SSL check results of zelx.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for zelx.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Tue, 21 Jul 2026 09:54:34 +0000

The mailservers of zelx.de can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @zelx.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.zelx.de
2a01:238:42c6:1800:aa55:fdb:8fd8:81aa
10
supported
mail.zelx.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s
mail.zelx.de
85.214.41.111
10
supported
mail.zelx.de
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
2 s

Outgoing Mails

We have received emails from these servers with @zelx.de sender addresses. Test mail delivery

Host TLS Version & Cipher
server.zelx.de (81.169.137.219)
TLSv1.3 TLS_AES_256_GCM_SHA384
server.zelx.de (81.169.200.227)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384

Certificates

First seen at:

CN=mail.zelx.de

Certificate chain
  • mail.zelx.de
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption

      • R13
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption

          • ISRG Root X1 (Certificate is self-signed.)
            • remaining
            • 4096 bit
            • sha256WithRSAEncryption

Subject
Common Name (CN)
  • mail.zelx.de
Alternative Names
  • *.mail.zelx.de
  • mail.zelx.de
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • R13
validity period
Not valid before
2026-05-15
Not valid after
2026-08-13
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
Fingerprints
SHA256
8A:16:81:79:AA:21:E8:CD:7B:17:C6:AB:8B:86:67:2C:22:AD:1F:CA:E3:28:3D:BB:A1:16:20:C3:E5:78:20:00
SHA1
77:4E:27:09:11:C0:AD:BE:DF:E3:0C:7E:3B:F7:44:25:C3:19:DF:00
X509v3 extensions
subjectKeyIdentifier
  • E8:52:4B:94:96:1C:1B:DA:76:DB:D0:DF:FB:11:18:71:FF:74:30:4B
authorityKeyIdentifier
  • keyid:E7:AB:9F:0F:2C:33:A0:53:D3:5E:4F:78:C8:B2:84:0E:3B:D6:92:33
authorityInfoAccess
  • CA Issuers - URI:http://r13.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://r13.c.lencr.org/125.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : May 15 09:42:15.590 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:AC:FF:24:4D:EC:12:20:58:D1:AC:13:
  • 44:0E:7A:21:35:9A:C1:68:DD:90:51:6C:B2:5C:EC:D7:
  • F4:B5:06:4F:E1:02:21:00:D0:3F:F0:6C:39:BD:74:AC:
  • 2B:98:54:1D:8A:1E:74:7F:E9:FD:CB:44:1A:71:FB:1D:
  • 20:CE:33:FC:04:1E:89:BF
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 46:AF:86:3D:3B:3E:E5:9F:A5:77:DE:A8:24:5D:36:B0:
  • D9:ED:22:A2:23:F4:61:77:41:22:94:52:EE:95:50:5F
  • Timestamp : May 15 09:42:15.730 2026 GMT
  • Extensions: 00:00:05:00:06:AA:62:81
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:6D:FB:DF:94:BD:A2:E4:7F:D6:1D:31:36:
  • F4:67:02:06:A2:E4:CD:44:BD:B4:14:22:24:F4:BA:11:
  • DE:35:04:4A:02:20:0C:AB:F1:66:CD:DE:41:77:A2:1F:
  • E6:9A:66:16:C7:8D:96:9C:E0:38:5A:32:1D:38:B2:D2:
  • 6F:0B:12:43:21:89