SSL check results of mail.baradur.es

NEW You can also bulk check multiple servers.

Discover if the mail servers for mail.baradur.es can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 12 Sep 2026 00:30:28 +0000

The mailservers of mail.baradur.es can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @mail.baradur.es addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.baradur.es
51.255.194.223
-
supported
mail.baradur.es
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s
mail.baradur.es
2001:41d0:305:2100::e2c7
-
supported
mail.baradur.es
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
10 s

Outgoing Mails

We have not received any emails from a @mail.baradur.es address so far. Test mail delivery

Certificates

First seen at:

CN=mail.baradur.es

Certificate chain
  • mail.baradur.es
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail.baradur.es
Alternative Names
  • mail.baradur.es
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-08-15
Not valid after
2026-11-13
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
3B:21:AB:9B:BE:D5:88:60:38:38:21:48:76:37:5C:E1:5C:6E:4F:49:E5:47:9D:10:0B:EF:FD:5D:4B:E5:DA:91
SHA1
A4:03:D5:D1:67:01:AB:9D:77:C7:FD:DC:11:FC:4D:CD:C9:39:91:4E
X509v3 extensions
subjectKeyIdentifier
  • 76:C0:A9:2F:40:78:77:7F:75:36:02:05:7A:E1:89:BE:22:61:7D:35
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/77.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Aug 15 18:10:28.912 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:05:B3:14:DC:9E:90:F8:D4:E7:38:76:11:
  • B2:94:3A:C3:6D:B6:99:44:C6:C4:D1:11:FB:24:23:2F:
  • 9E:86:C2:E2:02:21:00:E6:AC:FD:68:6B:E4:AB:89:89:
  • 59:07:0E:4A:61:9F:A7:08:4F:ED:A2:E2:19:97:79:7E:
  • 19:35:D0:7B:86:A6:C4
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6C:FE:50:19:43:A8:5E:A9:16:BC:52:D1:33:E4:DC:C9:
  • 1E:F1:41:1C:7D:25:84:20:D1:73:80:9E:18:18:EB:3A
  • Timestamp : Aug 15 18:10:29.992 2026 GMT
  • Extensions: 00:00:05:00:1E:6A:94:1E
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:4A:7B:46:A3:1A:85:3B:8F:A4:86:00:89:
  • 1A:13:28:C5:D1:EB:A4:0A:51:69:5E:1D:8E:67:E3:B5:
  • BC:38:83:17:02:21:00:C9:B8:6A:FA:B8:A3:E7:CC:80:
  • 58:13:91:44:36:1E:54:72:0B:9E:A0:80:28:5D:E6:45:
  • 99:9C:F1:33:17:B6:21

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail.baradur.es
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid