SSL check results of loss.it

NEW You can also bulk check multiple servers.

Discover if the mail servers for loss.it can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 06 Jun 2020 00:33:50 +0000

The mailservers of loss.it can be reached through an encrypted connection.

However, we found problems that may affect the security.

Servers

Incoming Mails

These servers are responsible for incoming mails to @loss.it addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx1.serverlet.com
94.23.71.143
10
supported
Debian9
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mx2.serverlet.com
130.185.108.69
10
supported
Debian9
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
5 s
mx3.serverlet.com
94.23.71.143
10
supported
Debian9
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have received emails from these servers with @loss.it sender addresses. Test mail delivery

Host TLS Version & Cipher
unknown (185.178.220.126)
Insecure - not encrypted!
unknown (200.35.56.161)
Insecure - not encrypted!
unknown (109.252.255.162)
Insecure - not encrypted!
unknown (200.77.186.199)
Insecure - not encrypted!
unknown (91.185.236.236)
Insecure - not encrypted!
unknown (62.122.201.170)
Insecure - not encrypted!
unknown (134.236.243.28)
Insecure - not encrypted!
unknown (103.221.254.54)
Insecure - not encrypted!
unknown (83.103.195.183)
Insecure - not encrypted!
unknown (203.130.130.40)
Insecure - not encrypted!
unknown (103.83.173.234)
Insecure - not encrypted!
unknown (155.0.202.254)
Insecure - not encrypted!
unknown (196.0.113.10)
Insecure - not encrypted!
unknown (209.16.78.27)
Insecure - not encrypted!
unknown (185.188.218.10)
Insecure - not encrypted!
unknown (117.103.5.186)
Insecure - not encrypted!
unknown (103.194.89.238)
Insecure - not encrypted!
unknown (103.36.11.178)
Insecure - not encrypted!
unknown (1.223.248.99)
Insecure - not encrypted!
unknown (78.133.163.190)
Insecure - not encrypted!
unknown (193.193.71.178)
Insecure - not encrypted!
unknown (37.235.28.42)
Insecure - not encrypted!
unknown (190.109.170.105)
Insecure - not encrypted!
unknown (92.247.142.182)
Insecure - not encrypted!
unknown (185.132.228.118)
Insecure - not encrypted!
unknown (176.107.80.105)
Insecure - not encrypted!

Certificates

First seen at:

CN=Debian9

Certificate chain
  • Debian9 (Certificate is self-signed.)
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption
    • Hostname Mismatch
    • Unknown Authority

Subject
Common Name (CN)
  • Debian9
Alternative Names
  • Debian9
Issuer

Certificate is self-signed.

validity period
Not valid before
2018-11-13
Not valid after
2028-11-10
Fingerprints
SHA256
EB:9C:E1:85:4F:56:15:C6:DA:EB:B6:84:44:29:85:0F:52:EE:3F:DF:81:D8:DF:CD:60:C7:2D:AC:25:4E:37:83
SHA1
DE:DD:E9:74:51:3B:49:13:74:21:1A:23:71:B9:0A:72:77:6B:31:6B
First seen at:

CN=Debian9

Certificate chain
  • Debian9 (Certificate is self-signed.)
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption
    • Hostname Mismatch
    • Unknown Authority

Subject
Common Name (CN)
  • Debian9
Alternative Names
  • Debian9
Issuer

Certificate is self-signed.

validity period
Not valid before
2018-11-20
Not valid after
2028-11-17
Fingerprints
SHA256
29:A1:DC:6F:D9:6C:13:65:8B:2B:0A:FE:76:CE:A8:72:B3:0C:E3:F2:8F:55:ED:58:AF:C5:AD:A7:66:42:DB:F1
SHA1
5D:89:76:81:8D:9A:BB:5C:26:7F:F1:6F:0D:DD:09:5F:57:4B:47:ED