SSL check results of ultratrimmer.nl

NEW You can also bulk check multiple servers.

Discover if the mail servers for ultratrimmer.nl can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 12 Sep 2026 00:30:29 +0000

The mailservers of ultratrimmer.nl can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @ultratrimmer.nl addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.ultratrimmer.nl
2a07:ae80:100::185:158:164:29
10
supported
*.ultratrimmer.nl
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mail.ultratrimmer.nl
185.158.164.29
10
supported
*.ultratrimmer.nl
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @ultratrimmer.nl address so far. Test mail delivery

Certificates

First seen at:

CN=*.ultratrimmer.nl

Certificate chain
  • *.ultratrimmer.nl
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • *.ultratrimmer.nl
Alternative Names
  • *.ultratrimmer.nl
  • ultratrimmer.nl
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-08-18
Not valid after
2026-11-16
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
91:7E:27:72:44:6C:83:32:FD:62:0E:CD:E7:FD:23:CE:F2:FB:C2:89:AF:23:CC:F4:FA:C9:13:E4:A4:24:C1:AB
SHA1
94:3D:F0:4B:34:F2:C0:B2:95:7E:0C:41:6C:90:15:7A:AB:B1:1F:28
X509v3 extensions
subjectKeyIdentifier
  • 13:50:91:64:FD:26:91:20:EE:98:EA:02:23:B4:99:91:F3:99:D5:F4
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/123.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : Aug 18 14:11:50.069 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:56:20:43:30:3A:19:35:B4:15:02:C8:EF:
  • 3B:47:FF:45:AD:C4:BD:F3:B7:18:64:E4:8A:F9:02:1F:
  • 17:C8:F7:CC:02:20:4F:93:60:79:A9:5B:BA:7D:07:6E:
  • 17:25:0B:EC:0A:37:ED:5E:54:9C:94:3E:59:9D:37:96:
  • EC:3A:9B:9D:C5:79
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Aug 18 14:11:50.364 2026 GMT
  • Extensions: 00:00:05:00:35:E1:DF:F4
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:D6:D5:EB:48:2E:92:B0:2A:24:BA:E5:
  • 53:CE:17:31:6F:CC:42:21:A9:C0:CD:A5:1F:07:3C:79:
  • FD:CE:47:0D:73:02:21:00:F2:9D:B2:E9:CF:FA:B9:5D:
  • 63:41:B6:EC:05:1B:D6:58:08:04:50:CD:E5:D2:31:BC:
  • D5:D9:95:D7:67:53:6E:59

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail.ultratrimmer.nl
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid