SSL check results of udema.net

NEW You can also bulk check multiple servers.

Discover if the mail servers for udema.net can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sun, 16 Aug 2026 11:19:46 +0000

We can not guarantee a secure connection to the mailservers of udema.net!

Please contact the operator of udema.net and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/udema.net

Servers

Incoming Mails

These servers are responsible for incoming mails to @udema.net addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.udema.net
116.202.155.136
10
supported
mail.mailtarget.net
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
relay.transip.nl
2a01:7c8:7c8::12
Results incomplete
30
supported
not checked
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
relay.transip.nl
2a01:7c8:7c8::29
Results incomplete
30
supported
not checked
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
relay.transip.nl
149.210.149.12
Results incomplete
30
supported
not checked
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
relay.transip.nl
149.210.149.29
Results incomplete
30
supported
not checked
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have not received any emails from a @udema.net address so far. Test mail delivery

Certificates

First seen at:

CN=mail.mailtarget.net

Certificate chain
  • mail.mailtarget.net
    • remaining
    • 256 bit
    • ecdsa-with-SHA384
    • Hostname Mismatch

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • mail.mailtarget.net
Alternative Names
  • mail.mailtarget.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-08-07
Not valid after
2026-11-05
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
38:56:30:2C:9A:C3:38:4C:73:98:18:83:F5:FF:98:A8:E1:6C:D2:84:17:56:B5:37:EE:C6:9C:64:8E:BF:5C:F1
SHA1
98:E6:9C:C8:09:20:1B:91:3D:C7:46:08:89:4F:06:88:62:6B:A0:9E
X509v3 extensions
subjectKeyIdentifier
  • 37:3D:E8:94:BF:49:43:6E:85:B9:FB:43:92:BF:71:59:74:59:92:BF
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/13.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Aug 7 23:04:51.346 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:2D:B4:8C:A5:12:6C:D8:EB:DC:8F:93:C5:
  • E9:72:3A:26:CD:B1:DA:E6:BD:97:5A:54:F4:98:CB:04:
  • 62:7D:4D:63:02:21:00:E9:70:EB:57:01:3F:19:36:20:
  • 86:97:8C:68:68:9E:C6:81:3D:46:D6:0D:47:B4:1E:01:
  • 6F:95:43:2E:66:4C:12
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Aug 7 23:04:51.986 2026 GMT
  • Extensions: 00:00:05:00:32:70:11:7B
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:77:08:FC:76:08:77:2B:BC:02:1D:04:A6:
  • C3:33:D2:0C:3A:73:8B:3F:5A:ED:9D:FD:96:5E:86:93:
  • D0:94:E7:FB:02:21:00:D5:2D:7A:35:B6:F5:BF:57:85:
  • F0:B7:0A:18:99:DF:E2:13:FC:C7:46:3E:43:7B:38:99:
  • BC:CE:49:4C:01:14:CF

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.relay.transip.nl
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.relay.transip.nl
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.relay.transip.nl
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.relay.transip.nl
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid