Page Security
Cookie prefix check
Whether your site's important cookies use the __Host- and __Secure- name prefixes that make browsers enforce their protections.
Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.
What we look at
We read the cookies your homepage sets and check for __Host- and __Secure- prefixes, and that prefixed cookies meet the rules the prefix demands.
Why it matters to your business
A prefix makes the browser refuse a cookie that is not set securely, which blocks some session-fixation tricks. A prefixed cookie that breaks the rules is silently dropped, which can quietly sign people out.
How to fix it
- Rename session cookies to __Host-name, set with Secure, Path=/ and no Domain attribute.
- Make sure every __Secure- cookie is set with the Secure flag.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
