Guest session
Check Detail

costco.com · DNS

Passed Grade A
100.0%
Hostname costco.com
Check name DNS
last run 10/03/2026 21:10
Result
Incomplete Grade B 78.2%

Result Detail

DNS
Host Type Answer TTL
23.58.110.34

Result Detail

HEADER
Alerts
  • Strict-Transport-Security: HSTS active but consider preload
  • X-Content-Type-Options: Header missing
  • X-Frame-Options: Header missing
  • Referrer-Policy: Header missing
  • Permissions-Policy: Permissions-Policy missing
  • Cross-Origin-Opener-Policy: Header missing
  • Cross-Origin-Embedder-Policy: Header missing
  • Cross-Origin-Resource-Policy: Header missing
  • Expect-CT: Expect-CT missing
  • X-Permitted-Cross-Domain-Policies: Header missing
  • Access-Control-Allow-Origin: Access-Control-Allow-Origin missing
  • Server: Sensitive header exposed
  • Origin-Agent-Cluster: Header missing
Normalized headers
content-security-policy default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests;
x-build-reference 1.22.3-22734697192
x-build-tag prd-usbc-release-v1.22.3
x-next-i18n-router-locale en-us
x-middleware-rewrite /en-us
x-nextjs-cache HIT
etag "d1pz6eidr723spo"
content-type text/html; charset=utf-8
x-envoy-upstream-service-time 131
server istio-envoy
x-costco-gdx-deployment blue
x-costco-gdx-backend external-web-backend
expires Tue, 10 Mar 2026 20:10:30 GMT
cache-control max-age=0, no-cache, no-store
pragma no-cache
date Tue, 10 Mar 2026 20:10:30 GMT
set-cookie akavpau_zezxapz5yf=1773173730~id=a7ef94cd70880256732654e9e330ae45; Domain=www.costco.com; Path=/; Secure; SameSite=None; akaas_AS01=2147483647~rv=87~id=8d51425b09913196ebd01f5db5ffeb62; path=/; Secure; SameSite=None; _abck=F639C64530D4600E9D6DAB2335799CDA~-1~YAAQf1ATAnp8fNecAQAARFlf2Q/MZkLP17JBN/UE8rXmQl6Jobusi+S0M3ajzrhgG5Q1s7nJFrs70pcfXdV0+woRZQpEKUYPAEWH0GSpf/2d+RDof2aofJVf4Dd2VHRHXd6QOqG+UTyARbVnzSQpFr/hTsjuSk1Z+0G8xhgzSBk6WuMX7naaHT0epCAStVyP0wbqfqWPL1q5bVB3rOHb9Hz5BftUg0Mspoc0qoLra1v82FmL87o8x4GS6BA4ypjHMyGsmUJ1I3mQWZ3dcJF1CG/7gBB54F02LwYhLq/730cu0f8tpmB/9dxcTEyY3BOWG6xU4749BqHMhD/nnsTTfv5nKFmPEP+ufsoHm29j/VKrStFW+xsQ2GmDGnukthEh2OumuX7eT/tdiy726BnHANAGVWw5xAfgVo1K4GZxRACeB44CUfQyeRWLV8ErrHQvlNaBKD/aMQk=~-1~-1~-1~-1~-1; Domain=.costco.com; Path=/; Expires=Wed, 10 Mar 2027 20:10:30 GMT; Max-Age=31536000; Secure; bm_sz=009AECE71F1CD987390315E6BCF6925C~YAAQf1ATAnt8fNecAQAARFlf2R8pVYoBWNUE8nW4+iCicGeIsVnzbADtaVr1f/4XTUD+0QMXbwqbmW6Roz0Bq29CWe0ThELCkaJkZuutROAQEShmdS+KOrJN5CVB28RWu4u2mjd+sc7hpAnNGO/RxtiKLwPaLIz7OYFaOsmCgukVgwQ0gd0laPDcqT1zfswoD5vPcqEk4s8LBbstn1Xp3ra7Fnppe786VcN4acE/IvvACJlVq0pzDuVlvj3r/fda5bkrHqXpP6ZltGfIN2dNzw4NQafrkwg4lZ3aNTC5wHCgeoPZSrR9MeJWFUiH72F06KofwaTpRYNL+u1wyqPKu9QAdIk+v1nmWLFqnpJWpRHXsNpvoA==~3356216~3224641; Domain=.costco.com; Path=/; Expires=Wed, 11 Mar 2026 00:10:30 GMT; Max-Age=14400
strict-transport-security max-age=31536000;includeSubDomains
server-timing ak_p; desc="1773173430506_34820223_10955312_3413_23849_33_27_15";dur=1
Transport
Check name Status Actual Expected Detail Severity Recommendation
Strict-Transport-Security ⚠️ Warning max-age=31536000;includeSubDomains max-age>=15768000; includeSubDomains; preload HSTS active but consider preload Critical Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Expect-CT ❌ Missing enforce; max-age>=86400 Expect-CT missing Medium Expect-CT: enforce, max-age=86400, report-uri="https://report.example.com"
Content Security
Check name Status Actual Expected Detail Severity Recommendation
Content-Security-Policy ✅ Passed default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests; default-src 'self'; frame-ancestors 'none' default-src 'self'; frame-ancestors 'none' Critical Content-Security-Policy: default-src 'self'; frame-ancestors 'none'
MIME
Check name Status Actual Expected Detail Severity Recommendation
X-Content-Type-Options ❌ Missing nosniff Header missing High X-Content-Type-Options: nosniff
Framing
Check name Status Actual Expected Detail Severity Recommendation
X-Frame-Options ❌ Missing DENY or SAMEORIGIN Header missing High X-Frame-Options: DENY
Privacy
Check name Status Actual Expected Detail Severity Recommendation
