SSL check results of maevi.net

NEW You can also bulk check multiple servers.

Discover if the mail servers for maevi.net can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 14 Sep 2026 05:43:47 +0000

The mailservers of maevi.net can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @maevi.net addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx.maevi.net
2a14:6f44:7f00:0:25::1
10
supported
mx.maevi.net
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
4 s
mx.maevi.net
77.73.117.246
10
supported
mx.maevi.net
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s

Outgoing Mails

We have not received any emails from a @maevi.net address so far. Test mail delivery

Certificates

First seen at:

CN=mx.maevi.net

Certificate chain
  • mx.maevi.net
    • remaining
    • 384 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mx.maevi.net
Alternative Names
  • imap.maevi.net
  • mail.maevi.net
  • mx.maevi.net
  • smtp.maevi.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-08-16
Not valid after
2026-11-14
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
29:2E:5A:4C:06:78:E6:2A:03:69:A2:9B:92:B8:8E:03:E8:D0:49:0E:59:28:6A:39:F7:F8:7F:82:88:CA:F5:89
SHA1
CE:7E:C7:62:F1:C9:9B:2B:AD:04:A8:06:35:04:83:9C:A6:CC:62:19
X509v3 extensions
subjectKeyIdentifier
  • 75:8D:8F:94:77:EA:E7:00:6F:92:3D:86:41:24:FD:15:C8:F1:D1:54
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/13.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : CB:38:F7:15:89:7C:84:A1:44:5F:5B:C1:DD:FB:C9:6E:
  • F2:9A:59:CD:47:0A:69:05:85:B0:CB:14:C3:14:58:E7
  • Timestamp : Aug 16 16:26:29.192 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:5A:47:98:A0:AB:57:55:5B:C5:87:A3:FF:
  • E8:E0:24:F9:88:E6:93:32:D9:5F:5D:D1:41:AB:24:AB:
  • 5C:3A:F3:8B:02:20:61:38:0A:43:5A:86:A5:0D:E0:9A:
  • 99:C2:98:99:A2:DF:6E:15:97:15:59:B6:F6:ED:48:3F:
  • 8A:E8:C5:B6:2E:FD
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Aug 16 16:26:29.363 2026 GMT
  • Extensions: 00:00:05:00:35:45:E4:13
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:31:F8:DB:65:59:67:9E:71:DA:4F:80:0D:
  • 73:C4:08:2D:9E:18:F3:0D:64:96:22:00:2D:84:20:C3:
  • FF:B2:5C:4C:02:21:00:C5:2D:C2:22:75:AC:E7:A0:C0:
  • A8:5C:E2:D2:BE:ED:10:94:0F:07:FB:A1:CE:7C:FE:41:
  • F3:B8:55:15:36:21:7C

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx.maevi.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid