SSL check results of defend2.org

NEW You can also bulk check multiple servers.

Discover if the mail servers for defend2.org can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sun, 05 Jul 2026 19:23:02 +0000

The mailservers of defend2.org can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @defend2.org addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx-1.defend2.org
96.246.224.30
0
supported
*.defend2.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
5 s

Outgoing Mails

We have received emails from these servers with @defend2.org sender addresses. Test mail delivery

Host TLS Version & Cipher
mx-1.defend2.org (96.246.224.30)
TLSv1.3 TLS_AES_256_GCM_SHA384
mta7.srv.hcvlny.cv.net (167.206.4.202)
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
mta2.srv.hcvlny.cv.net (167.206.4.197)
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256

Certificates

First seen at:

CN=*.defend2.org

Certificate chain
  • *.defend2.org
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption

      • R13
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • *.defend2.org
Alternative Names
  • *.defend2.org
  • defend2.org
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R13
validity period
Not valid before
2026-05-14
Not valid after
2026-08-12
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
Fingerprints
SHA256
DE:16:4F:13:02:08:E2:22:43:63:05:00:DD:A4:46:D5:EB:78:41:C0:A0:6A:83:0B:C8:FD:EB:D6:27:7D:D9:24
SHA1
80:F0:C5:B5:DB:66:CC:54:27:A6:7A:5E:0A:56:B0:55:8F:32:20:5F
X509v3 extensions
subjectKeyIdentifier
  • 71:77:6B:89:3D:76:62:A1:5E:7E:DD:38:0D:EB:D5:9A:93:18:CD:BA
authorityKeyIdentifier
  • keyid:E7:AB:9F:0F:2C:33:A0:53:D3:5E:4F:78:C8:B2:84:0E:3B:D6:92:33
authorityInfoAccess
  • CA Issuers - URI:http://r13.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r13.c.lencr.org/54.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : May 14 23:31:22.942 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:3C:E4:84:5D:98:F2:40:DC:0B:3B:A1:6F:
  • B6:41:D6:88:43:18:50:A4:23:C2:91:DA:67:27:B4:1F:
  • EA:4F:AF:05:02:20:3B:BF:AC:07:E3:92:44:DD:A8:A7:
  • D4:FC:A0:46:92:77:A1:1D:95:0F:7F:4C:03:0A:75:F1:
  • 91:5F:B6:74:4E:46
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : May 14 23:31:23.700 2026 GMT
  • Extensions: 00:00:05:00:12:D2:03:58
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:8E:06:4A:5C:04:02:DC:F1:4A:E9:EC:
  • 4E:8E:1C:85:99:C3:AC:11:9C:01:AA:5E:59:EA:A1:2B:
  • B5:C0:4F:0A:BE:02:20:39:7B:F9:44:57:C8:57:EC:72:
  • 2E:21:5B:28:0B:D6:18:E4:BA:91:C2:99:65:91:39:06:
  • 60:85:DE:E7:9D:FA:C0

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx-1.defend2.org
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid