SSL check results of maler-blase.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for maler-blase.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 15 Oct 2021 12:59:15 +0000

The mailservers of maler-blase.de can be reached through an encrypted connection.

However, we found problems that may affect the security.

Servers

Incoming Mails

These servers are responsible for incoming mails to @maler-blase.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.maler-blase.de
89.1.171.229
10
supported
maler-blase.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
supported
  • ECDHE_RSA_WITH_RC4_128_SHA
  • SSL_RSA_WITH_RC4_128_SHA
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
blase.dynpc.net
89.1.171.229
15
supported
maler-blase.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
supported
  • ECDHE_RSA_WITH_RC4_128_SHA
  • SSL_RSA_WITH_RC4_128_SHA
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @maler-blase.de address so far. Test mail delivery

Certificates

First seen at:

CN=maler-blase.de

Certificate chain
  • maler-blase.de
    • remaining
    • 3072 bit
    • sha256WithRSAEncryption
    • Hostname Mismatch

      • R3
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • maler-blase.de
Alternative Names
  • config.maler-blase.de
  • mail.maler-blase.de
  • maler-blase.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R3
validity period
Not valid before
2021-09-11
Not valid after
2021-12-10
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
6C:60:58:50:48:74:04:E7:88:E2:C0:27:D8:71:C1:B7:BB:81:DB:6A:14:87:33:B3:C0:2A:DD:41:8A:53:BF:08
SHA1
15:C2:63:20:55:5A:17:BD:DD:4C:9A:DE:1B:8A:CB:26:06:8A:41:DC
X509v3 extensions
subjectKeyIdentifier
  • 3F:75:96:E0:E2:54:EE:C6:FF:C9:0D:61:83:D9:F2:00:5B:0A:EE:04
authorityKeyIdentifier
  • keyid:14:2E:B3:17:B7:58:56:CB:AE:50:09:40:E6:1F:AF:9D:8B:14:C2:C6
authorityInfoAccess
  • OCSP - URI:http://r3.o.lencr.org
  • CA Issuers - URI:http://r3.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
  • Policy: 1.3.6.1.4.1.44947.1.1.1
  • CPS: http://cps.letsencrypt.org
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 5C:DC:43:92:FE:E6:AB:45:44:B1:5E:9A:D4:56:E6:10:
  • 37:FB:D5:FA:47:DC:A1:73:94:B2:5E:E6:F6:C7:0E:CA
  • Timestamp : Sep 11 18:31:11.252 2021 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:DC:06:5E:C6:68:4C:FE:E0:D3:BC:0F:
  • 7B:25:E5:3E:AF:2F:A2:76:1B:AF:7D:1B:C0:8E:5C:41:
  • 42:FC:F0:3F:79:02:20:12:C5:9C:76:27:1C:36:BA:0B:
  • D8:36:C0:86:8F:3A:6C:63:50:66:92:01:91:73:49:1F:
  • 24:A1:F6:15:20:B5:A8
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : F6:5C:94:2F:D1:77:30:22:14:54:18:08:30:94:56:8E:
  • E3:4D:13:19:33:BF:DF:0C:2F:20:0B:CC:4E:F1:64:E3
  • Timestamp : Sep 11 18:31:11.226 2021 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:1C:C0:2D:59:1C:99:D6:D6:8C:2E:C8:E9:
  • 91:BB:3D:7C:B9:CE:04:2D:72:5E:BB:02:CC:09:20:67:
  • 13:29:8C:47:02:21:00:AA:87:4E:CE:9C:AC:0A:E8:CF:
  • 0F:CA:F2:02:15:4D:71:AD:41:B8:70:6A:58:BA:06:3C:
  • C6:B0:DB:8B:22:8A:0E