SSL check results of web.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for web.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 21 Apr 2025 09:19:11 +0000

No connection to the mailservers of web.de could be established.

Servers

Incoming Mails

These servers are responsible for incoming mails to @web.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx-ha02.web.de
212.227.17.8
Results incomplete
100
supported
mx.web.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
mx-ha03.web.de
212.227.15.17
Results incomplete
100
supported
mx.web.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have received emails from these servers with @web.de sender addresses. Test mail delivery

Host TLS Version & Cipher
unknown (IPv6:2a05:8b81:1000:ac::d5e3)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
mout.web.de (212.227.17.11)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.17.12)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (217.72.192.78)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.15.3)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.15.4)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.15.14)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout02.posteo.de (185.67.36.142)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384

Certificates

First seen at:

CN=mx.web.de,O=1&1 Mail & Media GmbH,L=Montabaur,ST=Rheinland-Pfalz,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Rheinland-Pfalz
Locality (L)
  • Montabaur
Organization (O)
  • 1&1 Mail & Media GmbH
Common Name (CN)
  • mx.web.de
Alternative Names
  • mx.web.de
  • mx-ha02.web.de
  • mx-ha03.web.de
  • dhmx01.web.de
  • dhmx02.web.de
Issuer
Country (C)
  • DE
Organization (O)
  • Deutsche Telekom Security GmbH
Common Name (CN)
  • Telekom Security ServerID OV Class 2 CA
validity period
Not valid before
2025-02-19
Not valid after
2026-02-23
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Client Authentication
  • TLS Web Server Authentication
Fingerprints
SHA256
AB:21:B5:81:65:59:7B:D1:A8:0D:41:95:3E:76:86:7C:EE:B9:B6:4F:4B:FF:D3:9C:E0:92:8F:B4:EA:09:1B:DC
SHA1
10:DB:4C:0C:DE:6F:DC:E7:EE:50:C1:F6:DB:71:F4:EB:6C:07:2D:EC
X509v3 extensions
authorityKeyIdentifier
  • keyid:1C:05:93:B1:7F:A8:34:30:8C:52:E0:96:40:A0:72:A3:10:5D:E0:FF
subjectKeyIdentifier
  • CD:0B:DA:C2:3A:E2:6C:46:2C:32:E0:94:9B:97:D2:6F:89:C9:D7:71
certificatePolicies
  • Policy: 2.23.140.1.2.2
  • CPS: http://docs.serverid.telesec.de/cps/serverid.htm
crlDistributionPoints
  • Full Name:
  • URI:http://crl.serverid.telesec.de/rl/Telekom_Security_ServerID_OV_Class_2_CA.crl
authorityInfoAccess
  • OCSP - URI:http://ocsp.serverid.telesec.de/ocspr
  • CA Issuers - URI:http://crt.serverid.telesec.de/crt/Telekom_Security_ServerID_OV_Class_2_CA.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 0E:57:94:BC:F3:AE:A9:3E:33:1B:2C:99:07:B3:F7:90:
  • DF:9B:C2:3D:71:32:25:DD:21:A9:25:AC:61:C5:4E:21
  • Timestamp : Feb 19 07:05:20.572 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:CF:75:4A:ED:11:9D:DC:82:9F:1D:A9:
  • E6:73:F6:CA:B5:0D:90:8E:61:32:D1:63:E0:C5:21:04:
  • 0C:99:E2:33:F7:02:20:5F:06:B0:29:BE:72:A3:B2:A4:
  • BA:33:51:07:99:0D:FB:08:F6:D1:EA:E8:27:8A:BF:6D:
  • 79:70:E5:E5:F1:D4:A8
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:
  • E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6
  • Timestamp : Feb 19 07:05:21.286 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:B6:CE:56:C7:13:99:BB:C5:8A:7E:EE:
  • C8:C4:CA:81:7D:38:FF:B2:FF:D5:C3:F3:50:01:66:97:
  • F9:F3:D3:4B:40:02:21:00:FF:19:FE:F8:D0:60:3D:6A:
  • 57:74:8A:48:5F:CD:29:64:CC:89:0E:01:63:3D:38:6C:
  • D6:CC:B4:39:88:6A:E7:37
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 19:86:D4:C7:28:AA:6F:FE:BA:03:6F:78:2A:4D:01:91:
  • AA:CE:2D:72:31:0F:AE:CE:5D:70:41:2D:25:4C:C7:D4
  • Timestamp : Feb 19 07:05:20.338 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:95:2A:A6:50:C6:D9:1B:6E:9B:4E:08:
  • 8F:FF:65:03:E2:88:ED:17:10:31:39:CB:6A:E3:FF:D1:
  • 9F:85:F7:21:60:02:21:00:FA:0B:52:3E:B6:8D:79:66:
  • 84:7D:AF:87:2C:C9:1A:47:AA:58:46:96:51:A1:41:50:
  • 58:75:F8:6E:95:6F:26:77
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 49:9C:9B:69:DE:1D:7C:EC:FC:36:DE:CD:87:64:A6:B8:
  • 5B:AF:0A:87:80:19:D1:55:52:FB:E9:EB:29:DD:F8:C3
  • Timestamp : Feb 19 07:05:20.353 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:ED:0D:96:8A:CE:C7:A5:E4:32:78:BE:
  • 20:97:E7:0E:AB:32:55:A9:EC:F9:66:1C:E7:00:BD:34:
  • ED:50:E0:71:C6:02:21:00:87:4B:79:63:6F:C9:D2:D0:
  • 96:19:98:AC:0A:39:3F:E6:F3:8A:6E:36:23:11:84:62:
  • DD:76:5D:4A:70:1B:29:D2
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 64:11:C4:6C:A4:12:EC:A7:89:1C:A2:02:2E:00:BC:AB:
  • 4F:28:07:D4:1E:35:27:AB:EA:FE:D5:03:C9:7D:CD:F0
  • Timestamp : Feb 19 07:05:20.517 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:F8:30:17:D9:EA:06:65:5D:0D:19:9F:
  • 31:DA:F4:AF:AA:37:7C:CC:00:38:81:6B:A9:38:02:30:
  • 1F:D8:E3:87:02:02:21:00:EF:C3:76:43:CD:A0:CD:11:
  • C9:B9:DF:7E:F3:83:75:02:BB:37:9A:3F:46:FD:F2:E1:
  • 9E:4C:DB:26:9E:EF:07:3D

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx-ha02.web.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx-ha03.web.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid