SSL check results of joergheber.org

NEW You can also bulk check multiple servers.

Discover if the mail servers for joergheber.org can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 26 Sep 2026 00:30:14 +0000

The mailservers of joergheber.org can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @joergheber.org addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
noether.joergheber.org
2600:3c01:e000:aa4::1
10
supported
noether.joergheber.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s
noether.joergheber.org
74.207.241.121
10
supported
noether.joergheber.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s
curie.joergheber.org
2a01:7e03:e001:b2::1
20
supported
curie.joergheber.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s
curie.joergheber.org
172.233.154.228
20
supported
curie.joergheber.org
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s

Outgoing Mails

We have not received any emails from a @joergheber.org address so far. Test mail delivery

Certificates

First seen at:

CN=curie.joergheber.org

Certificate chain
  • curie.joergheber.org
    • remaining
    • 384 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • curie.joergheber.org
Alternative Names
  • curie.joergheber.org
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-09-23
Not valid after
2026-12-22
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
48:B5:48:84:0E:F1:65:57:28:11:89:58:D6:6D:1F:AC:CE:41:C8:61:77:98:E6:F3:F4:DF:BC:27:5B:39:D5:60
SHA1
26:0E:1B:80:46:59:FD:D6:B2:7B:24:D6:B1:AA:CA:58:40:23:B9:04
X509v3 extensions
subjectKeyIdentifier
  • C7:F0:0E:ED:BA:D8:8A:ED:33:20:6F:23:A6:91:08:20:92:78:B2:0B
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/71.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D8:09:55:3B:94:4F:7A:FF:C8:16:19:6F:94:4F:85:AB:
  • B0:F8:FC:5E:87:55:26:0F:15:D1:2E:72:BB:45:4B:14
  • Timestamp : Sep 23 17:07:57.332 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:2A:A7:44:99:EE:1A:B8:91:DC:E1:3B:00:
  • 76:D6:4C:4E:55:BC:3D:C3:4D:7E:3F:A4:1A:D5:B2:CA:
  • 48:38:D9:F3:02:20:48:B7:EF:C5:B9:2C:58:31:30:0D:
  • 6D:39:1F:99:37:A1:AF:50:87:9E:4F:E9:C3:02:A9:67:
  • E6:EC:A1:9A:28:C7
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 8E:CA:47:0B:AC:DE:6A:F3:A2:06:B0:A4:7A:84:B7:46:
  • FE:1F:C6:BF:95:3E:25:E6:9B:4E:E4:02:48:F3:C6:E8
  • Timestamp : Sep 23 17:07:57.861 2026 GMT
  • Extensions: 00:00:05:00:13:56:6C:96
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:6B:82:5A:5E:95:85:D3:A1:EA:E0:2F:DF:
  • DE:6E:8E:0B:09:47:BE:EE:65:70:65:BA:39:45:7C:41:
  • 06:BA:58:6D:02:21:00:C4:D8:69:22:F2:80:90:93:4C:
  • 48:F6:8E:4A:6F:9A:5E:81:0A:A2:F7:F9:64:BB:07:CD:
  • 3C:51:B1:01:83:AB:98
First seen at:

CN=noether.joergheber.org

Certificate chain
  • noether.joergheber.org
    • remaining
    • 384 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • noether.joergheber.org
Alternative Names
  • noether.joergheber.org
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-09-23
Not valid after
2026-12-22
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
E7:85:97:6F:E6:F5:2E:DA:B8:BD:21:BC:A0:F5:67:CE:BC:BA:47:EE:0A:A2:63:EB:C6:37:06:5C:7C:10:8B:02
SHA1
06:2B:16:05:A8:E5:00:13:8B:90:CA:52:D2:EB:53:F1:29:B4:A5:28
X509v3 extensions
subjectKeyIdentifier
  • 62:6F:19:BA:7A:94:53:8B:1C:C9:04:88:38:47:82:B1:D3:79:61:95
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/93.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 26:E3:64:6E:58:69:21:23:BC:34:3F:47:24:35:9B:37:
  • 92:CD:24:5A:88:D8:15:D3:93:33:FD:99:18:AB:47:23
  • Timestamp : Sep 23 16:33:20.282 2026 GMT
  • Extensions: 00:00:05:00:45:8B:7B:4B
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:C3:3A:49:44:30:48:DB:FB:25:20:DD:
  • 9A:B6:F0:2E:1F:E9:12:B7:BA:16:70:2C:75:CD:67:07:
  • 7B:26:BD:8A:C3:02:21:00:EC:8A:CE:3A:E7:62:E0:95:
  • FB:E9:1C:49:72:D9:3A:E0:DB:B6:B5:83:58:D2:79:BB:
  • 86:81:90:01:A1:EA:A7:8C
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Sep 23 16:33:26.722 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:06:39:53:EE:39:E1:38:97:9B:30:1D:2D:
  • 5A:26:CE:F9:1B:C0:6F:E5:44:02:BE:B1:F3:C9:48:2D:
  • E3:66:4B:63:02:20:43:92:FC:04:01:0C:C1:E7:CA:18:
  • 51:2E:C9:DB:A3:64:64:EE:36:BA:78:DA:80:F4:0B:21:
  • 58:E5:6E:A9:B2:DE

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.curie.joergheber.org
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.noether.joergheber.org
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid