SSL check results of zmx.li

NEW You can also bulk check multiple servers.

Discover if the mail servers for zmx.li can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Mon, 05 Oct 2026 00:30:13 +0000

The mailservers of zmx.li can be reached through a secure connection.

Servers

Incoming Mails

These servers are responsible for incoming mails to @zmx.li addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mx.zeta.moe
2a01:4f8:1c18:bcce::
10
supported
*.zeta.moe
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
mx.zeta.moe
178.104.92.42
10
supported
*.zeta.moe
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have not received any emails from a @zmx.li address so far. Test mail delivery

Certificates

First seen at:

CN=*.zeta.moe

Certificate chain
  • *.zeta.moe
    • remaining
    • 256 bit
    • ecdsa-with-SHA384

      • YE2
        • remaining
        • 384 bit
        • ecdsa-with-SHA384

          • Root YE
            • remaining
            • 384 bit
            • ecdsa-with-SHA384

              • ISRG Root X2 (Certificate is self-signed.)
                • remaining
                • 384 bit
                • ecdsa-with-SHA384

Subject
Common Name (CN)
  • *.zeta.moe
Alternative Names
  • *.zeta.moe
  • zeta.moe
Issuer
Country (C)
  • US
Organization (O)
  • Let's Encrypt
Common Name (CN)
  • YE2
validity period
Not valid before
2026-10-01
Not valid after
2026-12-30
This certifcate has been verified for the following usages:
  • Digital Signature
  • TLS Web Server Authentication
Fingerprints
SHA256
3A:89:03:E2:94:22:24:6D:45:70:3D:25:E6:43:CA:56:EE:78:9F:D3:19:5E:AB:49:B3:63:77:5E:E7:C0:6D:7E
SHA1
8A:29:A5:37:3D:F3:3E:42:75:80:95:6E:7E:55:61:1B:DC:0B:B9:4D
X509v3 extensions
subjectKeyIdentifier
  • AC:14:7B:0B:63:7F:95:C8:DD:EB:C0:12:42:D2:D0:9A:4B:E2:5A:85
authorityKeyIdentifier
  • keyid:B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
authorityInfoAccess
  • CA Issuers - URI:http://ye2.i.lencr.org/
certificatePolicies
  • Policy: 2.23.140.1.2.1
crlDistributionPoints
  • Full Name:
  • URI:http://ye2.c.lencr.org/111.crl
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : Oct 1 23:03:49.765 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:2D:09:E0:91:45:1A:14:80:21:A3:75:BA:
  • 0E:56:99:A4:84:11:C0:85:74:45:EE:F8:73:C7:ED:63:
  • 1C:A8:37:07:02:20:76:F3:8F:5B:46:7B:55:50:58:9B:
  • 4E:73:26:63:23:3B:D7:95:C3:BE:DF:07:C1:35:38:54:
  • D4:D5:83:86:B2:46
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 8E:CA:47:0B:AC:DE:6A:F3:A2:06:B0:A4:7A:84:B7:46:
  • FE:1F:C6:BF:95:3E:25:E6:9B:4E:E4:02:48:F3:C6:E8
  • Timestamp : Oct 1 23:03:49.862 2026 GMT
  • Extensions: 00:00:05:00:19:C8:15:BC
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:84:18:AA:3F:28:45:8D:90:9F:7B:79:
  • 19:03:B5:A0:8F:0B:EC:5A:F4:18:E8:99:97:EA:0A:FE:
  • 45:DB:4E:38:AD:02:21:00:A0:74:D9:BB:4F:52:C5:B2:
  • 56:E9:76:EB:28:B2:AB:89:A7:1C:98:92:9A:98:DB:0C:
  • 8E:AF:DC:57:F5:54:5B:27

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mx.zeta.moe
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-256 Hash
valid
valid