83/100 SECURITY SCORE

Certificate Information

Subject
CN=accounts.magento.com
Issuer
C=US, O=Amazon, CN=Amazon RSA 2048 M02
Valid From
May 09, 2025
Valid Until
June 07, 2026 212 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6B:EC:80:0D:10:DD:DA:BF:CD:FA:4B:38:79:75:4F:CD:A3:13:B2:51:50:01:FB:16:95:FC:9B:61:A6:A5:E1:9D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15724800; includeSubdomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

72 domains
accounts.magento.com afterwork-chicago.magento.com afterwork-dallas.magento.com afterwork-la.magento.com afterwork-minneapolis.magento.com afterwork-nyc.magento.com afterwork-philadelphia.magento.com afterwork-seattle.magento.com afterwork-sf.magento.com afterwork.magento.com b2bexperience.magento.com biworkshops.magento.com blog.magento.com careers.magento.com celinks.magento.com commerceandcarryout.magento.com conf.magento.com de.magento.com design.magento.com dmexco.magento.com ecgservices.magento.com ecommerceexperience.magento.com eeeula.magento.com eeula.magento.com email.magento.com enterprise.magento.com go.magento.com golinks.magento.com helpcenter.magento.com holidays-in-july.magento.com imagine.magento.com imagine2015.magento.com info.magento.com internetworld.magento.com irce.magento.com kickoff-apam.magento.com kickoff-emea.magento.com live-au.magento.com live-eu.magento.com m2m-la.magento.com m2m-portland.magento.com magento-u.magento.com magentousupport.magento.com meesa.magento.com mmeula.magento.com mobileapp.magento.com nrf.magento.com partnermarketing.magento.com shoporg.magento.com smallbusiness.magento.com status.magento.com stratus.magento.com support.magento.com training.magento.com ua.magento.com webmail.magento.com wiki.magento.com www1.magento.com de.enterprise.magento.com eeeula.ecgservices.magento.com merch.docs.magento.com www.marketplace.magento.com

Other domains in certificate

de.magentocommerce.com demo-admin.magentocommerce.com demo.magentocommerce.com docs.magentocommerce.com enterprise-admin.magentocommerce.com enterprise-demo.magentocommerce.com license.magentocommerce.com picture.magentocommerce.com support.magentocommerce.com widgets.magentocommerce.com