Referrer-Policy ❌ Missing strict-origin-when-cross-origin / same-origin Header missing Medium Referrer-Policy: strict-origin-when-cross-origin
Browser Features
Check name Status Actual Expected Detail Severity Recommendation
Permissions-Policy ❌ Missing camera=(); geolocation=(); microphone=() Permissions-Policy missing Medium Permissions-Policy: camera=(), geolocation=(), microphone=()
Cross-Origin
Check name Status Actual Expected Detail Severity Recommendation
Cross-Origin-Opener-Policy ❌ Missing same-origin Header missing High Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy ❌ Missing require-corp Header missing High Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Resource-Policy ❌ Missing same-origin Header missing Medium Cross-Origin-Resource-Policy: same-origin
Origin-Agent-Cluster ❌ Missing ?1 Header missing Low Origin-Agent-Cluster: ?1
Caching
Check name Status Actual Expected Detail Severity Recommendation
Cache-Control ✅ Passed max-age=0, no-cache, no-store no-store, private, max-age=0 no-store, private, max-age=0 High Cache-Control: no-store, private, max-age=0
Legacy
Check name Status Actual Expected Detail Severity Recommendation
X-Permitted-Cross-Domain-Policies ❌ Missing none Header missing Low X-Permitted-Cross-Domain-Policies: none
CORS
Check name Status Actual Expected Detail Severity Recommendation
Access-Control-Allow-Origin ❌ Missing Scoped origin (no wildcard) Access-Control-Allow-Origin missing Medium Access-Control-Allow-Origin: https://app.example.com
Information Disclosure
Check name Status Actual Expected Detail Severity Recommendation
Server ❌ Missing istio-envoy Header removed or generic Sensitive header exposed High Remove Server header or set to a generic token
X-Powered-By ✅ Passed Header removed Header not exposed High Remove X-Powered-By header
X-AspNet-Version ✅ Passed Header removed Header not exposed Medium Remove framework version headers
Raw headers
HTTP/2 200 
content-security-policy: default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests;
x-build-reference: 1.22.3-22734697192
x-build-tag: prd-usbc-release-v1.22.3
x-next-i18n-router-locale: en-us
x-middleware-rewrite: /en-us
x-nextjs-cache: HIT
etag: "d1pz6eidr723spo"
content-type: text/html; charset=utf-8
x-envoy-upstream-service-time: 131
server: istio-envoy
x-costco-gdx-deployment: blue
x-costco-gdx-backend: external-web-backend
expires: Tue, 10 Mar 2026 20:10:30 GMT
cache-control: max-age=0, no-cache, no-store
pragma: no-cache
date: Tue, 10 Mar 2026 20:10:30 GMT
set-cookie: akavpau_zezxapz5yf=1773173730~id=a7ef94cd70880256732654e9e330ae45; Domain=www.costco.com; Path=/; Secure; SameSite=None
set-cookie: akaas_AS01=2147483647~rv=87~id=8d51425b09913196ebd01f5db5ffeb62; path=/; Secure; SameSite=None
strict-transport-security: max-age=31536000;includeSubDomains
set-cookie: _abck=F639C64530D4600E9D6DAB2335799CDA~-1~YAAQf1ATAnp8fNecAQAARFlf2Q/MZkLP17JBN/UE8rXmQl6Jobusi+S0M3ajzrhgG5Q1s7nJFrs70pcfXdV0+woRZQpEKUYPAEWH0GSpf/2d+RDof2aofJVf4Dd2VHRHXd6QOqG+UTyARbVnzSQpFr/hTsjuSk1Z+0G8xhgzSBk6WuMX7naaHT0epCAStVyP0wbqfqWPL1q5bVB3rOHb9Hz5BftUg0Mspoc0qoLra1v82FmL87o8x4GS6BA4ypjHMyGsmUJ1I3mQWZ3dcJF1CG/7gBB54F02LwYhLq/730cu0f8tpmB/9dxcTEyY3BOWG6xU4749BqHMhD/nnsTTfv5nKFmPEP+ufsoHm29j/VKrStFW+xsQ2GmDGnukthEh2OumuX7eT/tdiy726BnHANAGVWw5xAfgVo1K4GZxRACeB44CUfQyeRWLV8ErrHQvlNaBKD/aMQk=~-1~-1~-1~-1~-1; Domain=.costco.com; Path=/; Expires=Wed, 10 Mar 2027 20:10:30 GMT; Max-Age=31536000; Secure
set-cookie: bm_sz=009AECE71F1CD987390315E6BCF6925C~YAAQf1ATAnt8fNecAQAARFlf2R8pVYoBWNUE8nW4+iCicGeIsVnzbADtaVr1f/4XTUD+0QMXbwqbmW6Roz0Bq29CWe0ThELCkaJkZuutROAQEShmdS+KOrJN5CVB28RWu4u2mjd+sc7hpAnNGO/RxtiKLwPaLIz7OYFaOsmCgukVgwQ0gd0laPDcqT1zfswoD5vPcqEk4s8LBbstn1Xp3ra7Fnppe786VcN4acE/IvvACJlVq0pzDuVlvj3r/fda5bkrHqXpP6ZltGfIN2dNzw4NQafrkwg4lZ3aNTC5wHCgeoPZSrR9MeJWFUiH72F06KofwaTpRYNL+u1wyqPKu9QAdIk+v1nmWLFqnpJWpRHXsNpvoA==~3356216~3224641; Domain=.costco.com; Path=/; Expires=Wed, 11 Mar 2026 00:10:30 GMT; Max-Age=14400
server-timing: ak_p; desc="1773173430506_34820223_10955312_3413_23849_33_27_15";dur=1

Result Detail

SSL
Check name Status Value
certificate chain is complete ✅ Passed 3
root CA is trusted ✅ Passed Trusted
cert valid for ✅ Passed 180
chain certs are valid until ✅ Passed 07.09.2026
CN matches Domainname ✅ Passed costco.com
certificate subject ✅ Passed jurisdictionC=US, jurisdictionST=Washington, businessCategory=Private Organization, serialNumber=601 024 674, C=US, ST=Washington, L=Issaquah, O=Costco Wholesale CORPORATION, CN=costco.com
certificate issuer ✅ Passed C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1
signature algorithm ✅ Passed ecdsa-with-SHA384
TLS protocol ✅ Passed TLSv1.3 TLS_AES_256_GCM_SHA384
Subject Alternative Names ✅ Passed costco.com, www.costco.com
Public Key ✅ Passed EC 256
Certificate chain
# Common name Issuer Valid until CA
0 costco.com C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 07.09.2026 01:59:59 No
1 costco.com C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 07.09.2026 01:59:59 No
2 DigiCert Global G3 TLS ECC SHA384 2020 CA1 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3 14.04.2031 01:59:59 Yes
TLS details
Negotiated protocol TLSv1.3
Cipher suite TLS_AES_256_GCM_SHA384 (256 bit)
Cipher version TLSv1.3
Perfect Forward Secrecy Attention
Earliest chain expiry 07.09.2026 01:59
Fingerprints
SHA-256 4B:FF:F7:23:E5:C7:C3:8A:3A:9E:A8:66:5D:BB:47:3A:C5:9B:86:D9:85:9E:B1:E7:23:26:6C:22:27:87:65:BA
SHA-1 BE:D4:38:BA:83:19:AA:CE:24:92:80:72:16:A3:B5:79:26:1B:5A:18
Revocation
OCSP URLs
http://ocsp.digicert.com
CRL URLs
Full Name: URI:http://crl3.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1-2.crl Full Name: URI:http://crl4.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1-2.crl
Issuer URLs (AIA)
http://cacerts.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1-2.crt
OCSP Must-Staple No
Trust evaluation

Attempted: Yes

Trusted: Yes

OpenSSL diagnostic command
openssl s_client -connect costco.com:443 -servername costco.com

Result Detail

WAF
Sign up to use!
Ownership verification required

Real WAF results become available after signing up. Until then we show you a small teaser from the imagination department.

  • Shield level Mythisch
  • Watchers Gremlins im Standby
  • Last attack Story folgt nach Registrierung