SSL check results of systemli.org

NEW You can also bulk check multiple servers.

Discover if the mail servers for systemli.org can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Wed, 26 May 2021 06:56:38 +0000

The mailservers of systemli.org can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @systemli.org addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.systemli.org
2a00:c38:11e:ffff::a032
10
supported
mail.systemli.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s
mail.systemli.org
212.103.72.247
10
supported
mail.systemli.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s

Outgoing Mails

We have not received any emails from a @systemli.org address so far. Test mail delivery

Certificates

First seen at:

CN=mail.systemli.org

Certificate chain
  • mail.systemli.org
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption

      • R3
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • DST Root CA X3 (Certificate is self-signed.)
            • remaining
            • 2048 bit
            • sha1WithRSAEncryption

Subject
Common Name (CN)
  • mail.systemli.org
Alternative Names
  • mail.systemli.org
  • mail1.systemli.org
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R3
validity period
Not valid before
2021-03-27
Not valid after
2021-06-25
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
6C:0F:3A:FB:1B:DD:DC:BB:A7:72:BF:42:4D:D5:55:2E:85:E2:3F:D9:13:5F:AB:00:FD:87:AA:1F:A7:D4:9A:EC
SHA1
E0:B8:7E:5F:80:C0:93:B9:3B:51:FC:CA:42:A6:AC:CD:CD:FD:A9:20
X509v3 extensions
subjectKeyIdentifier
  • E6:CB:09:34:A2:60:14:52:81:02:8E:D4:9B:CE:A9:FC:6C:57:25:5E
authorityKeyIdentifier
  • keyid:14:2E:B3:17:B7:58:56:CB:AE:50:09:40:E6:1F:AF:9D:8B:14:C2:C6
authorityInfoAccess
  • OCSP - URI:http://r3.o.lencr.org
  • CA Issuers - URI:http://r3.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
  • Policy: 1.3.6.1.4.1.44947.1.1.1
  • CPS: http://cps.letsencrypt.org
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : F6:5C:94:2F:D1:77:30:22:14:54:18:08:30:94:56:8E:
  • E3:4D:13:19:33:BF:DF:0C:2F:20:0B:CC:4E:F1:64:E3
  • Timestamp : Mar 27 12:42:15.006 2021 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:A5:3A:C8:C5:E8:3E:C8:AF:C9:B0:91:
  • E5:A1:4F:ED:89:A7:43:F8:4D:7F:3E:33:35:88:33:F6:
  • CB:73:BF:8A:F4:02:20:11:AD:BC:F5:4C:47:40:38:A2:
  • 31:C4:7D:08:BB:BF:DD:07:07:5A:99:C4:71:61:09:C9:
  • C9:B4:22:86:B7:BD:DE
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6F:53:76:AC:31:F0:31:19:D8:99:00:A4:51:15:FF:77:
  • 15:1C:11:D9:02:C1:00:29:06:8D:B2:08:9A:37:D9:13
  • Timestamp : Mar 27 12:42:15.382 2021 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:33:DE:FE:44:95:07:86:51:CD:1D:CE:03:
  • 17:E5:C4:B5:FC:F0:E4:82:64:B6:E3:4F:D2:B3:35:BA:
  • A5:F6:35:AA:02:21:00:D5:49:E2:12:97:C6:B9:E6:2D:
  • 4D:09:DE:31:00:A6:F3:28:FC:7E:3B:95:08:48:2C:FB:
  • 74:BD:E5:66:06:3B:61

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail.systemli.org
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.systemli.org
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.systemli.org
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.systemli.org
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.systemli.org
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail.systemli.org
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid