SSL Security Test of
mail.spyandowl.com

Test the SSL/TLS stack of your web or email server for security, cryptographic flaws and misconfigurations, and compliance with NIST & HIPAA
Free online tool with PDF report
  • Web Server SSL/TLS Security
  • Post-Quantum Cryptography (PQC) Readiness
  • Email Server SSL/TLS Security
  • PCI DSS, GDPR, HIPAA & NIST Compliance
  • SSL Certificate Validity
  • Best-Practices Compliance
Free online tool with PDF report
186,815,042 tests performed
Provided "as is" without any warranty of any kind
506
tests
running
105,206
tests
in 24 hours
Tests in 24 Hours
Share this report:

Summary of mail.spyandowl.com:993 (IMAPS) SSL Security Test

Provided "as is" without any warranty of any kind.
This test was made 105 days ago and may be outdated
Refresh Test
Date/Time:Jun 9th, 2026 20:44 GMT+0
Source IP/Port:216.40.42.134:993
Protocol:IMAPS
Location:Toronto, CanadaCanada
Your final score:
  • A
  • B
  • C
  • F
F
Email server's SPF and DMARC are properly set.
Good configuration
The SSL certificate is untrusted. Modern browsers will display a security warning message to all website visitors. Review and remediate highlighted issues.
Non-compliant with PCI DSS requirements
The server has TLS 1.0 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 30th of June 2018.
Non-compliant with PCI DSS and NIST
The server has TLS 1.1 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 31st of March 2025.
Non-compliant with PCI DSS and NIST
The server supports the most recent and secure TLS protocol version of TLS 1.3.
Good configuration
The tested service seems to be a IMAPS.
Information

Test Results Summary for mail.spyandowl.com

  • SSL/TLS Certificate Analysis
    1 SSL/TLS end-entity certificate detected: the first certificate is an untrusted RSA 2048 bits certificate with issuer R13 valid until August 17, 2026. 1 certificate chain detected. Show details.
  • PCI DSS Compliance Test
    4 of 13 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with PCI DSS: P-256, P-521, P-384, X25519 and X448. There are 2 more issues which make the server non-compliant with PCI DSS: certificates are untrusted, potential Marvin Attack. Show details.
  • NIST and HIPAA Compliance Test
    5 of 13 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with HIPAA: P-256, P-521, P-384, X25519 and X448. There is 1 more issue which makes the server non-compliant with HIPAA: certificate does not include an OCSP responder url. Show details.
  • Industry Best Practices Test
    1 issue related to industry best practices was identified: server supports client-initiated secure renegotiation. Show details.

Compliance Summary for mail.spyandowl.com

  • PCI DSS Compliance Failed: 4 of 13 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with PCI DSS: P-256, P-521, P-384, X25519 and X448. There are 2 more issues which make the server non-compliant with PCI DSS: certificates are untrusted, potential Marvin Attack.
  • HIPAA Compliance Failed: 5 of 13 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with HIPAA: P-256, P-521, P-384, X25519 and X448. There is 1 more issue which makes the server non-compliant with HIPAA: certificate does not include an OCSP responder url.
  • GDPR Compliance Failed: 4 of 13 supported cipher suites are not compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with GDPR: P-256, P-521, P-384, X25519 and X448. There are 2 more issues which make the server non-compliant with GDPR: certificates are untrusted, potential Marvin Attack.
Please wait. Data is loading...
Share this report: