and two are behind a WAF that refused us: netflix.com and moz.com (403). For the six, everything depends on the declarations in the head being present and correct; a consumer that only asks for /favicon.ico — an RSS reader, a bookmark manager, a link preview bot — gets a 404 and shows a placeholder.
Zero sites returned an HTML page at /favicon.ico. We looked for this specifically because single-page apps with catch-all routes are widely reported to serve a 200 for every path, which would make an image check meaningless. In this sample nobody does; the only 200s at that path were real images.
Finding 3: PNG is the format everyone actually ships
Across all declared and default icons we downloaded, the format mix is PNG 153, ICO 76, SVG 23. The 1990s container is still the second most common format, and it is almost entirely because of the default path: of the 53 sites serving something at /favicon.ico, 44 serve a genuine ICO file, 8 serve a PNG under that name, and 1 serves a WebP.
That single WebP is worth naming: searchenginejournal.com returns image/webp at /favicon.ico, which is a CDN image-optimisation layer rewriting the response. It is harmless there because the page also declares a 144×144 PNG. It would not be harmless on a site that relied on the default path, because WebP is not on Google's supported list — the same list that excludes SVG.
13 sites (21.3%) declare an SVG icon: github.com, figma.com, tumblr.com, rust-lang.org, go.dev, developer.mozilla.org, ahrefs.com, semrush.com, yoast.com, mit.edu, stripe.com, netlify.com and digitalocean.com. Every one of them also ships a raster icon, so none of them loses anything. That is the pattern: SVG as the enhancement for browsers that support it, raster as the thing that always works. Not one site in the sample relies on SVG alone.
Finding 4: what the files actually measure
We read the real pixel dimensions out of each file header rather than trusting the sizes attribute — which is just as well, because only 30 of 61 sites (49.2%) write a sizes attribute on any icon link. Google's guidance is a square icon of at least 8×8, with a recommendation above 48×48. Here is the largest icon we could fetch from each site:
≥256px: 13 sites. 180–255px: 21. 64–179px: 13. 48–63px: 7. 32–47px: 6.
Those six are the interesting ones — zoom.us, nodejs.org, twitch.tv, archive.org, khanacademy.org and squareup.com — where the largest icon anywhere on the page is 32×32. Two of them are among the most-visited sites on the internet. Being below the recommendation is not a penalty; it is a resolution limit on every surface that renders the icon larger than a tab.
The default path is where sizes get sloppy. Of the 52 /favicon.ico files we could measure, only 30 are 48×48 or larger. The distribution: 48×48 (22 sites), 32×32 (15), 16×16 (6), 256×256 (4), 64×64 (3) — plus two oddities, a 25×25 at target.com and a 99×96 at cloudflare.com. Six sites still ship a 16×16 default in 2026.
Two icons in the sample are not square, which Google's guidelines require: slack.com declares a file named favicon-32.png that is actually 35×34, and Cloudflare's default is 99×96. Both are close enough to square to look fine, and both would be rejected by a checker that enforces the ratio.
Finding 5: the metadata around the icon is where the errors are
The icon files themselves are almost always fine — we found no site whose declared icons were all broken. The mistakes are in the attributes describing them:
Only 59.0% of sites put a type attribute on any icon link, and 49.2% put sizes. Two sites declare a format that does not match the bytes: bloomberg.com and zoom.us both say type="image/png" and both serve an ICO file. That is survivable, because every browser sniffs the content, but it defeats the point of the attribute — the one consumer that reads type is the one deciding what it is able to render.
theguardian.com declares its apple-touch-icon as an SVG. iOS does not render SVG for that slot, so the declaration exists and the home-screen icon it describes does not. It is the mirror image of the SVG-as-favicon question: there, SVG is a valid enhancement for browsers; here, it is a format the target platform never supported.
Finding 6: nobody in the sample used a data: URI
Zero of the 61 sites declared an icon as a data: URI. That matters because Google requires the favicon to be a file that Googlebot-Image can crawl, and there is no URL in a data: URI for a crawler to request.
