SSL check results of vf20.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for vf20.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Wed, 05 Aug 2026 15:48:04 +0000

The mailservers of vf20.de can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @vf20.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx.vf20.de
2a03:4000:64:d73::2
10
supported
*.vf20.de
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
5 s
mx.vf20.de
188.68.62.114
10
supported
*.vf20.de
DANE
errors
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
5 s

Outgoing Mails

We have not received any emails from a @vf20.de address so far. Test mail delivery

Certificates

First seen at:

CN=*.vf20.de

Certificate chain
  • *.vf20.de
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE1
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • *.vf20.de
Alternative Names
  • *.vf20.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE1
validity period
Not valid before
2026-06-09
Not valid after
2026-09-07
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
C2:19:92:57:05:A0:16:5E:5A:66:45:9C:63:3C:E9:6A:71:CC:0D:5B:16:B4:E0:D9:A3:1F:AF:6C:68:33:57:4F
SHA1
03:15:85:D3:53:8B:C5:4F:50:1A:53:29:9F:83:DD:20:9A:DB:F4:A6
X509v3 extensions
subjectKeyIdentifier
  • 43:D5:44:3F:2E:E1:6E:E6:A2:0F:18:0E:A5:08:8F:94:5B:4A:FB:56
authorityKeyIdentifier
  • keyid:BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
authorityInfoAccess
  • CA Issuers - URI:http://ye1.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye1.c.lencr.org/59.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 46:AF:86:3D:3B:3E:E5:9F:A5:77:DE:A8:24:5D:36:B0:
  • D9:ED:22:A2:23:F4:61:77:41:22:94:52:EE:95:50:5F
  • Timestamp : Jun 9 15:31:51.228 2026 GMT
  • Extensions: 00:00:05:00:09:18:FE:71
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:E8:A1:30:51:96:A6:EB:CC:43:7D:92:
  • 1C:FB:3E:22:6D:1C:4C:BF:E1:61:F4:0A:5D:90:59:23:
  • A1:3C:34:97:19:02:21:00:9C:B6:01:F0:D3:B2:AB:75:
  • C3:90:39:92:A0:10:CB:46:DD:BF:1C:05:9A:12:6E:60:
  • 5D:38:FE:CC:03:EB:98:50
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D8:09:55:3B:94:4F:7A:FF:C8:16:19:6F:94:4F:85:AB:
  • B0:F8:FC:5E:87:55:26:0F:15:D1:2E:72:BB:45:4B:14
  • Timestamp : Jun 9 15:31:51.216 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:D4:6E:85:8F:98:46:80:04:A8:5E:54:
  • 02:BC:16:1C:BC:15:BD:11:68:DB:CA:B1:91:AD:45:EE:
  • D3:E8:FF:FD:6E:02:21:00:F3:3C:71:AA:FB:6D:61:C1:
  • FF:EB:37:A8:05:43:7A:EA:D8:15:DE:B6:2E:ED:A5:19:
  • 5E:BE:2C:56:4B:AD:43:49

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx.vf20.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid