costco.com · DNS
Result Detail
DNS| Host | Type | Answer | TTL |
|---|---|---|---|
| 23.58.110.34 | — |
Result Detail
HEADERAlerts
- Strict-Transport-Security: HSTS active but consider preload
- X-Content-Type-Options: Header missing
- X-Frame-Options: Header missing
- Referrer-Policy: Header missing
- Permissions-Policy: Permissions-Policy missing
- Cross-Origin-Opener-Policy: Header missing
- Cross-Origin-Embedder-Policy: Header missing
- Cross-Origin-Resource-Policy: Header missing
- Expect-CT: Expect-CT missing
- X-Permitted-Cross-Domain-Policies: Header missing
- Access-Control-Allow-Origin: Access-Control-Allow-Origin missing
- Server: Sensitive header exposed
- Origin-Agent-Cluster: Header missing
Normalized headers
| content-security-policy | default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests; |
|---|---|
| x-build-reference | 1.22.3-22734697192 |
| x-build-tag | prd-usbc-release-v1.22.3 |
| x-next-i18n-router-locale | en-us |
| x-middleware-rewrite | /en-us |
| x-nextjs-cache | HIT |
| etag | "d1pz6eidr723spo" |
| content-type | text/html; charset=utf-8 |
| x-envoy-upstream-service-time | 131 |
| server | istio-envoy |
| x-costco-gdx-deployment | blue |
| x-costco-gdx-backend | external-web-backend |
| expires | Tue, 10 Mar 2026 20:10:30 GMT |
| cache-control | max-age=0, no-cache, no-store |
| pragma | no-cache |
| date | Tue, 10 Mar 2026 20:10:30 GMT |
| set-cookie | akavpau_zezxapz5yf=1773173730~id=a7ef94cd70880256732654e9e330ae45; Domain=www.costco.com; Path=/; Secure; SameSite=None; akaas_AS01=2147483647~rv=87~id=8d51425b09913196ebd01f5db5ffeb62; path=/; Secure; SameSite=None; _abck=F639C64530D4600E9D6DAB2335799CDA~-1~YAAQf1ATAnp8fNecAQAARFlf2Q/MZkLP17JBN/UE8rXmQl6Jobusi+S0M3ajzrhgG5Q1s7nJFrs70pcfXdV0+woRZQpEKUYPAEWH0GSpf/2d+RDof2aofJVf4Dd2VHRHXd6QOqG+UTyARbVnzSQpFr/hTsjuSk1Z+0G8xhgzSBk6WuMX7naaHT0epCAStVyP0wbqfqWPL1q5bVB3rOHb9Hz5BftUg0Mspoc0qoLra1v82FmL87o8x4GS6BA4ypjHMyGsmUJ1I3mQWZ3dcJF1CG/7gBB54F02LwYhLq/730cu0f8tpmB/9dxcTEyY3BOWG6xU4749BqHMhD/nnsTTfv5nKFmPEP+ufsoHm29j/VKrStFW+xsQ2GmDGnukthEh2OumuX7eT/tdiy726BnHANAGVWw5xAfgVo1K4GZxRACeB44CUfQyeRWLV8ErrHQvlNaBKD/aMQk=~-1~-1~-1~-1~-1; Domain=.costco.com; Path=/; Expires=Wed, 10 Mar 2027 20:10:30 GMT; Max-Age=31536000; Secure; bm_sz=009AECE71F1CD987390315E6BCF6925C~YAAQf1ATAnt8fNecAQAARFlf2R8pVYoBWNUE8nW4+iCicGeIsVnzbADtaVr1f/4XTUD+0QMXbwqbmW6Roz0Bq29CWe0ThELCkaJkZuutROAQEShmdS+KOrJN5CVB28RWu4u2mjd+sc7hpAnNGO/RxtiKLwPaLIz7OYFaOsmCgukVgwQ0gd0laPDcqT1zfswoD5vPcqEk4s8LBbstn1Xp3ra7Fnppe786VcN4acE/IvvACJlVq0pzDuVlvj3r/fda5bkrHqXpP6ZltGfIN2dNzw4NQafrkwg4lZ3aNTC5wHCgeoPZSrR9MeJWFUiH72F06KofwaTpRYNL+u1wyqPKu9QAdIk+v1nmWLFqnpJWpRHXsNpvoA==~3356216~3224641; Domain=.costco.com; Path=/; Expires=Wed, 11 Mar 2026 00:10:30 GMT; Max-Age=14400 |
| strict-transport-security | max-age=31536000;includeSubDomains |
| server-timing | ak_p; desc="1773173430506_34820223_10955312_3413_23849_33_27_15";dur=1 |
Transport
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Strict-Transport-Security | ⚠️ Warning | max-age=31536000;includeSubDomains | max-age>=15768000; includeSubDomains; preload | HSTS active but consider preload | Critical | Strict-Transport-Security: max-age=63072000; includeSubDomains; preload |
| Expect-CT | ❌ Missing | enforce; max-age>=86400 | Expect-CT missing | Medium | Expect-CT: enforce, max-age=86400, report-uri="https://report.example.com" |
Content Security
