Skip to content
DnsLister Forum

Where domain hunters compare notes

internet.nl STARTTLS test fails on mailbox.org’s mail servers

For anyone who hasn't used it: internet.nl is a free Dutch testing site, run by a non-profit backed by the Dutch government and their national cyber security centre. You give it a domain, it checks whether your mail setup follows modern standards — SPF, DKIM, DMARC, DNSSEC, STARTTLS, DANE — and scores it. Its pass/fail rules follow NCSC-NL's TLS guidelines, which are stricter than what most providers actually run, so a failing grade doesn't mean anything is broken.

I ran my mailbox.org-hosted domain through it (result from internet.nl). Everything DNS-side passes. What fails is the TLS config on mailbox.org's own mail servers (mxext1–4):

  • Cipher suites: all four still offer TLS_RSA_WITH_AES_256_CBC_SHA256 and TLS_RSA_WITH_AES_128_CBC_SHA256. RSA key exchange, so no forward secrecy.
  • DH parameters: DH-4096, marked insufficient. Not a size issue — it looks like a self-generated group instead of ffdhe4096 from RFC 7919, and the test can't verify custom groups.
  • Cipher order: DHE preferred over ECDHE. Slower, no security gain.

Credit where it's due: DNSSEC and DANE are fully set up on all four servers, with a working rollover scheme. That's the part that actually stops an attacker from stripping STARTTLS, and most providers still don't do it. The legacy RSA suites are probably kept for old sending servers that can't do better.

Still, dropping two dead cipher suites and swapping in a standard DH group both seem like small changes.

I opened a ticket three weeks ago and have only gotten the auto-reply. Has anyone here gotten an actual technical answer out of mailbox.org support on this kind of thing, or is the user forum the better route?

Source: r/Mailbox_org · by /u/gnireorb

Leave a Reply

Your email address will not be published. Required fields are marked *