SSL check results of knutanstoetz.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for knutanstoetz.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Thu, 09 Jan 2025 01:30:07 +0000

We can not guarantee a secure connection to the mailservers of knutanstoetz.de!

Please contact the operator of knutanstoetz.de and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/knutanstoetz.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @knutanstoetz.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.knutanstoetz.de
178.254.45.234
10
supported
server1.knutanstoetz.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail.knutanstoetz.de
178.254.4.101
Results incomplete
10
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have not received any emails from a @knutanstoetz.de address so far. Test mail delivery

Certificates

First seen at:

CN=server1.knutanstoetz.de

Certificate chain
  • server1.knutanstoetz.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption
    • Hostname Mismatch

      • R11
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • server1.knutanstoetz.de
Alternative Names
  • server1.knutanstoetz.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R11
validity period
Not valid before
2025-01-07
Not valid after
2025-04-07
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
9F:E9:94:73:96:E2:57:B8:20:17:C3:A1:47:99:BB:10:32:3A:59:9E:F5:C4:14:BC:8F:69:90:9C:96:6F:F9:F6
SHA1
82:98:AB:4C:23:08:BF:AF:AB:9C:69:A7:02:89:00:49:5B:19:C4:ED
X509v3 extensions
subjectKeyIdentifier
  • 71:BC:30:7F:B8:B9:17:E5:B8:E8:8A:8C:8B:01:C9:4D:F7:17:E2:27
authorityKeyIdentifier
  • keyid:C5:CF:46:A4:EA:F4:C3:C0:7A:6C:95:C4:2D:B0:5E:92:2F:26:E3:B9
authorityInfoAccess
  • OCSP - URI:http://r11.o.lencr.org
  • CA Issuers - URI:http://r11.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1:
  • D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50
  • Timestamp : Jan 7 17:16:45.472 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:E2:89:C7:35:A7:88:3E:E6:65:EA:88:
  • 3E:79:8B:5E:5A:D8:B1:D7:64:4E:17:AB:23:C8:4F:3F:
  • 9E:43:D0:9D:F2:02:20:4A:C1:4E:E5:C7:70:99:3D:FF:
  • 4F:B8:FB:A6:FB:96:FB:CC:30:67:39:BE:4C:D4:D1:9A:
  • 9C:EF:B7:7B:91:14:BD
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : E0:92:B3:FC:0C:1D:C8:E7:68:36:1F:DE:61:B9:96:4D:
  • 0A:52:78:19:8A:72:D6:72:C4:B0:4D:A5:6D:6F:54:04
  • Timestamp : Jan 7 17:16:45.549 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:D2:C4:8A:12:65:09:03:5A:89:AC:EE:
  • 1C:58:38:6A:41:26:55:CE:61:65:21:E4:29:BC:16:E4:
  • F0:95:2F:9E:61:02:20:28:4E:A6:4E:C7:0B:DA:B0:35:
  • 1F:75:05:87:1E:A3:A6:9F:02:2E:DD:37:4A:D3:4B:7E:
  • DF:26:32:68:FF:22:6C