SSL check results of dfps.state.tx.us

NEW You can also bulk check multiple servers.

Discover if the mail servers for dfps.state.tx.us can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 25 May 2020 15:50:44 +0000

The mailservers of dfps.state.tx.us can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @dfps.state.tx.us addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mxvip01-esa.hhs.state.tx.us
168.40.202.62
30
supported
mxvip01-esa.hhs.state.tx.us
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
19 s
esa04mx.hhs.state.tx.us
168.40.200.38
Results incomplete
40 not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
7 s
esa01mx.hhs.state.tx.us
168.40.200.35
40
supported
mxvip01-esa.hhs.state.tx.us
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
18 s
esa06mx.hhs.state.tx.us
168.40.200.40
40
supported
mxvip01-esa.hhs.state.tx.us
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
20 s
esa02mx.hhs.state.tx.us
168.40.200.36
40
supported
mxvip01-esa.hhs.state.tx.us
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
20 s
esa05mx.hhs.state.tx.us
168.40.200.39
40
supported
mxvip01-esa.hhs.state.tx.us
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
19 s
esa03mx.hhs.state.tx.us
168.40.200.37
40
supported
mxvip01-esa.hhs.state.tx.us
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
19 s

Outgoing Mails

We have not received any emails from a @dfps.state.tx.us address so far. Test mail delivery

Certificates

First seen at:

CN=mxvip01-esa.hhs.state.tx.us,OU=IT HHS Network Support Services,O=Tx Health & Human Services Commission,L=Austin,ST=Texas,C=US

Certificate chain
Subject
Country (C)
  • US
State (ST)
  • Texas
Locality (L)
  • Austin
Organization (O)
  • Tx Health & Human Services Commission
Organizational Unit (OU)
  • IT HHS Network Support Services
Common Name (CN)
  • mxvip01-esa.hhs.state.tx.us
Alternative Names
  • esa01mx.hhs.state.tx.us
  • esa02mx.hhs.state.tx.us
  • esa03mx.hhs.state.tx.us
  • esa04mx.hhs.state.tx.us
  • esa05mx.hhs.state.tx.us
  • esa06mx.hhs.state.tx.us
  • mxvip01-esa.hhs.state.tx.us
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Common Name (CN)
  • DigiCert SHA2 Secure Server CA
validity period
Not valid before
2018-02-05
Not valid after
2021-02-05
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
AF:94:61:4D:6F:87:5C:0D:24:0F:DA:D6:14:DF:7A:E8:BA:84:90:13:13:1A:B5:45:E9:8C:70:F9:26:A1:36:5B
SHA1
7F:97:25:02:5E:C9:C0:E9:35:E7:46:63:F0:36:E2:B1:42:A9:E7:58
X509v3 extensions
authorityKeyIdentifier
  • keyid:0F:80:61:1C:82:31:61:D5:2F:28:E7:8D:46:38:B4:2C:E1:C6:D9:E2
subjectKeyIdentifier
  • A2:2D:E7:BB:51:29:86:73:4C:B5:DD:10:93:5A:35:95:3B:39:E7:C3
crlDistributionPoints
  • Full Name:
  • URI:http://crl3.digicert.com/ssca-sha2-g6.crl
  • Full Name:
  • URI:http://crl4.digicert.com/ssca-sha2-g6.crl
certificatePolicies
  • Policy: 2.16.840.1.114412.1.1
  • CPS: https://www.digicert.com/CPS
  • Policy: 2.23.140.1.2.2
authorityInfoAccess
  • OCSP - URI:http://ocsp.digicert.com
  • CA Issuers - URI:http://cacerts.digicert.com/DigiCertSHA2SecureServerCA.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A4:B9:09:90:B4:18:58:14:87:BB:13:A2:CC:67:70:0A:
  • 3C:35:98:04:F9:1B:DF:B8:E3:77:CD:0E:C8:0D:DC:10
  • Timestamp : Feb 5 19:04:52.463 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:3B:80:5D:77:48:12:D3:E7:4F:0C:84:7E:
  • 84:D0:4B:02:64:91:7D:DE:16:8F:96:35:77:F0:3A:03:
  • 1B:16:92:6D:02:20:4C:A2:2D:AA:9F:DF:40:EA:46:EA:
  • 3D:E0:56:28:A3:10:01:48:58:10:7F:2F:1A:1E:9E:35:
  • FA:AD:C6:C6:58:84
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 87:75:BF:E7:59:7C:F8:8C:43:99:5F:BD:F3:6E:FF:56:
  • 8D:47:56:36:FF:4A:B5:60:C1:B4:EA:FF:5E:A0:83:0F
  • Timestamp : Feb 5 19:04:52.640 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:11:89:49:78:C0:CA:AA:32:53:B5:37:5C:
  • 1B:3D:22:2C:78:54:76:71:5A:2E:F3:50:7A:D2:E6:F6:
  • 52:A3:35:6F:02:20:3E:2A:F3:4A:E1:29:02:28:72:8F:
  • AB:AF:78:8E:13:71:F3:5B:8A:E6:BE:DF:1A:98:99:CD:
  • 7B:C0:2A:51:19:D0
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : BB:D9:DF:BC:1F:8A:71:B5:93:94:23:97:AA:92:7B:47:
  • 38:57:95:0A:AB:52:E8:1A:90:96:64:36:8E:1E:D1:85
  • Timestamp : Feb 5 19:04:52.531 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:6D:05:4D:15:25:3A:ED:16:A0:E1:16:48:
  • A8:B5:79:39:81:6E:A7:53:35:66:59:00:CA:CD:E0:33:
  • 2C:C2:AE:29:02:20:3B:65:46:70:AC:53:EE:9B:3C:14:
  • 80:0B:58:48:82:0D:B2:A5:7D:27:D9:83:1A:5F:05:4C:
  • 92:8A:44:03:C7:98
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6F:53:76:AC:31:F0:31:19:D8:99:00:A4:51:15:FF:77:
  • 15:1C:11:D9:02:C1:00:29:06:8D:B2:08:9A:37:D9:13
  • Timestamp : Feb 5 19:04:53.165 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:7E:C4:AF:09:F0:A0:2D:0C:7C:AE:B6:DD:
  • 01:7A:53:27:E0:6F:94:39:6B:C7:B2:D5:71:73:73:4B:
  • 85:2D:F6:F8:02:20:3A:1E:A1:3D:2F:ED:53:37:8F:02:
  • E0:75:E5:E9:DD:E5:D0:D5:0F:EB:79:F4:68:E2:16:F4:
  • 05:53:30:85:16:9A