SSL check results of kassel.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for kassel.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 25 May 2020 17:07:02 +0000

We can not guarantee a secure connection to the mailservers of kassel.de!

Please contact the operator of kassel.de and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/kassel.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @kassel.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.stadt-kassel.de
80.69.207.8
10
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail2.stadt-kassel.de
80.69.207.7
20
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail.kassel.de
45.138.56.8
30
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail3.stadt-kassel.de
46.252.134.74
Results incomplete
40 not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
mail4.stadt-kassel.de
80.69.207.11
50
supported
*.stadt-kassel.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @kassel.de address so far. Test mail delivery

Certificates

First seen at:

CN=*.stadt-kassel.de,O=Stadt Kassel,L=Kassel,ST=Hessen,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Hessen
Locality (L)
  • Kassel
Organization (O)
  • Stadt Kassel
Common Name (CN)
  • *.stadt-kassel.de
Alternative Names
  • *.stadt-kassel.de
  • stadt-kassel.de
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Organizational Unit (OU)
  • www.digicert.com
Common Name (CN)
  • GeoTrust TLS RSA CA G1
validity period
Not valid before
2020-05-04
Not valid after
2022-06-08
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
8C:91:73:F7:23:D6:A8:E5:E8:F2:F2:6F:5F:C2:44:72:C6:73:CF:98:6F:1E:91:50:5E:39:2D:68:30:58:89:19
SHA1
71:C9:9D:F4:F9:68:2C:33:E8:82:E6:F7:D8:86:0D:A7:B2:26:06:77
X509v3 extensions
authorityKeyIdentifier
  • keyid:94:4F:D4:5D:8B:E4:A4:E2:A6:80:FE:FD:D8:F9:00:EF:A3:BE:02:57
subjectKeyIdentifier
  • B2:31:43:7E:8E:2D:4A:B5:0F:C8:20:DE:0E:E2:D1:31:39:2E:61:0D
crlDistributionPoints
  • Full Name:
  • URI:http://cdp.geotrust.com/GeoTrustTLSRSACAG1.crl
certificatePolicies
  • Policy: 2.16.840.1.114412.1.1
  • CPS: https://www.digicert.com/CPS
  • Policy: 2.23.140.1.2.2
authorityInfoAccess
  • OCSP - URI:http://status.geotrust.com
  • CA Issuers - URI:http://cacerts.geotrust.com/GeoTrustTLSRSACAG1.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 29:79:BE:F0:9E:39:39:21:F0:56:73:9F:63:A5:77:E5:
  • BE:57:7D:9C:60:0A:F8:F9:4D:5D:26:5C:25:5D:C7:84
  • Timestamp : May 4 14:15:04.711 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:EE:49:0D:5C:29:F6:6F:AB:8F:8F:91:
  • 6F:DC:F5:83:47:20:18:8A:DC:90:55:25:2A:C5:EC:23:
  • 5B:D6:57:76:C9:02:20:57:24:14:27:B5:68:D2:06:6F:
  • B0:C2:07:41:69:43:7D:D5:1B:1D:2A:CF:A2:E3:25:E8:
  • B0:70:E6:CB:6B:BB:12
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 22:45:45:07:59:55:24:56:96:3F:A1:2F:F1:F7:6D:86:
  • E0:23:26:63:AD:C0:4B:7F:5D:C6:83:5C:6E:E2:0F:02
  • Timestamp : May 4 14:15:04.718 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:6A:3E:E4:DD:28:A3:0F:77:6B:77:36:DF:
  • D0:7B:40:D3:55:01:17:C4:D4:1E:AB:43:B9:1A:D2:97:
  • C0:F5:36:7C:02:20:2B:F4:D2:D2:61:09:D5:C9:86:7D:
  • 3B:AA:63:85:02:63:4B:41:8E:62:EE:25:CD:23:1B:9F:
  • 06:CE:EE:53:10:0F
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 51:A3:B0:F5:FD:01:79:9C:56:6D:B8:37:78:8F:0C:A4:
  • 7A:CC:1B:27:CB:F7:9E:88:42:9A:0D:FE:D4:8B:05:E5
  • Timestamp : May 4 14:15:04.748 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:D3:FD:D1:BB:2B:8C:63:C6:A8:82:87:
  • DD:01:8C:59:0E:E6:F6:22:CB:F4:7D:14:64:E6:4D:C6:
  • 76:6D:EF:95:D5:02:20:56:51:93:4E:34:9E:CF:A5:55:
  • EC:86:6B:B5:BA:B6:55:C1:40:87:96:15:5A:8E:AE:2B:
  • 7D:59:EA:61:7D:61:5F