Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Validate your Mail Transfer Agent's opportunistic TLS configuration and cipher suites. Ensure RFC 3207 compliance and verify robust transport-layer encryption against STRIPTLS downgrade attacks.
STARTTLS (RFC 3207) is an SMTP protocol extension that upgrades a plaintext connection to an encrypted TLS session on the same port (25 or 587). The client issues the STARTTLS command during the EHLO exchange, establishing a cryptographic tunnel that protects credentials and message payloads from passive eavesdropping and MITM interception.
Without STARTTLS, email is transmitted in plaintext between servers. Attackers on the network path can read, alter, or inject messages. STARTTLS enforces confidentiality for every hop.
Failing to pair STARTTLS with MTA-STS or DANE, permitting SSLv3/TLS 1.0, and using non-PFS cipher suites are the top misconfigurations leaving servers vulnerable to downgrade attacks.
Type your domain or MX hostname into the STARTTLS checker above.
Our engine connects to your MTA and issues a real STARTTLS negotiation.
Inspect TLS version, cipher suite, certificate validity, and PFS support.
Follow our recommendations to disable weak protocols and add MTA-STS.
Performs an explicit STARTTLS negotiation with your MTA, simulating a full client hello exchange to analyze supported cipher suites, elliptic curve groups, and key exchange algorithms, identifying weak cryptographic primitives.
Detects vulnerability to STRIPTLS and active downgrade attacks by verifying the MTA's compliance with strict transport security policies, including MTA-STS and DNSSEC-backed DANE TLSA constraints.
Conducts a deep cryptographic inspection of the presented certificate chain, validating SAN/CN alignment, revocation status (OCSP/CRL), expiration dates, and verifying trust anchors against root CA stores.
Exhaustively enumerates and grades the symmetric encryption and hashing algorithms negotiated during the STARTTLS handshake, flagging deprecated block ciphers like CBC or weak hashing like SHA-1.
Validates the server's preference for Ephemeral Diffie-Hellman (DHE) or Elliptic Curve (ECDHE) key exchanges, ensuring that past sessions remain secure even if the server's long-term private key is compromised.
Audits the supported TLS versions, ensuring the MTA enforces a minimum of TLS 1.2 and supports TLS 1.3, while aggressively rejecting vulnerable legacy protocols like SSLv3, TLS 1.0, and TLS 1.1.
Automate TLS certificate monitoring, get instant alerts on cipher suite regressions, and receive AI-powered remediation for transport-layer vulnerabilities across all your mail servers.