SSL check results of safo.at

NEW You can also bulk check multiple servers.

Discover if the mail servers for safo.at can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sun, 15 Feb 2026 11:28:42 +0000

The mailservers of safo.at can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @safo.at addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx1.safo.at
185.35.181.194
10
supported
mx1.safo.at
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mx2.safo.at
185.35.181.195
20
supported
mx2.safo.at
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @safo.at address so far. Test mail delivery

Certificates

First seen at:

CN=mx1.safo.at

Certificate chain
  • mx1.safo.at
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption

      • R13
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mx1.safo.at
Alternative Names
  • mx1.safo.at
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R13
validity period
Not valid before
2026-01-11
Not valid after
2026-04-11
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
48:7B:F2:7C:4C:98:70:D4:BD:5F:D6:6F:D8:EC:A4:23:FA:6F:02:02:D2:05:EA:AD:B0:E8:B4:B0:6C:F7:CB:47
SHA1
86:24:D6:6B:64:16:56:EC:DE:AC:48:E2:D6:F5:90:29:62:2B:83:AC
X509v3 extensions
subjectKeyIdentifier
  • 20:FD:53:E4:DA:DF:15:67:70:BF:C6:79:B2:A3:9A:40:62:07:72:5D
authorityKeyIdentifier
  • keyid:E7:AB:9F:0F:2C:33:A0:53:D3:5E:4F:78:C8:B2:84:0E:3B:D6:92:33
authorityInfoAccess
  • CA Issuers - URI:http://r13.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r13.c.lencr.org/61.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 0E:57:94:BC:F3:AE:A9:3E:33:1B:2C:99:07:B3:F7:90:
  • DF:9B:C2:3D:71:32:25:DD:21:A9:25:AC:61:C5:4E:21
  • Timestamp : Jan 11 02:00:16.379 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:8B:3B:A2:E8:19:95:A6:F0:D6:2E:D4:
  • A0:6E:12:84:D1:DD:02:4A:46:16:97:AF:7C:2E:09:18:
  • 6C:22:26:F7:EE:02:20:58:8F:B3:A9:E4:57:79:F1:BC:
  • 19:05:37:E0:A3:35:34:57:5A:18:42:10:15:6F:53:81:
  • 36:41:7F:41:EA:AD:09
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D1:6E:A9:A5:68:07:7E:66:35:A0:3F:37:A5:DD:BC:03:
  • A5:3C:41:12:14:D4:88:18:F5:E9:31:B3:23:CB:95:04
  • Timestamp : Jan 11 02:00:16.586 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:82:F3:EE:0C:BA:F2:13:02:C3:51:43:
  • 67:2C:54:46:7F:C3:FF:DF:81:19:12:64:35:0C:BA:63:
  • 37:D8:B9:0A:79:02:20:1C:31:AC:DD:30:42:71:8F:AC:
  • 53:C5:EE:49:3A:C3:8B:00:59:43:CC:68:94:A4:59:11:
  • E9:17:75:06:04:B4:14
First seen at:

CN=mx2.safo.at

Certificate chain
  • mx2.safo.at
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption

      • R13
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mx2.safo.at
Alternative Names
  • mx2.safo.at
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R13
validity period
Not valid before
2026-01-11
Not valid after
2026-04-11
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
36:31:B6:6C:C2:C0:E3:4E:EB:AB:91:13:5A:65:AA:CD:3E:80:AA:5F:99:01:80:9F:6E:27:94:C8:4F:9F:C1:C8
SHA1
85:90:EA:60:F7:51:A0:15:81:20:F3:6F:84:0C:F5:F6:13:77:C4:58
X509v3 extensions
subjectKeyIdentifier
  • 48:56:99:7F:51:16:0F:05:83:B7:EE:98:12:4D:DC:5C:85:2D:5F:5E
authorityKeyIdentifier
  • keyid:E7:AB:9F:0F:2C:33:A0:53:D3:5E:4F:78:C8:B2:84:0E:3B:D6:92:33
authorityInfoAccess
  • CA Issuers - URI:http://r13.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r13.c.lencr.org/3.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : CB:38:F7:15:89:7C:84:A1:44:5F:5B:C1:DD:FB:C9:6E:
  • F2:9A:59:CD:47:0A:69:05:85:B0:CB:14:C3:14:58:E7
  • Timestamp : Jan 11 02:00:16.445 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:C8:A0:F7:93:66:69:AB:D1:DD:0B:B7:
  • 41:DA:8F:55:AA:35:E6:9A:5A:1B:A3:13:8B:BF:FB:83:
  • 25:50:67:11:0F:02:21:00:ED:1D:72:E2:EB:5D:EE:F5:
  • FB:1D:C9:20:3D:37:FA:28:8F:99:6F:3F:28:77:53:CA:
  • E7:25:36:5C:DD:21:07:2D
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : E3:23:8D:F2:8D:A2:88:E0:AA:E0:AC:F0:FA:90:C9:85:
  • F0:B6:BF:F5:D2:A5:27:B0:01:FC:1C:44:58:C4:B6:E8
  • Timestamp : Jan 11 02:00:16.523 2026 GMT
  • Extensions: 00:00:05:00:2F:01:A4:3B
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:16:FE:EE:DA:F6:65:61:DD:9B:20:0F:34:
  • A7:7B:90:50:6A:FF:50:AC:A8:DA:ED:92:1F:5E:A4:7C:
  • D2:5B:9B:20:02:21:00:DC:77:64:7F:E2:EC:E9:3F:E8:
  • 53:C1:B6:10:E1:40:9F:40:1A:0D:2D:EE:6D:A5:F0:30:
  • D7:91:23:07:22:04:78