SSL check results of ok.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for ok.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 03 Jul 2020 13:56:36 +0000

The mailservers of ok.de can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @ok.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx2.ok.de
88.198.218.184
1
supported
*.ok.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
17 s
mx1.ok.de
88.198.199.115
5
supported
*.ok.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
12 s

Outgoing Mails

We have not received any emails from a @ok.de address so far. Test mail delivery

Certificates

First seen at:

CN=*.ok.de,OU=Domain Control Validated

Certificate chain
Subject
Organizational Unit (OU)
  • Domain Control Validated
Common Name (CN)
  • *.ok.de
Alternative Names
  • *.ok.de
  • ok.de
Issuer
Country (C)
  • BE
Organization (O)
  • GlobalSign nv-sa
Common Name (CN)
  • AlphaSSL CA - SHA256 - G2
validity period
Not valid before
2018-06-18
Not valid after
2020-07-29
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
F4:06:EE:EA:89:7D:09:3E:45:9B:B5:99:D9:19:D8:97:FB:9B:7A:02:ED:4A:DF:85:7A:71:DF:E2:70:26:62:C4
SHA1
20:4F:E1:BA:E6:07:7C:74:40:6A:B9:19:A5:9C:66:BD:AF:9B:1B:3C
X509v3 extensions
authorityInfoAccess
  • CA Issuers - URI:http://secure2.alphassl.com/cacert/gsalphasha2g2r1.crt
  • OCSP - URI:http://ocsp2.globalsign.com/gsalphasha2g2
certificatePolicies
  • Policy: 1.3.6.1.4.1.4146.1.10.10
  • CPS: https://www.globalsign.com/repository/
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://crl2.alphassl.com/gs/gsalphasha2g2.crl
subjectKeyIdentifier
  • 94:90:C7:82:68:B5:73:48:AA:4A:03:FF:FF:8C:23:91:F4:98:67:82
authorityKeyIdentifier
  • keyid:F5:CD:D5:3C:08:50:F9:6A:4F:3A:B7:97:DA:56:83:E6:69:D2:68:F7
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 87:75:BF:E7:59:7C:F8:8C:43:99:5F:BD:F3:6E:FF:56:
  • 8D:47:56:36:FF:4A:B5:60:C1:B4:EA:FF:5E:A0:83:0F
  • Timestamp : Jun 18 16:18:41.168 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:DD:80:0D:8D:2F:69:3D:86:38:7A:B4:
  • A0:7C:20:67:97:7C:86:EC:CF:79:3F:A5:83:FF:44:DC:
  • 1D:72:E9:7B:1F:02:20:45:28:17:D3:E4:73:BA:61:98:
  • 13:E4:4E:40:FA:D3:13:1F:CE:A5:2E:3F:F0:64:B0:BB:
  • 9A:A2:B0:21:09:2C:54
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A4:B9:09:90:B4:18:58:14:87:BB:13:A2:CC:67:70:0A:
  • 3C:35:98:04:F9:1B:DF:B8:E3:77:CD:0E:C8:0D:DC:10
  • Timestamp : Jun 18 16:18:42.023 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:A8:B0:F3:87:48:8B:46:0E:81:6C:FC:
  • 76:AF:3D:09:77:B6:4A:2F:33:8E:FE:CB:72:6B:A2:75:
  • 11:06:5A:71:3D:02:21:00:AA:61:C9:6C:94:6D:3D:52:
  • 21:5C:DA:55:21:2D:C9:92:23:70:AC:3F:B1:55:F9:10:
  • 8C:19:EA:03:FA:BD:D9:B7
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6F:53:76:AC:31:F0:31:19:D8:99:00:A4:51:15:FF:77:
  • 15:1C:11:D9:02:C1:00:29:06:8D:B2:08:9A:37:D9:13
  • Timestamp : Jun 18 16:18:41.197 2018 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:EB:5F:D3:50:56:84:E4:97:C7:F9:70:
  • 51:A3:F9:BC:06:0D:4A:81:E8:F4:ED:41:A3:C4:9A:BE:
  • FF:FC:0F:3F:92:02:20:1D:50:80:38:4F:E7:33:7E:34:
  • D7:81:B5:10:1E:73:39:C7:21:4B:20:F1:7E:9A:0D:95:
  • 42:E9:28:67:DB:DF:35