SSL check results of tuxchen.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for tuxchen.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 05 Oct 2026 12:57:45 +0000

The mailservers of tuxchen.de can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @tuxchen.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.tuxchen.de
2001:4ba0:cafe:14b::1
10
supported
mail.tuxchen.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
9 s
mail.tuxchen.de
89.163.221.137
10
supported
mail.tuxchen.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
5 s

Outgoing Mails

We have not received any emails from a @tuxchen.de address so far. Test mail delivery

Certificates

First seen at:

CN=mail.tuxchen.de

Certificate chain
  • mail.tuxchen.de
    • remaining
    • 384 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail.tuxchen.de
Alternative Names
  • mail.tuxchen.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-09-26
Not valid after
2026-12-25
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
19:31:28:75:3E:C5:21:7E:05:0C:96:BB:51:5E:5E:1E:49:39:63:37:F2:83:D6:62:48:4F:4E:D6:D9:CD:02:6B
SHA1
8F:DF:6C:1F:0C:85:4B:32:56:2A:18:E5:0D:0F:6A:35:F1:96:7C:7E
X509v3 extensions
subjectKeyIdentifier
  • 58:D1:90:E7:3A:55:66:3C:50:B2:03:A1:01:40:4A:20:C9:91:BC:8F
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/66.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : CB:38:F7:15:89:7C:84:A1:44:5F:5B:C1:DD:FB:C9:6E:
  • F2:9A:59:CD:47:0A:69:05:85:B0:CB:14:C3:14:58:E7
  • Timestamp : Sep 26 20:30:31.549 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:F1:5E:2B:0D:19:B6:F4:23:69:78:8F:
  • E2:AD:B1:23:5A:C2:C1:E6:CC:54:B8:C1:BB:40:52:28:
  • 98:E9:6F:D3:D0:02:20:51:4E:F5:8E:F8:E8:CD:BC:5D:
  • 74:48:7A:23:BE:81:34:4F:A2:74:D3:BC:61:82:A3:64:
  • 57:68:23:4B:5F:18:34
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Sep 26 20:30:32.586 2026 GMT
  • Extensions: 00:00:05:00:45:84:D2:4E
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:FC:22:E9:30:E5:00:49:A9:36:E0:F6:
  • EE:FF:0D:82:F6:28:F3:8E:A6:B9:F8:39:F1:D0:80:27:
  • 5F:BC:7F:05:A8:02:21:00:F3:BB:C9:D2:84:EC:33:DB:
  • 72:30:86:0B:6D:DD:51:20:D1:09:62:D3:BF:51:54:8C:
  • FD:46:86:64:14:99:62:D0

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail.tuxchen.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid