SSL check results of jugendsuenden.info

NEW You can also bulk check multiple servers.

Discover if the mail servers for jugendsuenden.info can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 22 Aug 2026 16:48:50 +0000

The mailservers of jugendsuenden.info can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @jugendsuenden.info addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.big-black.de
2003:a:310:8b00::91
10
supported
mail.big-black.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
3 s
mail.big-black.de
87.128.16.155
10
supported
mail.big-black.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
3 s
mail2.big-black.de
2001:41d0:1008:30a4::1
20
supported
mail2.big-black.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mail2.big-black.de
137.74.206.164
20
supported
mail2.big-black.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @jugendsuenden.info address so far. Test mail delivery

Certificates

First seen at:

CN=mail2.big-black.de

Certificate chain
  • mail2.big-black.de
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail2.big-black.de
Alternative Names
  • mail2.big-black.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-07-19
Not valid after
2026-10-17
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
7D:B9:56:6E:AC:E0:12:4A:B3:89:93:99:B2:70:66:F5:45:AD:15:B1:58:55:E3:7C:83:7F:2D:F6:36:53:55:BE
SHA1
66:43:F9:AF:BA:60:A5:CF:E1:69:F1:48:3B:0D:3D:CD:A7:96:A9:25
X509v3 extensions
subjectKeyIdentifier
  • 35:FE:4D:3D:55:20:47:BC:3E:84:94:0F:D8:FF:63:3A:79:9D:55:BE
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/56.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : Jul 19 14:41:05.531 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:EA:18:BA:1A:1E:6C:15:3E:DA:4E:2C:
  • 9C:E9:A0:76:26:4A:A7:E2:42:65:D9:F3:89:00:DA:E1:
  • 62:3E:6E:2A:CA:02:21:00:85:CD:04:DC:79:37:11:CC:
  • 38:19:82:B7:B0:8B:91:A3:2D:0B:AE:8D:F9:4A:EE:BD:
  • D3:32:F4:68:9A:3A:1C:6E
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 46:AF:86:3D:3B:3E:E5:9F:A5:77:DE:A8:24:5D:36:B0:
  • D9:ED:22:A2:23:F4:61:77:41:22:94:52:EE:95:50:5F
  • Timestamp : Jul 19 14:41:05.644 2026 GMT
  • Extensions: 00:00:05:00:0D:A1:87:25
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:33:0E:69:B4:2F:F8:AE:1A:7C:3B:83:0C:
  • 61:D0:5D:1C:E4:5C:62:DA:95:C3:15:5E:3D:A6:E9:0F:
  • F7:93:CA:08:02:21:00:A1:66:1D:42:9A:D7:9C:36:6C:
  • F0:0A:C8:7F:44:12:BB:70:E4:F2:E5:C7:67:32:E6:D2:
  • 41:E9:FA:E6:B3:31:C4
First seen at:

CN=mail.big-black.de

Certificate chain
  • mail.big-black.de
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail.big-black.de
Alternative Names
  • autoconfig.big-black.de
  • autodiscover.big-black.de
  • mail.big-black.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-08-08
Not valid after
2026-11-06
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
CD:5B:BC:21:16:B1:B7:4A:F8:BE:C3:71:E8:9B:BF:C5:6E:5A:BD:5B:53:66:96:81:60:41:B8:8F:63:03:A7:C6
SHA1
EA:E6:46:DA:AD:B6:C5:A9:EF:F9:83:9C:D0:90:A9:CB:CA:DB:8C:58
X509v3 extensions
subjectKeyIdentifier
  • 0E:D5:8F:56:DB:3E:E2:77:B3:D3:F5:64:FB:3D:1A:47:4D:DE:2F:37
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/110.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Aug 8 01:49:08.183 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:F0:42:E3:DB:E7:87:0F:8C:B5:D9:3F:
  • 26:0C:7C:81:1C:2E:F7:02:1D:AF:64:8D:B6:E1:41:E5:
  • CE:44:4A:C9:41:02:21:00:D4:3A:FC:DA:A8:AA:69:44:
  • 6E:EE:64:EC:4E:EF:3F:6F:09:33:9C:5E:BE:0C:CF:47:
  • 92:74:FA:F5:99:1D:4E:32
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Aug 8 01:49:08.986 2026 GMT
  • Extensions: 00:00:05:00:32:79:3D:55
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:20:DB:22:27:5B:89:CC:03:D8:63:1C:87:
  • 58:2F:47:32:9A:63:30:C7:3D:0A:BA:EB:97:15:B0:48:
  • D3:A6:2D:29:02:20:1B:F9:21:13:F6:87:FA:35:1C:7C:
  • 7F:17:D2:FF:E6:4B:60:09:20:6C:68:F4:D9:73:10:26:
  • 6F:07:D8:EC:CE:72

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail2.big-black.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail.big-black.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
error
Debug
valid