SSL check results of sp-con.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for sp-con.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 25 May 2020 09:21:50 +0000

The mailservers of sp-con.de can be reached through an encrypted connection.

However, we found problems that may affect the security.

Servers

Incoming Mails

These servers are responsible for incoming mails to @sp-con.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
exchsrv.sp-con.de
80.147.13.140
10
supported
https.proxy.nul
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s
relay.rzone.de
81.169.145.96
Results incomplete
100
supported
relay.rzone.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have received emails from these servers with @sp-con.de sender addresses. Test mail delivery

Host TLS Version & Cipher
unknown (80.147.13.140)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384

Certificates

First seen at:

CN=relay.rzone.de

Certificate chain
Subject
Common Name (CN)
  • relay.rzone.de
Alternative Names
  • relay.rzone.de
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Organizational Unit (OU)
  • www.digicert.com
Common Name (CN)
  • Thawte RSA CA 2018
validity period
Not valid before
2020-03-06
Not valid after
2021-04-24
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
34:53:C7:4F:D4:E8:F1:BD:28:40:87:2A:F5:63:49:3A:FF:E9:D5:66:DB:C5:A0:7B:F3:8C:0F:91:2B:EC:6A:D3
SHA1
90:77:6D:44:1A:78:DC:4F:CF:84:72:38:86:D5:C4:58:83:6E:63:01
X509v3 extensions
authorityKeyIdentifier
  • keyid:A3:C8:5E:65:54:E5:30:78:C1:05:EA:07:0A:6A:59:CC:B9:FE:DE:5A
subjectKeyIdentifier
  • 0B:8A:47:A5:72:46:95:E7:B1:61:5C:5C:D3:0E:6E:D5:25:F9:EA:5B
crlDistributionPoints
  • Full Name:
  • URI:http://cdp.thawte.com/ThawteRSACA2018.crl
certificatePolicies
  • Policy: 2.16.840.1.114412.1.2
  • CPS: https://www.digicert.com/CPS
  • Policy: 2.23.140.1.2.1
authorityInfoAccess
  • OCSP - URI:http://status.thawte.com
  • CA Issuers - URI:http://cacerts.thawte.com/ThawteRSACA2018.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 7D:3E:F2:F8:8F:FF:88:55:68:24:C2:C0:CA:9E:52:89:
  • 79:2B:C5:0E:78:09:7F:2E:6A:97:68:99:7E:22:F0:D7
  • Timestamp : Mar 6 19:04:09.482 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:1D:6C:2A:BD:82:8C:D2:74:1B:B8:6F:C4:
  • AA:B7:4B:A3:03:40:5F:C6:CD:23:2E:BE:15:57:E8:2C:
  • D8:9F:47:07:02:21:00:C1:0E:51:3F:36:07:4B:2A:66:
  • A0:1D:5C:03:F5:33:36:34:75:EB:5E:77:8C:15:B2:81:
  • AA:84:2D:00:6A:52:8D
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 5C:DC:43:92:FE:E6:AB:45:44:B1:5E:9A:D4:56:E6:10:
  • 37:FB:D5:FA:47:DC:A1:73:94:B2:5E:E6:F6:C7:0E:CA
  • Timestamp : Mar 6 19:04:09.482 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:F8:8B:92:66:69:A4:49:43:03:DE:0D:
  • FC:BA:1A:76:94:44:C6:DA:D0:A1:A9:37:31:F3:88:AB:
  • D5:F8:0F:7E:16:02:20:61:A6:84:99:F7:CF:B9:1E:02:
  • 54:69:7A:3C:3D:EE:23:E3:B9:CE:F8:49:54:4D:9F:D9:
  • 76:A8:24:28:8A:04:A5
First seen at:

CN=https.proxy.nul,OU=Fireware,O=WatchGuard_Technologies

Certificate chain
Subject
Organization (O)
  • WatchGuard_Technologies
Organizational Unit (OU)
  • Fireware
Common Name (CN)
  • https.proxy.nul
Issuer
Organization (O)
  • WatchGuard_Technologies
Organizational Unit (OU)
  • Fireware
Common Name (CN)
  • Fireware HTTPS Proxy (SN 8014036883EA9 2019-01-31 11:04:05 UTC) CA
validity period
Not valid before
2019-01-01
Not valid after
2029-01-28
This certifcate has been verified for the following usages:
  • TLS Web Client Authentication
Fingerprints
SHA256
11:28:FF:C2:A4:A6:CC:C5:56:23:6B:7E:64:AC:E2:F4:B4:73:98:E8:74:58:A1:BA:2A:A6:E7:AE:61:E8:A4:EC
SHA1
BE:E5:58:01:CA:8F:F7:67:38:9D:EF:4E:CF:D4:02:3B:C0:7C:AE:7E