SSL check results of hu-si.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for hu-si.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Thu, 20 Nov 2025 09:55:02 +0000

We can not guarantee a secure connection to the mailservers of hu-si.de!

Please contact the operator of hu-si.de and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/hu-si.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @hu-si.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.hu-si.de
2a03:4000:1a:8d::28
10
supported
mail.hu-si.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
7 s
mail.hu-si.de
185.162.249.28
10
supported
mail.hu-si.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mail2.hu-si.de
2a03:4000:27:4df::84
Results incomplete
50 not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
6 s
mail2.hu-si.de
185.244.193.84
50
supported
mail2.tincloud.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
3 s

Outgoing Mails

We have not received any emails from a @hu-si.de address so far. Test mail delivery

Certificates

First seen at:

CN=mail.hu-si.de

Certificate chain
  • mail.hu-si.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption

      • R13
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mail.hu-si.de
Alternative Names
  • autoconfig.hu-si.de
  • autodiscover.hu-si.de
  • imap.hu-si.de
  • mail.hu-si.de
  • pop3.hu-si.de
  • smtp.hu-si.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R13
validity period
Not valid before
2025-11-17
Not valid after
2026-02-15
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
BF:4B:BD:F4:D6:0C:0C:A0:E4:F7:34:4D:70:34:67:EC:AE:FA:DD:A4:98:78:39:54:4F:FF:43:5B:CD:23:35:BD
SHA1
14:AF:7C:EB:74:29:B0:F5:1D:97:E3:60:F5:48:1B:D1:8F:17:D8:D1
X509v3 extensions
subjectKeyIdentifier
  • 9A:19:79:69:43:CC:CB:EA:4B:FB:64:31:DD:7D:6D:1B:98:C5:12:4B
authorityKeyIdentifier
  • keyid:E7:AB:9F:0F:2C:33:A0:53:D3:5E:4F:78:C8:B2:84:0E:3B:D6:92:33
authorityInfoAccess
  • CA Issuers - URI:http://r13.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r13.c.lencr.org/21.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : CB:38:F7:15:89:7C:84:A1:44:5F:5B:C1:DD:FB:C9:6E:
  • F2:9A:59:CD:47:0A:69:05:85:B0:CB:14:C3:14:58:E7
  • Timestamp : Nov 17 13:07:29.066 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:98:69:26:2C:1E:D7:2E:3A:F1:61:DD:
  • 5E:36:3C:1D:6C:A8:FB:4D:FF:E2:82:B4:F2:7F:57:A7:
  • 8A:88:E1:97:17:02:20:42:9E:27:9C:BB:BC:B3:EB:78:
  • 18:D9:D9:17:D1:65:B1:5A:9A:96:5C:8F:1E:10:F5:8D:
  • 4A:CC:3B:F6:AB:27:07
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:
  • E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6
  • Timestamp : Nov 17 13:07:29.121 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:74:43:15:E2:0D:3A:19:5E:63:5A:52:6E:
  • 1A:4C:0D:B6:DA:EB:A3:97:27:BA:88:E2:FB:D2:78:67:
  • 31:0B:27:D3:02:21:00:82:0F:01:47:1D:C9:54:E8:8F:
  • FA:2C:05:5E:45:CF:CB:03:06:C3:E0:AD:1C:C6:B0:12:
  • EF:37:9A:48:B2:08:0C
First seen at:

CN=mail2.tincloud.de

Certificate chain
  • mail2.tincloud.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption
    • Expired

      • R10
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mail2.tincloud.de
Alternative Names
  • mail2.hu-si.de
  • mail2.tincloud.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R10
validity period
Not valid before
2025-08-19
Not valid after
2025-11-17
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
C5:16:89:F4:F0:68:1C:D0:26:CB:70:E7:8F:97:BB:00:61:52:E0:DA:7C:E4:24:44:2A:21:92:0B:3D:F8:D9:3F
SHA1
5B:A5:BE:0C:43:36:38:D3:FE:AF:45:EB:58:0B:CB:F7:C6:1A:62:C7
X509v3 extensions
subjectKeyIdentifier
  • 56:DC:12:B3:08:FF:54:55:FA:08:B5:D5:AD:F7:D1:D1:6A:EF:80:0E
authorityKeyIdentifier
  • keyid:BB:BC:C3:47:A5:E4:BC:A9:C6:C3:A4:72:0C:10:8D:A2:35:E1:C8:E8
authorityInfoAccess
  • CA Issuers - URI:http://r10.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r10.c.lencr.org/78.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8:
  • 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A
  • Timestamp : Aug 20 00:25:50.138 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:FE:A5:D6:7B:50:BF:31:1C:A2:88:4E:
  • D7:93:46:DF:EB:8D:69:56:17:6B:D5:64:D4:13:CE:1F:
  • 07:38:10:07:DA:02:21:00:99:F3:9E:A5:FD:9B:0E:5B:
  • E1:C3:32:5A:B2:74:04:F6:A4:FE:30:07:7E:CC:19:72:
  • C7:14:F4:97:1A:41:F6:09
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A4:42:C5:06:49:60:61:54:8F:0F:D4:EA:9C:FB:7A:2D:
  • 26:45:4D:87:A9:7F:2F:DF:45:59:F6:27:4F:3A:84:54
  • Timestamp : Aug 20 00:25:54.067 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:3B:3D:8A:B1:43:79:EA:7F:46:31:59:CB:
  • 48:0D:26:DB:CB:0D:09:CB:5D:14:41:1C:4E:57:C3:6C:
  • 55:B6:D0:DD:02:20:78:48:CC:72:89:87:7F:AD:83:7A:
  • 44:1F:AD:E6:CE:F0:AA:6E:79:B2:D2:F5:5B:C5:71:55:
  • 66:92:EF:13:A8:09

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail.hu-si.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail2.hu-si.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid