Open
Cached
·
just now
85/100
SECURITY SCORE
Certificate Information
Subject
C=ES, ST=Bizkaia, L=Bilbao, O=Banco Bilbao Vizcaya Argentaria SA, CN=bbva.mx
Issuer
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1
Valid From
March 12, 2025
Valid Until
March 12, 2026
59 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
2C:71:CD:9B:53:5C:F6:60:F4:38:0C:E3:68:1E:CC:3E:F0:60:4A:0A:4E:6A:48:ED:D1:06:A0:4F:D7:F0:79:1C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains; preload
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
44 domains
bbva.mx
*.bbva.mx
facturafundacionbbva.mx
fundacionbbva.mx
segbbva.mx
*.facturafundacionbbva.mx
*.fundacionbbva.mx
*.segbbva.mx
bbva.com.mx
*.bbva.com.mx
bbvaautodigital.com.mx
*.bbvaautodigital.com.mx
bbvacobranza.mx
*.bbvacobranza.mx
bbvaconsumerfinance.mx
*.bbvaconsumerfinance.mx
bbvacreditossindicados.mx
*.bbvacreditossindicados.mx
bbvadescuentos.mx
*.bbvadescuentos.mx
bbvaempresas.mx
*.bbvaempresas.mx
bbvaextranet.mx
*.bbvaextranet.mx
bbvaglobe.mx
*.bbvaglobe.mx
bbvainmuebles.mx
*.bbvainmuebles.mx
bbvaleasing.mx
*.bbvaleasing.mx
bbvanet.com.mx
*.bbvanet.com.mx
bbvanetcash.mx
*.bbvanetcash.mx
bbvaplanpiso.mx
*.bbvaplanpiso.mx
bbvaproveedores.mx
*.bbvaproveedores.mx
bbvasegurodeauto.mx
*.bbvasegurodeauto.mx
bbvaseguros.mx
*.bbvaseguros.mx
bbvasegurossalud.mx
*.bbvasegurossalud.mx
Other domains in certificate