Summary of mail.spyandowl.com:993 (IMAPS) SSL Security Test
Provided "as is" without any warranty of any kind.
This test was made 76 days ago and may be outdated
Refresh Test
Date/Time:Jun 9th, 2026 20:44 GMT+0
Source IP/Port:216.40.42.134:993
Protocol:IMAPS
Location:Toronto, Canada
Your final score:
- A
- B
- C
- F
F
Test Results Summary for mail.spyandowl.com
- 1 SSL/TLS end-entity certificate(s) detected: the first certificate is an untrusted RSA 2048 bits certificate with issuer R13 valid until August 17, 2026. 1 certificate chain(s) detected. Show details.
- 4 of 13 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with PCI DSS: P-256, P-521, P-384, X25519 and X448. There are 2 more issue(s) which make the server non-compliant with PCI DSS: certificates are untrusted, potential Marvin Attack. Show details.
- 5 of 13 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with HIPAA: P-256, P-521, P-384, X25519 and X448. There are 1 more issue(s) which make the server non-compliant with HIPAA: certificate does not provide OCSP revocation information. Show details.
- 1 issue(s) related to industry best practices were identified: server supports client-initiated secure renegotiation. Show details.
Compliance Summary for mail.spyandowl.com
- PCI DSS Compliance Failed: 4 of 13 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with PCI DSS: P-256, P-521, P-384, X25519 and X448. There are 2 more issue(s) which make the server non-compliant with PCI DSS: certificates are untrusted, potential Marvin Attack.
- HIPAA Compliance Failed: 5 of 13 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with HIPAA: P-256, P-521, P-384, X25519 and X448. There are 1 more issue(s) which make the server non-compliant with HIPAA: certificate does not provide OCSP revocation information.
- GDPR Compliance Failed: 4 of 13 supported cipher suites are not compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with GDPR: P-256, P-521, P-384, X25519 and X448. There are 2 more issue(s) which make the server non-compliant with GDPR: certificates are untrusted, potential Marvin Attack.