Open
Cached
·
just now
87/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q3
Valid From
August 06, 2025
Valid Until
February 02, 2026
16 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
36:45:88:A5:7E:62:0D:42:BF:B2:45:0B:A3:1F:30:70:1E:A2:9F:22:DE:1A:13:EC:9C:0A:B8:89:9A:D3:5E:8F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Strong
default-src; script-src; style-src; +5 more
default-src 'self' *.zywave;script-src 'self' *.zywave.com *.zywave.co.uk www.google.com 'nonce-SMkXqWY2uk9VevznVJTmMsijhcnn0hP1YCpDmoTOxiI=';style-src 'self' 'nonce-SMkXqWY2uk9VevznVJTmMsijhcnn0hP1YCpDmoTOxiI=';frame-src 'self' www.google.com;connect-src 'self';img-src 'self' data: *.zywave.com *.zywave.co.uk;manifest-src *.zywave.com *.zywave.co.uk;frame-ancestors 'self'
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
68 domains
*.zywave.com
*.onzywave.com
*.portal.zywave.com
accountportal.net
*.accountportal.net
accuagency.com
*.accuagency.com
advisen.com
*.advisen.com
*.agencymatrix.com
brokeragebuilder.com
*.brokeragebuilder.com
clientportalonline.com
*.clientportalonline.com
codesixfour.com
*.codesixfour.com
dmwarehouse.com
*.dmwarehouse.com
*.getitc.com
hr360.com
*.hr360.com
hrbasicsonline.com
*.hrbasicsonline.com
hrconnection.com
*.hrconnection.com
imperva.com
inscontact.com
*.inscontact.com
*.insurancewebsitebuilder.com
itccarrierrates.com
*.itccarrierrates.com
itcdataservices.com
*.itcdataservices.com
itcratingservices.com
*.itcratingservices.com
iwantinsurance.com
*.iwantinsurance.com
*.quotes.iwantinsurance.com
miedge.biz
*.miedge.biz
miedge.net
*.miedge.net
modmaster.com
*.modmaster.com
myinsportal.com
*.myinsportal.com
mywaveelements.com
*.mywaveelements.com
*.onzywave.co.uk
partnerxe.com
*.partnerxe.com
*.portal.partnerxe.com
*.sisportal-dev.partnerxe.com
*.sisportal-prod.partnerxe.com
*.sisportal-qa.partnerxe.com
planadvisor.com
*.planadvisor.com
plandocbuilder.com
*.plandocbuilder.com
*.proposal.insure
ratefactory.com
*.ratefactory.com
secureclient.net
*.secureclient.net
turborater.com
*.turborater.com
*.wrap360.com
*.zywave.co.uk
Other domains in certificate