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Content-Security-Policy | ✅ Passed | default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests; | default-src 'self'; frame-ancestors 'none' | default-src 'self'; frame-ancestors 'none' | Critical | Content-Security-Policy: default-src 'self'; frame-ancestors 'none' |
MIME
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| X-Content-Type-Options | ❌ Missing | nosniff | Header missing | High | X-Content-Type-Options: nosniff |
Framing
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| X-Frame-Options | ❌ Missing | DENY or SAMEORIGIN | Header missing | High | X-Frame-Options: DENY |
Privacy
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Referrer-Policy | ❌ Missing | strict-origin-when-cross-origin / same-origin | Header missing | Medium | Referrer-Policy: strict-origin-when-cross-origin |
Browser Features
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Permissions-Policy | ❌ Missing | camera=(); geolocation=(); microphone=() | Permissions-Policy missing | Medium | Permissions-Policy: camera=(), geolocation=(), microphone=() |
Cross-Origin
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Cross-Origin-Opener-Policy | ❌ Missing | same-origin | Header missing | High | Cross-Origin-Opener-Policy: same-origin | |
| Cross-Origin-Embedder-Policy | ❌ Missing | require-corp | Header missing | High | Cross-Origin-Embedder-Policy: require-corp | |
| Cross-Origin-Resource-Policy | ❌ Missing | same-origin | Header missing | Medium | Cross-Origin-Resource-Policy: same-origin | |
| Origin-Agent-Cluster | ❌ Missing | ?1 | Header missing | Low | Origin-Agent-Cluster: ?1 |
Caching
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Cache-Control | ✅ Passed | max-age=0, no-cache, no-store | no-store, private, max-age=0 | no-store, private, max-age=0 | High | Cache-Control: no-store, private, max-age=0 |
Legacy
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| X-Permitted-Cross-Domain-Policies | ❌ Missing | none | Header missing | Low | X-Permitted-Cross-Domain-Policies: none |
CORS
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Access-Control-Allow-Origin | ❌ Missing | Scoped origin (no wildcard) | Access-Control-Allow-Origin missing | Medium | Access-Control-Allow-Origin: https://app.example.com |
Information Disclosure
| Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
|---|---|---|---|---|---|---|
| Server | ❌ Missing | istio-envoy | Header removed or generic | Sensitive header exposed | High | Remove Server header or set to a generic token |
| X-Powered-By | ✅ Passed | Header removed | Header not exposed | High | Remove X-Powered-By header | |
| X-AspNet-Version | ✅ Passed | Header removed | Header not exposed | Medium | Remove framework version headers |
Raw headers
HTTP/2 200 content-security-policy: default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests; x-build-reference: 1.22.3-22734697192 x-build-tag: prd-usbc-release-v1.22.3 x-next-i18n-router-locale: en-us x-middleware-rewrite: /en-us x-nextjs-cache: HIT etag: "d1pz6eidr723spo" content-type: text/html; charset=utf-8 x-envoy-upstream-service-time: 131 server: istio-envoy x-costco-gdx-deployment: blue x-costco-gdx-backend: external-web-backend expires: Tue, 10 Mar 2026 20:10:30 GMT cache-control: max-age=0, no-cache, no-store pragma: no-cache date: Tue, 10 Mar 2026 20:10:30 GMT set-cookie: akavpau_zezxapz5yf=1773173730~id=a7ef94cd70880256732654e9e330ae45; Domain=www.costco.com; Path=/; Secure; SameSite=None set-cookie: akaas_AS01=2147483647~rv=87~id=8d51425b09913196ebd01f5db5ffeb62; path=/; Secure; SameSite=None strict-transport-security: max-age=31536000;includeSubDomains set-cookie: _abck=F639C64530D4600E9D6DAB2335799CDA~-1~YAAQf1ATAnp8fNecAQAARFlf2Q/MZkLP17JBN/UE8rXmQl6Jobusi+S0M3ajzrhgG5Q1s7nJFrs70pcfXdV0+woRZQpEKUYPAEWH0GSpf/2d+RDof2aofJVf4Dd2VHRHXd6QOqG+UTyARbVnzSQpFr/hTsjuSk1Z+0G8xhgzSBk6WuMX7naaHT0epCAStVyP0wbqfqWPL1q5bVB3rOHb9Hz5BftUg0Mspoc0qoLra1v82FmL87o8x4GS6BA4ypjHMyGsmUJ1I3mQWZ3dcJF1CG/7gBB54F02LwYhLq/730cu0f8tpmB/9dxcTEyY3BOWG6xU4749BqHMhD/nnsTTfv5nKFmPEP+ufsoHm29j/VKrStFW+xsQ2GmDGnukthEh2OumuX7eT/tdiy726BnHANAGVWw5xAfgVo1K4GZxRACeB44CUfQyeRWLV8ErrHQvlNaBKD/aMQk=~-1~-1~-1~-1~-1; Domain=.costco.com; Path=/; Expires=Wed, 10 Mar 2027 20:10:30 GMT; Max-Age=31536000; Secure set-cookie: bm_sz=009AECE71F1CD987390315E6BCF6925C~YAAQf1ATAnt8fNecAQAARFlf2R8pVYoBWNUE8nW4+iCicGeIsVnzbADtaVr1f/4XTUD+0QMXbwqbmW6Roz0Bq29CWe0ThELCkaJkZuutROAQEShmdS+KOrJN5CVB28RWu4u2mjd+sc7hpAnNGO/RxtiKLwPaLIz7OYFaOsmCgukVgwQ0gd0laPDcqT1zfswoD5vPcqEk4s8LBbstn1Xp3ra7Fnppe786VcN4acE/IvvACJlVq0pzDuVlvj3r/fda5bkrHqXpP6ZltGfIN2dNzw4NQafrkwg4lZ3aNTC5wHCgeoPZSrR9MeJWFUiH72F06KofwaTpRYNL+u1wyqPKu9QAdIk+v1nmWLFqnpJWpRHXsNpvoA==~3356216~3224641; Domain=.costco.com; Path=/; Expires=Wed, 11 Mar 2026 00:10:30 GMT; Max-Age=14400 server-timing: ak_p; desc="1773173430506_34820223_10955312_3413_23849_33_27_15";dur=1
Result Detail
SSL| Check name | Status | Value |
|---|---|---|
| certificate chain is complete | ✅ Passed | 3 |
| root CA is trusted | ✅ Passed | Trusted |
| cert valid for | ✅ Passed | 180 |
| chain certs are valid until | ✅ Passed | 07.09.2026 |
| CN matches Domainname | ✅ Passed | costco.com |
| certificate subject | ✅ Passed | jurisdictionC=US, jurisdictionST=Washington, businessCategory=Private Organization, serialNumber=601 024 674, C=US, ST=Washington, L=Issaquah, O=Costco Wholesale CORPORATION, CN=costco.com |
| certificate issuer | ✅ Passed | C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 |
| signature algorithm | ✅ Passed | ecdsa-with-SHA384 |
| TLS protocol | ✅ Passed | TLSv1.3 TLS_AES_256_GCM_SHA384 |
| Subject Alternative Names | ✅ Passed | costco.com, www.costco.com |
| Public Key | ✅ Passed | EC 256 |
Certificate chain
| # | Common name | Issuer | Valid until | CA |
|---|---|---|---|---|
| 0 | costco.com | C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 | 07.09.2026 01:59:59 | No |
| 1 | costco.com | C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 | 07.09.2026 01:59:59 | No |
| 2 | DigiCert Global G3 TLS ECC SHA384 2020 CA1 | C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3 | 14.04.2031 01:59:59 | Yes |
TLS details
| Negotiated protocol | TLSv1.3 |
|---|---|
| Cipher suite | TLS_AES_256_GCM_SHA384 (256 bit) |
| Cipher version | TLSv1.3 |
| Perfect Forward Secrecy | Attention |
| Earliest chain expiry | 07.09.2026 01:59 |
Fingerprints
| SHA-256 | 4B:FF:F7:23:E5:C7:C3:8A:3A:9E:A8:66:5D:BB:47:3A:C5:9B:86:D9:85:9E:B1:E7:23:26:6C:22:27:87:65:BA |
|---|---|
| SHA-1 | BE:D4:38:BA:83:19:AA:CE:24:92:80:72:16:A3:B5:79:26:1B:5A:18 |
Revocation
Trust evaluation
Attempted: Yes
Trusted: Yes
OpenSSL diagnostic command
openssl s_client -connect costco.com:443 -servername costco.com
Result Detail
WAFReal WAF results become available after signing up. Until then we show you a small teaser from the imagination department.
- Shield level Mythisch
- Watchers Gremlins im Standby
- Last attack Story folgt nach Registrierung