SSL check results of was-recht.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for was-recht.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Tue, 07 Jul 2026 00:30:43 +0000

We can not guarantee a secure connection to the mailservers of was-recht.de!

Please contact the operator of was-recht.de and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/was-recht.de

Servers

Incoming Mails

These servers are responsible for incoming mails to @was-recht.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
qrz6web01.quintalog.net
2a03:4000:6:7592::cafe
5
supported
qrz6web01.quintalog.net
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
1 s
qrz6web01.quintalog.net
37.120.175.46
5
supported
qrz6web01.quintalog.net
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
1 s
mx1.was-recht.de
37.120.175.46
10
supported
qrz6web01.quintalog.net
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
1 s
mx0.was-recht.de
80.237.138.5
Results incomplete
50
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
r2d2.0n4.de
2a0a:4cc0:1:198::cafe
100
supported
foo.0n4.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
r2d2.0n4.de
89.58.61.120
100
supported
foo.0n4.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s

Outgoing Mails

We have not received any emails from a @was-recht.de address so far. Test mail delivery

Certificates

First seen at:

CN=foo.0n4.de

Certificate chain
  • foo.0n4.de
    • remaining
    • 4096 bit
    • sha256WithRSAEncryption
    • Hostname Mismatch

      • R12
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • foo.0n4.de
Alternative Names
  • foo.0n4.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R12
validity period
Not valid before
2026-05-13
Not valid after
2026-08-11
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
Fingerprints
SHA256
88:41:DC:42:71:8C:5D:2C:0C:44:42:D3:56:BD:0A:EB:A6:9C:09:92:1D:2F:2A:89:8A:2F:5A:45:7C:74:1E:83
SHA1
0B:86:4C:5D:AD:19:1B:48:E7:07:45:DA:64:72:0F:C7:02:03:7A:7F
X509v3 extensions
subjectKeyIdentifier
  • 0B:25:1C:12:8D:0C:2D:F5:78:B0:A1:B5:DC:02:7F:8C:75:A0:15:2B
authorityKeyIdentifier
  • keyid:00:B5:29:F2:2D:8E:6F:31:E8:9B:4C:AD:78:3E:FA:DC:E9:0C:D1:D2
authorityInfoAccess
  • CA Issuers - URI:http://r12.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r12.c.lencr.org/50.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:
  • 82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77
  • Timestamp : May 13 08:50:16.151 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:FD:E3:E7:11:4B:CD:AC:3C:E0:73:6A:
  • 6A:EC:83:5C:C6:6F:4D:53:84:D1:43:D7:6E:D0:A9:E6:
  • E1:1E:FA:22:95:02:20:0D:6B:22:F4:B9:7A:DD:62:54:
  • 5B:2A:CD:87:ED:F4:B2:C4:C1:03:1E:E2:FC:C8:09:7A:
  • D2:02:E9:77:FB:FF:41
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 46:AF:86:3D:3B:3E:E5:9F:A5:77:DE:A8:24:5D:36:B0:
  • D9:ED:22:A2:23:F4:61:77:41:22:94:52:EE:95:50:5F
  • Timestamp : May 13 08:50:16.329 2026 GMT
  • Extensions: 00:00:05:00:06:7B:5A:5F
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:C1:05:71:F8:A2:37:C0:09:10:4D:32:
  • D7:DF:C1:51:36:1E:A2:81:41:1F:87:6C:86:5E:7F:24:
  • C8:11:4A:DF:94:02:20:1E:C7:A6:70:AF:3E:21:EA:47:
  • 79:FC:8C:FF:CD:EC:29:4F:27:23:37:09:C8:ED:23:1B:
  • 74:BB:4D:35:40:1D:8E
First seen at:

CN=qrz6web01.quintalog.net

Certificate chain
  • qrz6web01.quintalog.net
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • qrz6web01.quintalog.net
Alternative Names
  • qrz6web01.quintalog.net
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-07-04
Not valid after
2026-10-02
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
1B:2C:09:19:2C:25:DA:33:75:7C:9B:BD:B2:C9:11:A6:9B:E6:AA:D2:DF:FF:20:CB:44:B5:FA:C2:B2:13:95:39
SHA1
16:2C:40:8D:17:2A:86:BC:92:1A:B3:FB:BA:1D:D0:AD:9A:7B:76:C4
X509v3 extensions
subjectKeyIdentifier
  • C9:CA:30:5B:DA:77:DB:E3:DE:38:E5:06:B7:12:63:3F:6A:67:42:B7
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/81.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : Jul 4 09:41:52.830 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:54:45:A9:52:BC:E2:C4:97:5E:F2:B8:FA:
  • 3A:3A:0B:7B:6A:F5:A0:99:0F:15:9D:A1:1A:AB:B0:44:
  • 65:24:09:B4:02:20:1E:31:F4:C6:FE:24:96:CB:A7:D1:
  • A4:19:ED:24:49:37:68:73:8C:73:75:D1:47:23:79:CF:
  • 7B:84:DF:F2:A8:38
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
  • D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
  • Timestamp : Jul 4 09:41:53.725 2026 GMT
  • Extensions: 00:00:05:00:26:0B:60:F8
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:C5:7B:44:F9:62:D8:4F:D5:47:4B:39:
  • F1:9D:D8:91:96:A5:79:6A:CA:0F:68:AF:EF:74:9A:C7:
  • 62:AB:3E:7E:DE:02:20:3B:E5:43:56:9A:BB:CF:3A:C6:
  • 06:5C:B2:26:9A:82:BC:0A:D1:01:BB:F8:61:72:FD:CE:
  • 88:74:76:AD:67:C0:6B