SSL check results of liptus.it

NEW You can also bulk check multiple servers.

Discover if the mail servers for liptus.it can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 03 Aug 2019 06:32:58 +0000

The mailservers of liptus.it can be reached through an encrypted connection.

However, we found problems that may affect the security.

Servers

Incoming Mails

These servers are responsible for incoming mails to @liptus.it addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
smtp.liptus.it
93.56.18.170
10
supported
octwebw2k3.octweb.local
DANE
missing
PFS
unsupported
Heartbleed
not vulnerable
Weak ciphers
supported
  • SSL_RSA_WITH_RC4_128_MD5
  • SSL_RSA_EXPORT_WITH_RC4_40_MD5
  • SSL_RSA_WITH_RC4_128_SHA
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have received emails from these servers with @liptus.it sender addresses. Test mail delivery

Host TLS Version & Cipher
unknown (62.33.210.206)
Insecure - not encrypted!
unknown (202.138.242.7)
Insecure - not encrypted!
unknown (95.71.126.250)
Insecure - not encrypted!
unknown (46.100.95.163)
Insecure - not encrypted!
unknown (103.85.162.58)
Insecure - not encrypted!
unknown (185.141.39.230)
Insecure - not encrypted!
unknown (202.7.53.156)
Insecure - not encrypted!
unknown (77.247.88.10)
Insecure - not encrypted!
unknown (103.95.99.229)
Insecure - not encrypted!
unknown (92.241.17.80)
Insecure - not encrypted!
unknown (31.209.97.66)
Insecure - not encrypted!
unknown (103.42.252.1)
Insecure - not encrypted!
unknown (190.109.170.105)
Insecure - not encrypted!
unknown (109.72.97.66)
Insecure - not encrypted!

Certificates

First seen at:

CN=octwebw2k3.octweb.local

Certificate chain
  • octwebw2k3.octweb.local (Certificate is self-signed.)
    • remaining
    • 2048 bit
    • sha1WithRSAEncryption
    • Hostname Mismatch
    • Unknown Authority

Subject
Common Name (CN)
  • octwebw2k3.octweb.local
Alternative Names
  • octwebw2k3.octweb.local
Issuer

Certificate is self-signed.

validity period
Not valid before
2018-03-16
Not valid after
2023-03-16
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
Fingerprints
SHA256
CF:5A:47:CC:FF:45:5E:6A:8E:92:FD:78:80:4F:71:67:05:DF:38:77:34:55:B6:3F:4F:70:10:5F:23:6F:48:F9
SHA1
62:8A:81:D3:F2:98:79:A2:24:D3:EB:7C:3F:9A:EE:A5:D9:75:AD:FC