SSL check results of pentakel.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for pentakel.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 21 Aug 2026 00:30:38 +0000

The mailservers of pentakel.de can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @pentakel.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.hot-chilli.net
2a01:4f8:10b:43b0::3
10
supported
mail.hot-chilli.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
4 s
mail.hot-chilli.net
116.202.55.99
10
supported
mail.hot-chilli.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
4 s
mail2.hot-chilli.net
2a01:4f8:121:1165::3
Results incomplete
20
supported
not checked
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
4 s
mail2.hot-chilli.net
178.63.67.88
Results incomplete
20
supported
not checked
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
4 s
mail3.hot-chilli.net
2a01:4f8:200:1053::3
30
supported
mail3.hot-chilli.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
4 s
mail3.hot-chilli.net
144.76.136.77
30
supported
mail3.hot-chilli.net
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s

Outgoing Mails

We have not received any emails from a @pentakel.de address so far. Test mail delivery

Certificates

First seen at:

CN=mail3.hot-chilli.net

Certificate chain
  • mail3.hot-chilli.net
    • remaining
    • 384 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail3.hot-chilli.net
Alternative Names
  • mail3.hot-chilli.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-08-03
Not valid after
2026-11-01
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
A8:1A:B4:E6:57:6A:B5:2B:0B:DC:8C:8A:0C:D5:C6:A3:9E:08:8D:CB:4D:3C:EB:7C:19:5C:ED:7A:8A:BB:48:92
SHA1
93:03:C0:10:42:B6:A6:54:2E:0B:CD:AC:C0:96:92:C1:7B:70:67:BE
X509v3 extensions
subjectKeyIdentifier
  • 09:7E:B6:FE:C8:48:B9:62:E8:14:C8:48:3C:A3:1D:E2:2C:42:DD:AC
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/97.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:
  • 82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77
  • Timestamp : Aug 3 17:04:35.845 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:20:8C:34:51:27:3D:57:2D:11:65:A7:C5:
  • 3D:7C:00:65:24:D8:58:ED:E7:12:BE:47:CC:EF:4C:60:
  • 7D:1E:65:44:02:20:12:90:A0:25:43:76:47:CC:12:FB:
  • E5:87:A8:28:12:09:6E:34:51:F7:A9:25:74:68:54:F8:
  • 31:23:A7:93:34:C7
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A8:26:CB:E3:0A:C6:35:12:46:53:3F:E0:65:F1:4F:19:
  • D9:6E:19:08:13:C4:1D:D9:6D:79:00:B3:12:3C:55:27
  • Timestamp : Aug 3 17:04:36.029 2026 GMT
  • Extensions: 00:00:05:00:18:24:81:30
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:79:31:26:46:A5:0F:82:EE:29:80:EB:43:
  • 81:4F:1D:FC:CB:32:39:5A:53:E3:4A:28:59:6A:97:C8:
  • A0:A1:87:F8:02:21:00:DB:E9:E2:C9:7B:BB:16:52:42:
  • 50:B8:39:3F:E2:C6:DD:6F:A2:3B:8A:46:69:51:47:50:
  • 4D:B3:B0:85:F6:07:74
First seen at:

CN=mail.hot-chilli.net

Certificate chain
  • mail.hot-chilli.net
    • remaining
    • 384 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail.hot-chilli.net
Alternative Names
  • mail.hot-chilli.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-08-12
Not valid after
2026-11-10
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
FF:06:C4:8F:D6:E6:6E:6D:9D:AA:4B:62:B5:8F:91:FB:BB:2E:43:28:A8:FA:5F:E0:F3:76:DC:66:EB:F3:B2:92
SHA1
57:31:B8:A0:E6:54:B6:52:DC:25:92:04:2E:76:E7:FA:17:46:98:19
X509v3 extensions
subjectKeyIdentifier
  • 56:D5:7E:AD:DD:60:D1:0F:CD:F0:60:2D:3F:40:9C:D3:53:D5:6F:0D
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/77.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Aug 12 13:01:01.882 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:7B:34:68:F0:6F:DB:00:65:EF:49:80:4C:
  • 6E:DD:EA:20:58:0B:8A:67:C6:75:DE:80:CF:34:29:95:
  • BC:72:C1:A3:02:20:3C:8F:ED:63:3F:6F:9B:B4:D1:1C:
  • 8B:1D:41:9D:3C:66:0A:D0:86:F4:E9:6B:0F:AD:A0:16:
  • 51:E4:0A:AE:25:67
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A8:26:CB:E3:0A:C6:35:12:46:53:3F:E0:65:F1:4F:19:
  • D9:6E:19:08:13:C4:1D:D9:6D:79:00:B3:12:3C:55:27
  • Timestamp : Aug 12 13:01:02.030 2026 GMT
  • Extensions: 00:00:05:00:1B:75:4A:1F
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:45:2C:12:04:8F:E4:85:AA:39:4C:B8:87:
  • D8:69:0D:A1:70:70:EF:4C:08:2C:80:50:F6:09:D7:3A:
  • 73:E5:0F:22:02:21:00:B9:51:4A:06:D3:18:67:0E:42:
  • C9:3A:59:30:0B:3C:28:84:B0:98:B1:11:89:EE:FA:31:
  • AF:58:2F:03:25:38:ED

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail3.hot-chilli.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail2.hot-chilli.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.hot-chilli.net
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid