SSL check results of stalwart.kuzu.sh

NEW You can also bulk check multiple servers.

Discover if the mail servers for stalwart.kuzu.sh can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 31 Aug 2026 11:58:47 +0000

The mailservers of stalwart.kuzu.sh can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @stalwart.kuzu.sh addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
maia.kuzu.sh
2a00:11:fac1:3cff:1::1234
10
supported
*.maia.kuzu.sh
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @stalwart.kuzu.sh address so far. Test mail delivery

Certificates

First seen at:

CN=*.maia.kuzu.sh

Certificate chain
  • *.maia.kuzu.sh
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • *.maia.kuzu.sh
Alternative Names
  • *.maia.kuzu.sh
  • maia.kuzu.sh
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-08-31
Not valid after
2026-11-29
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
8A:F6:EC:A6:B1:7F:EA:7C:A4:FB:B6:3F:1B:01:33:4B:81:C7:E2:C6:33:3B:AA:3C:A6:B3:7A:F2:BB:C7:72:7E
SHA1
6A:C6:71:64:09:C6:E6:BF:B1:8F:4F:60:6C:B2:A3:D5:5D:F1:13:0D
X509v3 extensions
subjectKeyIdentifier
  • 5B:54:00:FF:EF:B9:E6:4F:12:4E:B4:91:C2:6E:57:86:C5:46:BC:16
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/13.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:
  • 82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77
  • Timestamp : Aug 31 10:27:59.187 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:5C:AC:18:EB:9D:2E:27:06:2C:54:A5:FA:
  • 5F:2D:2F:45:08:BD:5F:CE:1C:4C:11:02:0E:D1:01:E3:
  • 86:9F:E4:0C:02:20:5D:B0:F4:D0:D3:47:59:C9:2A:E4:
  • 33:81:EF:71:62:A4:8E:E4:A1:E7:F8:FA:77:31:F4:84:
  • 31:4D:A0:4A:60:E8
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 46:AF:86:3D:3B:3E:E5:9F:A5:77:DE:A8:24:5D:36:B0:
  • D9:ED:22:A2:23:F4:61:77:41:22:94:52:EE:95:50:5F
  • Timestamp : Aug 31 10:27:59.352 2026 GMT
  • Extensions: 00:00:05:00:21:8A:7C:82
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:1B:4C:35:F7:C5:BC:EB:B7:A1:93:BB:3E:
  • 86:3F:46:B4:14:30:DC:82:0A:28:D2:E1:A7:4A:47:32:
  • AB:6C:71:9C:02:21:00:FD:A3:68:0D:BD:83:91:03:4E:
  • 41:3C:E5:6C:BB:1E:09:D3:4B:AB:81:78:62:9E:6A:E1:
  • 57:83:7A:BD:9A:CE:8E