This site was the counter-example until today. Our own <head> declared a single inline SVG as a data: URI — with the angle brackets and spaces unencoded, which is a second problem — and /favicon.ico returned our 404 page. The browser tab looked right, which is why it survived review for months. We found it by running this survey's checks against our own domain, and the fix is now three real files generated by scripts/favicon-assets.mjs at build time: a multi-size favicon.ico (16, 32 and 48), an SVG, and a 180×180 apple-touch-icon.png. The generator now emits the three <link> tags as well, and the content gate fails the build if a declared static asset does not exist — which is the check that would have caught this on day one.
What to ship
A real /favicon.ico, containing 16, 32 and 48. It is the only icon most consumers will ever ask for by name, and 8 of the 61 sites here return nothing at that path. PNG payloads inside the ICO container are supported everywhere that matters.
A raster icon of at least 48×48, declared with sizes and a correct type. Google's supported formats are BMP, GIF, ICO, PNG, JPEG, PPM and TIFF. Six sites in this sample top out at 32×32 and would be better off with a 96 or 180.
An SVG as well, if you like — but never as the only icon. 13 sites here do it, and all 13 keep a raster fallback. That is the version that works.
An apple-touch-icon that is a PNG. 97 declarations across 61 sites make this the second most common role; one of them points at an SVG, which iOS ignores.
Keep the URL stable. Google's documentation is explicit about this, and it is the one favicon rule that is about patience rather than markup: a favicon that moves has to be re-crawled and re-processed before it appears.
Check the file, not the tag. The failure in this sample was never a missing <link> — it was a <link> pointing at a 401, a 404, a 25×25, or a format the target platform cannot read. Our meta tag generator emits the three declarations with the paths and attributes already correct, and the Open Graph survey covers the other half of what belongs in the head.
Limitations
61 homepages out of 78 attempted, from a hand-picked list of well-known sites, not a random sample of the web. Seventeen domains are missing entirely — 10 bot walls and 7 timeouts — and they are disproportionately large, heavily defended sites, so the sample is biased toward sites that are easy to crawl. The redirect chain survey and the heading survey lose almost exactly the same 17 domains, for the same reason.
We read server HTML only, and we fetched at most 20 icon URLs per site. Six sites declare eight or more, and coursera.org declares 14; where we hit the cap the untested declarations are not counted either way. A site that generates its icon links with JavaScript would look like it declares nothing — we saw no such case here, but the method cannot rule it out.
We measured what our user agent was served. Two sites refused the /favicon.ico request with a 403 and are recorded as undecidable rather than as missing. A browser-like user agent would have reached more, and some of what we call a 404 could be a WAF rule that answers 404 instead of 403. One site returned WebP from an image-optimising CDN, which may vary by region and by request headers.
Pixel dimensions come from file headers — PNG IHDR, ICO directory entries, GIF and BMP headers. That is exact for those formats. SVG has no intrinsic size in the same sense, so SVG files are counted as a format but excluded from the size table. We did not fetch manifest files, so icons declared only inside a webmanifest are invisible to this survey; 21 sites link a manifest and their real icon set may be larger than what we measured.
The statement about Google's supported formats, the 8×8 minimum, the 48×48 recommendation, the square requirement, the crawlability requirement and the stability requirement are all taken from Google's own favicon documentation, checked on 2026-10-04 rather than repeated from memory.
Reproduce it
The script and the shared domain list ship with this site. node scripts/survey-favicon.mjs fetches all 78 homepages and every icon they declare, and stores each response; --report re-derives every number from the stored data without touching the network; --evidence prints the raw <link> tags and the fetched file's status, format and dimensions behind each verdict, which is how every claim above was verified. Our robots.txt, JSON-LD, canonical, hreflang, AI crawler, llms.txt, sitemap and SERP snippet surveys run the same domain list from other angles.