Summary of exchange.iinet.net.au:993 (IMAPS) SSL Security Test
Provided "as is" without any warranty of any kind.
This test was made 1520 days ago and may be outdated
Refresh Test
Date/Time:Jul 21st, 2022 06:28 GMT+0
Source IP/Port:203.113.243.32:993
Protocol:IMAPS
Location:Arumpo, Australia
Your final score:
- A
- B
- C
- F
C
Email server's SPF is properly set.
Good configuration
The server has TLS 1.0 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 30th of June 2018.
Non-compliant with PCI DSS and NIST
The server has TLS 1.1 enabled. NIST recommends to drop TLS 1.1 support since SP 800-52 REV. 2
Information
The tested service seems to be a IMAPS.
Information
Test Results Summary for exchange.iinet.net.au
- 1 SSL/TLS end-entity certificate detected: the first certificate is a trusted RSA 2048 bits certificate with issuer Entrust Certification Authority - L1K valid until June 17, 2023. 1 certificate chain detected. Show details.
- 3 of 11 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with PCI DSS: P-256. No additional PCI DSS compliance issues were identified. Show details.
- 3 of 11 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with HIPAA: P-256. There are 2 more issues which make the server non-compliant with HIPAA: server does not support OCSP stapling, server does not support extended master sECret. Show details.
- 3 issues related to industry best practices were identified: server does not support TLS 1.3, server does not prefer cipher suites providing PFS, server supports client-initiated secure renegotiation. Show details.
Compliance Summary for exchange.iinet.net.au
- PCI DSS Compliance Failed: 3 of 11 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with PCI DSS: P-256. No additional PCI DSS compliance issues were identified.
- HIPAA Compliance Failed: 3 of 11 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with HIPAA: P-256. There are 2 more issues which make the server non-compliant with HIPAA: server does not support OCSP stapling, server does not support extended master sECret.
- GDPR Compliance Failed: 3 of 11 supported cipher suites are not compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with GDPR: P-256. No additional GDPR compliance issues were identified.