SSL check results of startplatzboerse.com

NEW You can also bulk check multiple servers.

Discover if the mail servers for startplatzboerse.com can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Tue, 08 Sep 2026 20:28:54 +0000

The mailservers of startplatzboerse.com can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @startplatzboerse.com addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
bkp2.mailtory.de
2a0a:4cc0:c1:3c0c::20
10
supported
bkp2.mailtory.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s
bkp2.mailtory.de
159.195.22.28
10
supported
bkp2.mailtory.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
7 s

Outgoing Mails

We have not received any emails from a @startplatzboerse.com address so far. Test mail delivery

Certificates

First seen at:

CN=bkp2.mailtory.de

Certificate chain
  • bkp2.mailtory.de
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • bkp2.mailtory.de
Alternative Names
  • bkp2.mailtory.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-08-05
Not valid after
2026-11-03
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
64:22:57:35:E1:9C:75:38:D8:4F:71:7C:01:C5:77:C6:1A:4E:47:98:0A:8A:3D:CD:DC:86:7E:67:3A:C8:61:60
SHA1
6E:AC:F5:71:34:29:E1:96:8B:2D:36:41:4E:7C:F0:AF:20:53:EF:37
X509v3 extensions
subjectKeyIdentifier
  • 80:67:1F:C5:CF:4E:3F:7F:2F:BA:9C:DD:8E:DF:F3:FC:0E:55:C5:8A
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/33.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Aug 5 11:40:09.825 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:35:9F:C2:0F:04:C2:A1:17:D5:11:DC:30:
  • 98:2C:F6:BB:91:D2:AC:D9:E9:B1:AA:C7:CA:1C:28:58:
  • 7E:FA:EE:AA:02:21:00:BD:9E:F1:D4:70:63:C7:02:DA:
  • E6:F1:66:05:D9:D8:0D:DC:DD:C1:37:CB:0C:B0:7F:68:
  • 85:36:E6:40:87:F4:2B
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A8:26:CB:E3:0A:C6:35:12:46:53:3F:E0:65:F1:4F:19:
  • D9:6E:19:08:13:C4:1D:D9:6D:79:00:B3:12:3C:55:27
  • Timestamp : Aug 5 11:40:10.030 2026 GMT
  • Extensions: 00:00:05:00:18:88:B5:3C
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:C6:BF:54:FB:6D:12:65:BA:70:23:FA:
  • CD:E2:1E:72:63:85:FD:EB:2B:F8:3B:EC:30:DB:FC:61:
  • 78:8C:95:2C:01:02:20:78:68:A1:61:CA:FB:89:C0:8D:
  • E0:94:F3:7E:84:EB:2B:12:C8:E6:C1:88:27:AF:A4:F8:
  • 4B:AF:F9:77:A6:74:21

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.bkp2.mailtory.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid