SSL check results of mail.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for mail.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Wed, 22 Jul 2026 02:57:36 +0000

The mailservers of mail.de can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @mail.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx01.mail.de
2a0f:f640::51
10
supported
*.mail.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mx01.mail.de
194.113.42.51
10
supported
*.mail.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mx02.mail.de
2a0f:f640::52
10
supported
*.mail.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mx02.mail.de
194.113.42.52
10
supported
*.mail.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have received emails from these servers with @mail.de sender addresses. Test mail delivery

Host TLS Version & Cipher
shout02.mail.de (IPv6:2001:868:100:600::217)
TLSv1.2 AECDH-AES256-SHA
shout01.mail.de (IPv6:2001:868:100:600::216)
TLSv1.2 AECDH-AES256-SHA
shout11.mail.de (IPv6:2001:868:100:600::f153)
TLSv1.3 TLS_AES_256_GCM_SHA384
shout12.mail.de (IPv6:2001:868:100:600::f154)
TLSv1.3 TLS_AES_256_GCM_SHA384

Certificates

First seen at:

CN=*.mail.de

Certificate chain
  • *.mail.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption

      • R12
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • *.mail.de
Alternative Names
  • *.mail.de
  • mail.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R12
validity period
Not valid before
2026-05-15
Not valid after
2026-08-13
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
Fingerprints
SHA256
63:72:FE:63:53:86:FD:50:80:D7:D3:0E:FA:5E:63:63:49:82:75:BD:5C:64:DF:9D:50:9F:6B:74:A0:65:44:4D
SHA1
0D:6C:D5:53:8D:77:24:46:3F:14:B0:91:C4:CD:0A:6C:FA:E3:29:60
X509v3 extensions
subjectKeyIdentifier
  • 60:68:2D:7D:E0:C2:B0:46:FB:68:03:43:DB:58:F7:83:4B:0F:BF:F7
authorityKeyIdentifier
  • keyid:00:B5:29:F2:2D:8E:6F:31:E8:9B:4C:AD:78:3E:FA:DC:E9:0C:D1:D2
authorityInfoAccess
  • CA Issuers - URI:http://r12.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r12.c.lencr.org/68.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : May 15 11:46:50.912 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:59:BC:2B:E2:4E:F4:7C:BE:1A:9C:60:FC:
  • 6C:4D:E8:3E:CF:A8:EF:4C:60:9A:EB:53:C7:5F:C5:01:
  • CB:32:BE:D7:02:20:28:43:18:7C:E9:72:2F:DC:D0:DE:
  • EE:21:12:AA:07:BE:4F:BA:FA:73:C0:4C:65:33:65:AD:
  • 2E:56:91:43:2F:74
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : May 15 11:46:51.701 2026 GMT
  • Extensions: 00:00:05:00:13:03:A7:F3
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:20:3A:A4:BA:D2:6A:10:D6:F2:BF:A5:A7:
  • D7:A7:38:29:27:2E:9A:EC:E1:5B:91:B9:EE:40:89:7D:
  • 67:6D:AC:0E:02:20:0A:54:1F:80:02:39:6F:96:AF:30:
  • F3:7F:1D:8C:79:55:83:ED:31:9A:10:C3:E6:F5:9B:A1:
  • 8A:52:17:37:8F:66

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx01.mail.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx01.mail.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mx02.mail.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx02.mail.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid