SSL check results of kassel.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for kassel.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 06 Dec 2019 14:17:21 +0000

We can not guarantee a secure connection to the mailservers of kassel.de!

Please contact the operator of kassel.de and ask him or her to solve this problem. This result stays accessible under the following address:

https://ssl-tools.net/mailservers/kassel.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @kassel.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.stadt-kassel.de
80.69.207.8
10
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail2.stadt-kassel.de
80.69.207.7
20
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail.kassel.de
45.138.56.8
30
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail3.stadt-kassel.de
46.252.134.74
Results incomplete
40 not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
mail4.stadt-kassel.de
80.69.207.11
50
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @kassel.de address so far. Test mail delivery

Certificates

First seen at:

CN=*.stadt-kassel.de,OU=Informationstechnologie,O=Stadt Kassel,L=Kassel,ST=Hessen,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Hessen
Locality (L)
  • Kassel
Organization (O)
  • Stadt Kassel
Organizational Unit (OU)
  • Informationstechnologie
Common Name (CN)
  • *.stadt-kassel.de
Alternative Names
  • *.stadt-kassel.de
  • stadt-kassel.de
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Organizational Unit (OU)
  • www.digicert.com
Common Name (CN)
  • GeoTrust TLS RSA CA G1
validity period
Not valid before
2018-03-07
Not valid after
2020-06-09
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
25:F6:5D:3B:60:EF:E1:4D:88:38:63:9E:15:03:3D:A4:9D:54:CE:70:A8:79:1A:35:E4:25:2E:2B:1F:78:75:79
SHA1
56:68:C2:C9:2D:EE:3E:4B:A7:70:20:33:CD:A5:53:4B:0A:6A:FC:66
X509v3 extensions
authorityKeyIdentifier
  • keyid:94:4F:D4:5D:8B:E4:A4:E2:A6:80:FE:FD:D8:F9:00:EF:A3:BE:02:57
subjectKeyIdentifier
  • 97:40:6B:2C:1D:4C:C3:7F:09:47:4F:5C:C4:EA:F0:91:08:04:99:57
crlDistributionPoints
  • Full Name:
  • URI:http://cdp.geotrust.com/GeoTrustTLSRSACAG1.crl
certificatePolicies
  • Policy: 2.16.840.1.114412.1.1
  • CPS: https://www.digicert.com/CPS
  • Policy: 2.23.140.1.2.2
authorityInfoAccess
  • OCSP - URI:http://status.geotrust.com
  • CA Issuers - URI:http://cacerts.geotrust.com/GeoTrustTLSRSACAG1.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A4:B9:09:90:B4:18:58:14:87:BB:13:A2:CC:67:70:0A:
  • 3C:35:98:04:F9:1B:DF:B8:E3:77:CD:0E:C8:0D:DC:10
  • Timestamp : Mar 7 07:38:06.006 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:50:01:05:B6:B7:6D:7F:D0:1A:E0:A4:C9:
  • D8:92:B0:42:B4:59:8B:5B:4E:99:9A:8C:6B:49:23:22:
  • 54:66:3E:2E:02:20:7A:80:B7:E0:B8:1B:06:E9:6E:CF:
  • 6B:82:42:52:40:EC:13:37:88:BB:58:B6:B5:65:18:BC:
  • 7E:68:26:47:F4:05
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6F:53:76:AC:31:F0:31:19:D8:99:00:A4:51:15:FF:77:
  • 15:1C:11:D9:02:C1:00:29:06:8D:B2:08:9A:37:D9:13
  • Timestamp : Mar 7 07:38:06.379 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:5D:1A:96:35:6C:18:62:B8:FD:B0:40:1E:
  • A9:5C:AC:61:44:FD:57:B7:42:AC:5B:D8:24:28:BB:CE:
  • D3:D2:2F:4E:02:20:1F:B3:EC:17:85:95:C3:5F:CE:D8:
  • F3:56:79:EC:B5:33:9D:79:41:23:CE:77:4C:AC:52:AF:
  • 71:C7:13:89:62:D9
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : BB:D9:DF:BC:1F:8A:71:B5:93:94:23:97:AA:92:7B:47:
  • 38:57:95:0A:AB:52:E8:1A:90:96:64:36:8E:1E:D1:85
  • Timestamp : Mar 7 07:38:06.187 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:53:FA:96:33:C9:9A:8D:DE:EC:A7:60:C7:
  • F2:91:B3:C2:92:C0:A7:70:BB:CB:7B:F2:4E:32:3E:3A:
  • 89:70:4C:D2:02:21:00:B5:98:33:25:8C:40:0F:5B:C0:
  • 04:C8:ED:0F:BE:67:C3:C9:9A:C5:FF:70:AD:22:24:EA:
  • D8:EE:94:0A:8D:FC:AA
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 55:81:D4:C2:16:90:36:01:4A:EA:0B:9B:57:3C:53:F0:
  • C0:E4:38:78:70:25:08:17:2F:A3:AA:1D:07:13:D3:0C
  • Timestamp : Mar 7 07:38:06.663 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:0C:C7:42:75:48:5B:EF:18:59:66:C4:11:
  • 62:00:A6:D2:18:04:84:7F:F6:86:15:E2:44:2C:3F:43:
  • E8:34:A1:73:02:20:3A:8A:A0:ED:BF:C7:03:03:2B:39:
  • 33:A6:3C:C9:74:F5:70:36:5A:02:B7:CC:55:5D:4C:03:
  • A8:83:B1:AB:4F:44