Open
Cached
·
just now
85/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=District of Columbia, L=Washington, O=AARP, CN=hosting.aarp.org
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
Valid From
June 25, 2025
Valid Until
December 09, 2025
32 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E6:55:A6:CC:BD:37:80:38:69:F2:83:E8:E7:03:9C:A7:51:BF:C0:91:8D:51:25:EE:9F:F1:1F:EF:91:A3:35:CB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000;
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
71 domains
aarp.org
enjoyaarp.org
getaarp.org
joinaarp.org
soyaarp.org
tryaarp.org
yesaarp.org
aarpcares.aarp.org
act.aarp.org
auto.aarp.org
autobuying.aarp.org
autos.aarp.org
blog.aarp.org
campaigns.aarp.org
celebratesyou.aarp.org
checkout.aarp.org
dataexplorer.aarp.org
dataexplorerfsb.aarp.org
drugprices.aarp.org
elearning.aarp.org
healthcostscalc.aarp.org
healthtools.aarp.org
hosting.aarp.org
jeopardy.aarp.org
lifereimagined.aarp.org
login.aarp.org
longevityeconomy.aarp.org
moneymap.aarp.org
now.aarp.org
onlinefitness.aarp.org
policydata.aarp.org
premioproposito.aarp.org
purposeprize.aarp.org
recipes.aarp.org
resume.aarp.org
rewards.aarp.org
signup.aarp.org
takeastand.aarp.org
travel.aarp.org
veterans.aarp.org
videos.aarp.org
volunteer.aarp.org
votingtool.aarp.org
www.enjoyaarp.org
www.getaarp.org
www.joinaarp.org
www.soyaarp.org
www.tryaarp.org
www.yesaarp.org
stage.dataexplorerfsb.aarp.org
vacation.rewards.aarp.org
aarpenrollment.com
www.aarpenrollment.com
aarpinfo.org
www.aarpinfo.org
aarpservices.com
www.aarpservices.com
createthegood.org
www.createthegood.org
demoasi.com
www.demoasi.com
help.aarp
www.help.aarp
luxeandluminous.com
myaarpconnection.com
www.myaarpconnection.com
mystayingsharp.org
www.mystayingsharp.org
relaxandradiate.com
stayingsharp.org
www.stayingsharp.org
Other domains in certificate