SSL check results of web.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for web.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Fri, 10 Apr 2026 18:48:58 +0000

No connection to the mailservers of web.de could be established.

Servers

Incoming Mails

These servers are responsible for incoming mails to @web.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx-ha02.web.de
212.227.17.8
Results incomplete
100
supported
mx.web.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
mx-ha03.web.de
212.227.15.17
Results incomplete
100
supported
mx.web.de
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have received emails from these servers with @web.de sender addresses. Test mail delivery

Host TLS Version & Cipher
unknown (IPv6:2a05:8b81:1000:ac::d5e3)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
mout.web.de (212.227.17.11)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.17.12)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (217.72.192.78)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.15.3)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.15.4)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout.web.de (212.227.15.14)
TLSv1.3 TLS_AES_256_GCM_SHA384
mout02.posteo.de (185.67.36.142)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384

Certificates

First seen at:

CN=mx.web.de,O=1&1 Mail & Media GmbH,L=Montabaur,ST=Rheinland-Pfalz,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Rheinland-Pfalz
Locality (L)
  • Montabaur
Organization (O)
  • 1&1 Mail & Media GmbH
Common Name (CN)
  • mx.web.de
Alternative Names
  • mx.web.de
  • mx-ha02.web.de
  • mx-ha03.web.de
  • dhmx01.web.de
  • dhmx02.web.de
Issuer
Country (C)
  • DE
Organization (O)
  • Deutsche Telekom Security GmbH
Common Name (CN)
  • Telekom Security ServerID OV Class 2 CA
validity period
Not valid before
2026-01-08
Not valid after
2027-01-12
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Client Authentication
  • TLS Web Server Authentication
Fingerprints
SHA256
6C:CA:4F:05:DD:EA:D9:B7:4B:87:BB:12:8C:FF:CB:90:91:F4:AA:5F:E2:7C:11:F8:F6:62:F7:02:CC:FA:B1:63
SHA1
C7:0A:1D:7E:EA:59:97:C8:13:9F:00:4D:11:97:A2:16:42:20:93:65
X509v3 extensions
authorityKeyIdentifier
  • keyid:1C:05:93:B1:7F:A8:34:30:8C:52:E0:96:40:A0:72:A3:10:5D:E0:FF
subjectKeyIdentifier
  • 6E:9C:65:65:3B:EA:16:37:0F:F9:F7:07:3E:EF:7B:E6:BC:3A:B4:E4
certificatePolicies
  • Policy: 2.23.140.1.2.2
  • CPS: http://docs.serverid.telesec.de/cps/serverid.htm
crlDistributionPoints
  • Full Name:
  • URI:http://crl.serverid.telesec.de/rl/Telekom_Security_ServerID_OV_Class_2_CA.crl
authorityInfoAccess
  • OCSP - URI:http://ocsp.serverid.telesec.de/ocspr
  • CA Issuers - URI:http://crt.serverid.telesec.de/crt/Telekom_Security_ServerID_OV_Class_2_CA.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : A2:81:00:18:73:4E:17:6E:1D:47:E0:95:40:F3:81:BA:
  • 54:66:97:CD:63:A8:43:50:71:6E:B8:09:4E:DA:F1:0D
  • Timestamp : Jan 8 07:43:53.550 2026 GMT
  • Extensions: 00:00:05:00:01:24:5F:72
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:D0:78:52:CF:98:47:D2:05:7B:A3:D4:
  • FD:73:1C:93:46:30:52:81:BE:0F:88:53:65:F2:5A:89:
  • 39:38:3D:84:F3:02:20:1D:13:37:65:4B:A9:C5:24:25:
  • 08:29:8F:06:3E:F6:16:71:02:E6:1F:E2:F6:C9:E7:F1:
  • 5E:45:1B:4C:10:9D:AC
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 1C:9F:68:2C:E9:FA:F0:45:69:50:F8:1B:96:8A:87:DD:
  • DB:32:10:D8:4C:E6:C8:B2:E3:82:52:4A:C4:CF:59:9F
  • Timestamp : Jan 8 07:43:53.442 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:96:E4:47:1F:89:F7:CC:9D:F6:DA:C7:
  • CC:C2:BE:51:6B:EB:B0:D3:79:A8:F5:26:FA:4F:BD:DA:
  • E8:89:0E:89:1B:02:20:5E:50:55:5F:30:AD:44:E0:94:
  • 95:8B:6C:34:37:3D:D3:BA:92:34:BA:F5:41:74:FD:D7:
  • 31:B7:CB:A1:A3:2F:2F
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 8E:CA:47:0B:AC:DE:6A:F3:A2:06:B0:A4:7A:84:B7:46:
  • FE:1F:C6:BF:95:3E:25:E6:9B:4E:E4:02:48:F3:C6:E8
  • Timestamp : Jan 8 07:43:54.186 2026 GMT
  • Extensions: 00:00:05:00:01:30:8F:55
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:F4:94:17:1D:0D:65:AB:B4:04:86:62:
  • 28:A9:07:DB:D3:62:62:10:8F:50:7D:CB:97:34:D8:C3:
  • 35:0A:37:CB:7F:02:21:00:B8:10:53:5B:B9:0B:13:71:
  • 3B:D3:2E:5A:14:48:89:AE:A1:3C:E5:DE:0C:2A:4D:1A:
  • EC:C3:C9:79:C1:14:A4:41
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 59:6E:6C:33:86:94:B2:59:72:A2:56:C8:A0:E8:DD:90:
  • 4A:76:E8:08:3D:DA:87:3B:01:08:38:28:14:3C:EE:59
  • Timestamp : Jan 8 07:43:53.250 2026 GMT
  • Extensions: 00:00:05:00:00:09:F8:38
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:4A:5D:E4:34:76:88:4D:37:39:10:98:44:
  • 07:14:4B:9C:EA:2E:84:03:51:1E:8B:F5:4F:19:EB:8E:
  • E0:24:0F:72:02:21:00:B3:42:96:DD:EC:C9:20:54:58:
  • 47:0C:E8:E7:28:94:4E:39:ED:4A:7A:00:F0:CF:4D:E6:
  • 7C:29:FA:5D:51:A0:B0
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 60:4C:9A:AF:7A:7F:77:5F:01:D4:06:FC:92:0D:C8:99:
  • EB:0B:1C:7D:F8:C9:52:1B:FA:FA:17:77:3B:97:8B:C9
  • Timestamp : Jan 8 07:43:53.169 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:38:19:B3:71:17:BD:C5:A3:5A:2C:0F:13:
  • 88:F1:7D:C5:4D:29:3B:B3:03:77:68:C3:D1:21:A2:AA:
  • A5:5F:E1:5A:02:21:00:B9:00:F2:10:86:77:1D:2F:0B:
  • 49:DB:02:4B:82:10:A9:DF:DD:AE:2C:6B:1C:D3:2E:47:
  • 82:F2:DE:7B:10:E2:AF

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx-ha02.web.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mx-ha02.web.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid
_25._tcp.mx-ha03.web.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
_25._tcp.mx-ha03.web.de
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid