SSL check results of kos.to

NEW You can also bulk check multiple servers.

Discover if the mail servers for kos.to can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 12 Sep 2026 00:30:28 +0000

The mailservers of kos.to can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @kos.to addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
helsinki.kos.to
2a01:4f9:c012:87d7::1
20
supported
kos.to
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s
helsinki.kos.to
157.180.33.111
20
supported
kos.to
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s

Outgoing Mails

We have not received any emails from a @kos.to address so far. Test mail delivery

Certificates

First seen at:

CN=kos.to

Certificate chain
  • kos.to
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • kos.to
Alternative Names
  • helsinki.kos.to
  • kos.to
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-07-22
Not valid after
2026-10-20
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
BA:5D:99:5C:D8:9A:B1:E7:82:11:41:9F:FB:32:71:34:F5:E1:6F:27:7C:B5:3E:63:A9:D0:80:C6:F8:93:5D:1F
SHA1
61:B4:A2:79:23:0D:9A:87:11:27:9B:19:0C:2D:AC:FE:18:FE:81:00
X509v3 extensions
subjectKeyIdentifier
  • E6:B3:C5:E5:F3:BF:97:5C:68:51:C9:06:62:28:00:3B:73:BD:C9:21
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/103.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C8:A3:C4:7F:C7:B3:AD:B9:35:6B:01:3F:6A:7A:12:6D:
  • E3:3A:4E:43:A5:C6:46:F9:97:AD:39:75:99:1D:CF:9A
  • Timestamp : Jul 22 08:13:45.297 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:AB:81:2C:5D:E5:BC:C9:CD:B1:DE:1F:
  • 2C:5A:0D:93:D7:49:D5:50:FB:30:1E:7C:72:E4:F2:15:
  • C6:5E:E9:22:42:02:21:00:8B:0F:B2:AE:0E:21:01:D4:
  • F2:55:15:54:D2:98:18:20:14:A6:D0:40:98:F6:52:0E:
  • EE:24:4B:00:A9:95:51:58
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A8:26:CB:E3:0A:C6:35:12:46:53:3F:E0:65:F1:4F:19:
  • D9:6E:19:08:13:C4:1D:D9:6D:79:00:B3:12:3C:55:27
  • Timestamp : Jul 22 08:13:45.288 2026 GMT
  • Extensions: 00:00:05:00:15:77:A2:49
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:04:E3:7F:0C:9E:39:37:AD:67:AD:98:06:
  • E7:AC:15:30:3F:47:07:1D:54:21:82:0D:60:8C:2F:2D:
  • 15:38:C3:25:02:21:00:8C:C4:6D:BF:46:FE:69:96:DA:
  • A2:32:E7:4E:8A:04:7C:8D:BB:17:4C:5B:F6:7F:1C:AB:
  • 0B:9B:CB:27:39:0B:2A