SSL check results of mx10.also.com

NEW You can also bulk check multiple servers.

Discover if the mail servers for mx10.also.com can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 03 Mar 2023 10:21:33 +0000

The mailservers of mx10.also.com can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @mx10.also.com addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx10.also.com
194.115.88.22
-
supported
mx10.also.com
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @mx10.also.com address so far. Test mail delivery

Certificates

First seen at:

CN=mx10.also.com,O=Also Holding AG,L=Emmen,ST=Luzern,C=CH

Certificate chain
Subject
Country (C)
  • CH
State (ST)
  • Luzern
Locality (L)
  • Emmen
Organization (O)
  • Also Holding AG
Common Name (CN)
  • mx10.also.com
Alternative Names
  • mx10.also.com
  • mx20.also.com
  • nsp.mx.also.com
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Organizational Unit (OU)
  • www.digicert.com
Common Name (CN)
  • GeoTrust TLS RSA CA G1
validity period
Not valid before
2023-01-12
Not valid after
2024-01-11
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
56:3E:5C:89:EB:60:C4:B4:61:09:DB:51:64:20:AE:9D:BD:FB:A3:50:41:7D:2D:B8:14:12:3D:C5:81:73:8F:D3
SHA1
0F:AC:A8:BC:D7:23:3C:9D:0E:3A:68:6D:28:3C:05:A9:3C:E3:06:FA
X509v3 extensions
authorityKeyIdentifier
  • keyid:94:4F:D4:5D:8B:E4:A4:E2:A6:80:FE:FD:D8:F9:00:EF:A3:BE:02:57
subjectKeyIdentifier
  • 49:1F:DE:1A:1F:D9:85:88:CF:D3:E7:2C:78:C5:52:60:2D:D2:5C:A5
crlDistributionPoints
  • Full Name:
  • URI:http://cdp.geotrust.com/GeoTrustTLSRSACAG1.crl
certificatePolicies
  • Policy: 2.23.140.1.2.2
  • CPS: http://www.digicert.com/CPS
authorityInfoAccess
  • OCSP - URI:http://status.geotrust.com
  • CA Issuers - URI:http://cacerts.geotrust.com/GeoTrustTLSRSACAG1.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : EE:CD:D0:64:D5:DB:1A:CE:C5:5C:B7:9D:B4:CD:13:A2:
  • 32:87:46:7C:BC:EC:DE:C3:51:48:59:46:71:1F:B5:9B
  • Timestamp : Jan 12 14:52:18.570 2023 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:7E:D2:8C:17:C1:76:51:24:65:4F:49:D8:
  • 2A:47:93:3A:0C:14:64:AA:03:0C:B7:90:F2:40:E0:A8:
  • 7B:B6:43:3D:02:20:0E:FD:AC:3C:8C:83:C3:00:D3:96:
  • 2B:02:0B:FD:AE:E4:FA:2D:3F:9A:CC:E0:69:C9:59:C1:
  • 9F:8A:B3:BB:8D:75
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 48:B0:E3:6B:DA:A6:47:34:0F:E5:6A:02:FA:9D:30:EB:
  • 1C:52:01:CB:56:DD:2C:81:D9:BB:BF:AB:39:D8:84:73
  • Timestamp : Jan 12 14:52:18.487 2023 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:3E:31:AF:47:BA:A7:80:12:22:75:11:D6:
  • BD:E3:0B:91:6D:CE:36:60:A0:19:EA:4A:44:38:99:F2:
  • 83:6A:DC:7B:02:21:00:E3:FD:3E:14:6D:3C:79:F1:68:
  • BC:E8:A7:B3:A5:61:6B:45:2D:B6:61:50:5C:FB:58:70:
  • A7:B2:3F:F7:F4:85:E7
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 3B:53:77:75:3E:2D:B9:80:4E:8B:30:5B:06:FE:40:3B:
  • 67:D8:4F:C3:F4:C7:BD:00:0D:2D:72:6F:E1:FA:D4:17
  • Timestamp : Jan 12 14:52:18.493 2023 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:C7:DE:58:4F:6E:54:BC:02:CB:09:6C:
  • 99:70:1D:56:52:47:5D:68:B2:6A:33:80:25:92:E3:78:
  • 62:A4:0A:C8:52:02:21:00:E1:99:8E:BA:26:60:14:7E:
  • 60:64:31:36:31:F1:8C:85:56:22:FA:54:54:23:34:B3:
  • DF:33:2C:19:BD:7B:DE:97

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx10.also.com
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx10.also.com
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid