SSL check results of blue-canoe.net

NEW You can also bulk check multiple servers.

Discover if the mail servers for blue-canoe.net can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 14 Sep 2026 14:40:21 +0000

The mailservers of blue-canoe.net can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @blue-canoe.net addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx1.blue-canoe.net
185.154.145.3
10
supported
mail.blue-canoe.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mx2.blue-canoe.net
185.26.241.73
20
supported
mx2.blue-canoe.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
3 s
mx3.blue-canoe.net
185.154.145.8
30
supported
mx3.blue-canoe.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @blue-canoe.net address so far. Test mail delivery

Certificates

First seen at:

CN=mx3.blue-canoe.net

Certificate chain
  • mx3.blue-canoe.net
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mx3.blue-canoe.net
Alternative Names
  • mx3.blue-canoe.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-09-07
Not valid after
2026-12-06
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
F1:55:1C:6B:F9:D0:CC:7B:88:5B:8E:DE:68:FF:15:D4:60:DA:B1:0E:88:98:5D:E9:69:67:A9:EC:10:FA:B2:58
SHA1
2E:FD:C8:B2:EB:A4:6F:1C:CC:C3:73:22:8A:73:7A:EE:73:05:1A:19
X509v3 extensions
subjectKeyIdentifier
  • BF:87:D7:B5:B0:18:91:4A:00:54:D1:EE:F7:56:21:BF:72:C3:F5:71
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/8.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D8:09:55:3B:94:4F:7A:FF:C8:16:19:6F:94:4F:85:AB:
  • B0:F8:FC:5E:87:55:26:0F:15:D1:2E:72:BB:45:4B:14
  • Timestamp : Sep 7 17:52:36.804 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:F9:68:88:19:FE:85:96:E8:51:51:61:
  • 11:3F:9C:21:D4:63:C3:28:0D:D0:E8:0C:CF:50:6A:D7:
  • B6:EA:95:73:2F:02:21:00:B5:4B:B2:A8:3C:32:04:D0:
  • 17:A6:24:8D:E9:96:8B:1D:E2:85:64:23:C6:CA:21:93:
  • 97:51:74:79:8B:AB:4E:B8
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Sep 7 17:52:37.539 2026 GMT
  • Extensions: 00:00:05:00:3D:AA:74:8D
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:0E:64:1A:08:48:53:0A:9C:3A:10:69:4D:
  • DC:40:26:98:BC:90:37:0F:26:27:CF:5A:1C:0D:97:78:
  • 46:59:10:68:02:21:00:F5:AF:97:14:18:8A:B7:94:14:
  • 2B:BD:31:69:84:7F:A3:64:7A:2D:8E:70:22:A9:61:AF:
  • E6:16:FD:24:A3:B2:15
First seen at:

CN=mail.blue-canoe.net

Certificate chain
  • mail.blue-canoe.net
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail.blue-canoe.net
Alternative Names
  • mail.blue-canoe.net
  • mx1.blue-canoe.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-07-31
Not valid after
2026-10-29
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
F1:C3:68:A5:ED:42:32:23:34:15:28:AF:92:97:81:C4:4A:46:B0:12:FF:A1:D4:CC:C7:2D:D0:02:E4:A6:19:98
SHA1
89:E0:0C:64:62:35:18:B4:D7:80:AB:3F:8A:74:07:EA:FF:1C:8D:5C
X509v3 extensions
subjectKeyIdentifier
  • ED:34:86:E5:6D:20:1C:66:CC:3D:03:E9:FD:F9:82:6C:2C:37:20:49
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/38.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : CB:38:F7:15:89:7C:84:A1:44:5F:5B:C1:DD:FB:C9:6E:
  • F2:9A:59:CD:47:0A:69:05:85:B0:CB:14:C3:14:58:E7
  • Timestamp : Jul 31 14:44:59.087 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:38:50:EE:81:C5:28:14:EE:57:90:39:3E:
  • A2:28:45:9E:1C:5B:CD:DD:97:65:9E:AB:BD:9F:12:1B:
  • 21:B1:0C:93:02:20:39:5D:40:F4:E5:DD:04:38:75:F7:
  • 41:74:97:33:A1:C6:5B:D7:7C:5E:80:54:64:38:60:67:
  • BB:70:72:03:97:25
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6C:FE:50:19:43:A8:5E:A9:16:BC:52:D1:33:E4:DC:C9:
  • 1E:F1:41:1C:7D:25:84:20:D1:73:80:9E:18:18:EB:3A
  • Timestamp : Jul 31 14:44:59.993 2026 GMT
  • Extensions: 00:00:05:00:18:CA:BB:DA
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:28:29:E4:CE:3A:97:EB:79:18:09:64:71:
  • 13:F4:8D:CB:EF:4B:4E:58:0D:A5:60:F1:E4:B6:F6:EF:
  • 71:66:D7:91:02:20:6C:F1:D9:20:21:87:07:5F:9A:DF:
  • BD:BE:02:D5:76:15:4A:51:33:6B:BC:41:56:BD:26:7C:
  • 37:E6:55:1B:02:BF
First seen at:

CN=mx2.blue-canoe.net

Certificate chain
  • mx2.blue-canoe.net
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mx2.blue-canoe.net
Alternative Names
  • mx2.blue-canoe.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-09-07
Not valid after
2026-12-06
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
3A:65:71:BD:01:5E:17:93:27:A1:D3:C3:A0:A3:17:AA:0C:16:8B:27:CA:80:FB:40:FE:28:A6:3F:66:08:F4:9F
SHA1
BE:3D:A0:5F:63:50:7A:47:A4:7E:F4:63:CF:C7:80:0A:E8:07:92:AF
X509v3 extensions
subjectKeyIdentifier
  • E9:8F:11:5C:5B:B5:41:E8:72:9A:AD:F5:8C:DE:53:71:79:7F:EF:16
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/59.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D8:09:55:3B:94:4F:7A:FF:C8:16:19:6F:94:4F:85:AB:
  • B0:F8:FC:5E:87:55:26:0F:15:D1:2E:72:BB:45:4B:14
  • Timestamp : Sep 7 22:16:29.087 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:2F:57:EB:61:B0:81:A4:BE:96:C7:D6:1B:
  • 09:1E:3A:6A:20:C3:C5:1F:48:AE:59:FE:BA:8C:B5:9F:
  • 11:00:85:7F:02:20:53:DD:95:FB:AE:6E:50:85:F9:EB:
  • 09:D3:CC:61:3A:42:45:95:94:0D:05:20:D7:05:5E:F4:
  • A7:E8:4A:46:94:9B
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6C:FE:50:19:43:A8:5E:A9:16:BC:52:D1:33:E4:DC:C9:
  • 1E:F1:41:1C:7D:25:84:20:D1:73:80:9E:18:18:EB:3A
  • Timestamp : Sep 7 22:16:29.662 2026 GMT
  • Extensions: 00:00:05:00:2F:C7:63:F8
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:ED:26:A9:32:E8:A8:C9:8A:BA:37:4F:
  • 7E:A7:F1:90:65:93:B6:74:38:00:DE:E4:6A:91:81:57:
  • 5C:4E:F8:6D:EB:02:21:00:F1:9C:C2:0D:5B:01:DB:E1:
  • 83:F3:2D:19:42:E9:E0:CC:CA:A6:AE:00:77:F6:2D:CA:
  • CD:EF:34:2A:6D:D9:D6:21

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx3.blue-canoe.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx1.blue-canoe.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx2.blue-canoe.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid