SSL check results of tincloud.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for tincloud.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Thu, 20 Nov 2025 07:52:26 +0000

We can not guarantee a secure connection to the mailservers of tincloud.de!

Please contact the operator of tincloud.de and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/tincloud.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @tincloud.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.tincloud.de
2a03:4000:1a:8d::28
10
supported
mail.tincloud.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s
mail.tincloud.de
185.162.249.28
10
supported
mail.tincloud.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
4 s
mail2.tincloud.de
2a03:4000:27:4df::84
Results incomplete
50 not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
3 s
mail2.tincloud.de
185.244.193.84
50
supported
mail2.tincloud.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
8 s

Outgoing Mails

We have not received any emails from a @tincloud.de address so far. Test mail delivery

Certificates

First seen at:

CN=mail2.tincloud.de

Certificate chain
  • mail2.tincloud.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption
    • Expired

      • R10
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mail2.tincloud.de
Alternative Names
  • mail2.hu-si.de
  • mail2.tincloud.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R10
validity period
Not valid before
2025-08-19
Not valid after
2025-11-17
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
C5:16:89:F4:F0:68:1C:D0:26:CB:70:E7:8F:97:BB:00:61:52:E0:DA:7C:E4:24:44:2A:21:92:0B:3D:F8:D9:3F
SHA1
5B:A5:BE:0C:43:36:38:D3:FE:AF:45:EB:58:0B:CB:F7:C6:1A:62:C7
X509v3 extensions
subjectKeyIdentifier
  • 56:DC:12:B3:08:FF:54:55:FA:08:B5:D5:AD:F7:D1:D1:6A:EF:80:0E
authorityKeyIdentifier
  • keyid:BB:BC:C3:47:A5:E4:BC:A9:C6:C3:A4:72:0C:10:8D:A2:35:E1:C8:E8
authorityInfoAccess
  • CA Issuers - URI:http://r10.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r10.c.lencr.org/78.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8:
  • 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A
  • Timestamp : Aug 20 00:25:50.138 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:FE:A5:D6:7B:50:BF:31:1C:A2:88:4E:
  • D7:93:46:DF:EB:8D:69:56:17:6B:D5:64:D4:13:CE:1F:
  • 07:38:10:07:DA:02:21:00:99:F3:9E:A5:FD:9B:0E:5B:
  • E1:C3:32:5A:B2:74:04:F6:A4:FE:30:07:7E:CC:19:72:
  • C7:14:F4:97:1A:41:F6:09
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A4:42:C5:06:49:60:61:54:8F:0F:D4:EA:9C:FB:7A:2D:
  • 26:45:4D:87:A9:7F:2F:DF:45:59:F6:27:4F:3A:84:54
  • Timestamp : Aug 20 00:25:54.067 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:3B:3D:8A:B1:43:79:EA:7F:46:31:59:CB:
  • 48:0D:26:DB:CB:0D:09:CB:5D:14:41:1C:4E:57:C3:6C:
  • 55:B6:D0:DD:02:20:78:48:CC:72:89:87:7F:AD:83:7A:
  • 44:1F:AD:E6:CE:F0:AA:6E:79:B2:D2:F5:5B:C5:71:55:
  • 66:92:EF:13:A8:09
First seen at:

CN=mail.tincloud.de

Certificate chain
  • mail.tincloud.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption

      • R12
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mail.tincloud.de
Alternative Names
  • mail.tincloud.de
  • rsd.tincloud.de
  • webmail.hu-si.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R12
validity period
Not valid before
2025-10-14
Not valid after
2026-01-12
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
4A:E5:15:8F:B8:15:95:BC:B5:71:B2:1A:A2:C6:76:11:C2:85:E9:52:67:F8:E9:F7:D7:50:DD:98:74:6D:D8:4B
SHA1
35:3A:55:2F:C1:BC:47:C7:C1:A7:CF:4D:0C:E6:1F:D5:D4:16:22:7D
X509v3 extensions
subjectKeyIdentifier
  • 9A:19:79:69:43:CC:CB:EA:4B:FB:64:31:DD:7D:6D:1B:98:C5:12:4B
authorityKeyIdentifier
  • keyid:00:B5:29:F2:2D:8E:6F:31:E8:9B:4C:AD:78:3E:FA:DC:E9:0C:D1:D2
authorityInfoAccess
  • CA Issuers - URI:http://r12.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r12.c.lencr.org/30.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:
  • E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6
  • Timestamp : Oct 14 19:05:31.209 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:55:0B:9F:98:18:8E:D3:3C:36:D7:EF:6E:
  • 9F:D2:E6:C4:76:E9:27:FB:B1:39:0E:35:65:E3:65:66:
  • B3:7C:49:CF:02:21:00:A1:E6:3E:3A:0D:A6:9B:36:12:
  • 32:3C:BA:9F:44:3F:F9:F3:F7:56:3B:74:95:B9:0C:11:
  • EA:03:DD:EA:13:68:F5
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 19:86:D4:C7:28:AA:6F:FE:BA:03:6F:78:2A:4D:01:91:
  • AA:CE:2D:72:31:0F:AE:CE:5D:70:41:2D:25:4C:C7:D4
  • Timestamp : Oct 14 19:05:31.615 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:D6:3C:60:46:23:EA:53:47:A4:FB:29:
  • BD:8D:09:B5:4C:70:DB:57:9A:4B:62:E5:33:C6:73:D9:
  • CB:83:41:61:33:02:20:53:27:0B:4D:FA:DE:3A:C7:CC:
  • 47:82:26:5D:AB:7E:7B:8E:BB:30:39:A6:BA:8D:81:80:
  • 79:1D:83:6C:7C:0F:D7

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail2.tincloud.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail2.tincloud.de
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail2.tincloud.de
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.tincloud.de
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mail.tincloud.de
  • DANE-TA: Trust Anchor Assertion
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mail.tincloud.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid