SSL check results of pivi.ch

NEW You can also bulk check multiple servers.

Discover if the mail servers for pivi.ch can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 13 Jul 2026 09:04:59 +0000

The mailservers of pivi.ch can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @pivi.ch addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.pivi.ch
2a02:1210:5e38:e900::102
10
supported
mail.pivi.ch
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
6 s
mail.pivi.ch
62.167.242.197
10
supported
mail.pivi.ch
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
6 s

Outgoing Mails

We have not received any emails from a @pivi.ch address so far. Test mail delivery

Certificates

First seen at:

CN=mail.pivi.ch

Certificate chain
  • mail.pivi.ch
    • remaining
    • 256 bit
    • sha256WithRSAEncryption

      • GandiCert
        • remaining
        • 4096 bit
        • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mail.pivi.ch
Alternative Names
  • mail.pivi.ch
  • mta-sts.pivi.ch
  • pivi.ch
  • mymailing.ch
  • mta-sts.mymailing.ch
  • pivi.internet-box.ch
  • autodiscover.pivi.ch
  • www.mymailing.ch
  • pivi-utm.ch
  • www.pivi.ch
Issuer
Country (C)
  • FR
Organization (O)
  • Gandi SAS
Common Name (CN)
  • GandiCert
validity period
Not valid before
2026-06-25
Not valid after
2027-01-09
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Agreement
  • TLS Web Server Authentication
Fingerprints
SHA256
85:AE:4E:6A:6C:DE:C9:DF:CE:1C:21:5D:03:11:7B:88:1C:9F:D4:8E:55:E7:B2:4D:46:60:3B:7A:30:3D:FB:0B
SHA1
54:E0:53:CE:52:D5:D9:50:0D:16:C3:1D:A2:29:0A:2E:3D:85:59:45
X509v3 extensions
authorityKeyIdentifier
  • keyid:BA:BB:46:88:45:EC:DD:5A:2B:18:C5:D1:4E:EC:E3:3C:06:52:53:AC
subjectKeyIdentifier
  • B0:01:14:4F:B1:ED:98:C7:5C:22:D2:87:F8:56:05:4E:4B:87:F7:D7
certificatePolicies
  • Policy: 2.23.140.1.2.1
  • CPS: http://www.digicert.com/CPS
crlDistributionPoints
  • Full Name:
  • URI:http://crl3.digicert.com/GandiCert.crl
  • Full Name:
  • URI:http://crl4.digicert.com/GandiCert.crl
authorityInfoAccess
  • OCSP - URI:http://ocsp.digicert.com
  • CA Issuers - URI:http://cacerts.digicert.com/GandiCert.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 4C:63:DC:98:E5:9C:1D:AB:88:F6:1E:8A:3D:DE:AE:8F:
  • AB:44:A3:37:7B:5F:9B:94:C3:FB:A1:9C:FC:C1:BE:26
  • Timestamp : Jun 25 09:59:11.973 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:FD:0C:7B:F7:16:F8:7B:AF:20:67:1B:
  • 69:27:A3:CE:A6:97:82:08:9D:E6:9B:9C:E7:26:29:72:
  • DF:4A:1D:62:9C:02:20:72:22:98:7C:C3:DB:82:4E:D3:
  • 9F:8B:D1:18:2F:30:AE:F9:2E:13:BF:7C:4A:CC:DF:B9:
  • 94:4A:A4:18:42:72:F7
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D6:D5:8D:A9:D0:17:53:F3:6A:4A:A0:C7:57:49:02:AF:
  • EB:C7:DC:2C:D3:8C:D9:F7:64:C8:0C:89:19:1E:9F:02
  • Timestamp : Jun 25 09:59:11.991 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:70:E5:3F:A7:C5:4F:AA:B5:FA:01:7D:6D:
  • C6:BD:30:47:5E:97:E6:62:D6:32:CF:95:37:B5:71:D0:
  • DA:B6:42:AC:02:20:6C:8D:65:DC:2B:00:A4:BE:8B:C6:
  • 60:E6:42:B8:E9:EF:01:B6:A5:41:BF:76:9F:B2:F6:83:
  • 46:3D:82:CC:01:E2
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1C:9F:68:2C:E9:FA:F0:45:69:50:F8:1B:96:8A:87:DD:
  • DB:32:10:D8:4C:E6:C8:B2:E3:82:52:4A:C4:CF:59:9F
  • Timestamp : Jun 25 09:59:12.221 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:F7:0E:6B:34:F2:3D:F5:85:3D:7B:E1:
  • DD:0E:83:74:6A:F3:DB:4A:E2:1E:73:D0:EA:05:6F:92:
  • E4:15:63:B5:C1:02:21:00:9A:7D:2A:BE:23:C0:A9:21:
  • BE:59:EA:F3:BD:61:D1:A7:96:49:AB:52:5F:ED:BC:09:
  • 71:88:62:B1:D9:84:C4:FA

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail.pivi.ch
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid