SSL check results of tirox.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for tirox.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 14 Aug 2026 00:30:24 +0000

We can not guarantee a secure connection to the mailservers of tirox.de!

Please contact the operator of tirox.de and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/tirox.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @tirox.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail1.tirox.de
178.254.21.194
10
supported
dedi.tirox.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
mail3.tirox.de
5.135.182.189
Results incomplete
30
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have not received any emails from a @tirox.de address so far. Test mail delivery

Certificates

First seen at:

CN=dedi.tirox.de

Certificate chain
  • dedi.tirox.de
    • remaining
    • 256 bit
    • ecdsa-with-SHA384
    • Hostname Mismatch

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • dedi.tirox.de
Alternative Names
  • dedi.tirox.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-06-13
Not valid after
2026-09-11
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
A8:7E:2F:C6:A9:AB:CA:51:BE:35:6E:A3:BB:21:A1:64:DA:87:38:3C:73:69:3D:EE:61:3A:D7:A8:44:BC:1A:E8
SHA1
2E:C4:27:38:33:60:15:81:98:DC:AB:05:E2:95:88:42:63:69:7D:4F
X509v3 extensions
subjectKeyIdentifier
  • D4:6B:4E:E4:4A:FB:3F:8E:E9:3F:07:92:41:51:BB:3A:E9:B6:03:7E
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/5.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : Jun 13 03:29:42.834 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:D9:2F:42:B5:92:11:69:F7:2A:3C:7B:
  • F2:0C:24:36:BE:13:93:62:D7:C3:D2:08:52:0F:C6:F9:
  • E7:F0:E7:56:3E:02:21:00:CD:B0:7C:FE:CB:DF:BA:D7:
  • B3:A1:65:59:AF:1B:F9:FE:92:16:3D:79:F3:A0:91:D5:
  • 0E:C7:F9:B4:14:A5:68:32
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Jun 13 03:29:43.700 2026 GMT
  • Extensions: 00:00:05:00:1E:35:0A:54
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:5F:C2:B7:51:1E:23:47:DC:B6:C0:0C:6F:
  • 61:50:BC:94:4C:EA:1E:E8:AA:12:12:9D:5D:69:F2:E9:
  • 0F:B6:7A:4D:02:21:00:98:00:E4:6F:FB:8D:B1:ED:3F:
  • EB:9C:D5:4F:65:47:91:CF:0D:35:E9:44:CA:E4:1A:E8:
  • 35:F7:27:AE:5D:2B:57