For anyone who hasn't used it: internet.nl is a free Dutch testing site, run by a non-profit backed by the Dutch government and their national cyber security centre. You give it a domain, it checks whether your mail setup follows modern standards — SPF, DKIM, DMARC, DNSSEC, STARTTLS, DANE — and scores it. Its pass/fail rules follow NCSC-NL's TLS guidelines, which are stricter than what most providers actually run, so a failing grade doesn't mean anything is broken.
I ran my mailbox.org-hosted domain through it (result from internet.nl). Everything DNS-side passes. What fails is the TLS config on mailbox.org's own mail servers (mxext1–4):
- Cipher suites: all four still offer
TLS_RSA_WITH_AES_256_CBC_SHA256andTLS_RSA_WITH_AES_128_CBC_SHA256. RSA key exchange, so no forward secrecy. - DH parameters: DH-4096, marked insufficient. Not a size issue — it looks like a self-generated group instead of
ffdhe4096from RFC 7919, and the test can't verify custom groups. - Cipher order: DHE preferred over ECDHE. Slower, no security gain.
Credit where it's due: DNSSEC and DANE are fully set up on all four servers, with a working rollover scheme. That's the part that actually stops an attacker from stripping STARTTLS, and most providers still don't do it. The legacy RSA suites are probably kept for old sending servers that can't do better.
Still, dropping two dead cipher suites and swapping in a standard DH group both seem like small changes.
I opened a ticket three weeks ago and have only gotten the auto-reply. Has anyone here gotten an actual technical answer out of mailbox.org support on this kind of thing, or is the user forum the better route?
Source: r/Mailbox_org · by /u/gnireorb