SSL check results of defense.tn

NEW You can also bulk check multiple servers.

Discover if the mail servers for defense.tn can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 14 Aug 2026 00:30:19 +0000

We can not guarantee a secure connection to the mailservers of defense.tn!

Please contact the operator of defense.tn and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/defense.tn

Servers

Incoming Mails

These servers are responsible for incoming mails to @defense.tn addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
ksmg.defense.tn
196.203.86.7
10
supported
ksmg.defense.tn
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
supported
  • SSL_RSA_WITH_RC4_128_SHA
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
18 s
mail.defense.tn
196.203.86.28
Results incomplete
20
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
7 s
mx1defense.ingw.tn
193.95.97.75
40
supported
FortiMail
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
supported
  • SSL_RSA_WITH_RC4_128_SHA
  • SSL_RSA_EXPORT_WITH_RC4_40_MD5
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
13 s
mx2defense.ingw.tn
196.203.249.75
50
supported
FortiMail
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
supported
  • SSL_RSA_WITH_RC4_128_SHA
  • SSL_RSA_EXPORT_WITH_RC4_40_MD5
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
14 s

Outgoing Mails

We have not received any emails from a @defense.tn address so far. Test mail delivery

Certificates

First seen at:

CN=ksmg.defense.tn

Certificate chain
  • ksmg.defense.tn (Certificate is self-signed.)
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption
    • Expired
    • Unknown Authority

Subject
Common Name (CN)
  • ksmg.defense.tn
Issuer

Certificate is self-signed.

validity period
Not valid before
2022-02-01
Not valid after
2024-02-01
Fingerprints
SHA256
20:3D:05:9B:48:B5:EF:D8:F9:62:55:BC:32:F1:51:40:B3:43:2C:C2:67:5F:73:4F:86:50:78:02:24:51:53:83
SHA1
68:AC:65:F5:A8:4C:2C:19:8B:E9:49:34:A5:14:A2:8E:FB:10:92:C4
First seen at:

emailAddress=support@fortinet.com,CN=FortiMail,OU=FortiMail,O=Fortinet,L=Sunnyvale,ST=California,C=US

Certificate chain
  • FortiMail
    • remaining
    • 2048 bit
    • sha1WithRSAEncryption
    • Hostname Mismatch

      • support (Certificate is self-signed.)
        • remaining
        • 2048 bit
        • sha1WithRSAEncryption
        • Unknown Authority

Subject
Country (C)
  • US
State (ST)
  • California
Locality (L)
  • Sunnyvale
Organization (O)
  • Fortinet
Organizational Unit (OU)
  • FortiMail
Common Name (CN)
  • FortiMail
Email
  • support@fortinet.com
Issuer
Country (C)
  • US
State (ST)
  • California
Locality (L)
  • Sunnyvale
Organization (O)
  • Fortinet
Organizational Unit (OU)
  • Certificate Authority
Common Name (CN)
  • support
Email
  • support@fortinet.com
validity period
Not valid before
2010-11-18
Not valid after
2038-01-19
Fingerprints
SHA256
5F:50:80:BD:E2:B9:61:59:C9:96:0B:1C:1C:9E:F1:1A:A8:94:D6:41:A9:07:73:74:D0:6A:DB:91:81:AE:F3:06
SHA1
CF:33:F0:CA:C6:AB:7B:9A:1B:C2:15:10:3C:33:95:B0:EE:54:D6:AB