My Mailcow installation has a 94% score on the Internet.nl email tests which is great. I’m wondering if a future mailcow update will fix some of the errors that still appear. Or are we on our own? I haven’t learned how to fix them myself yet, but the internet.nl fediverse account sent some tips: https://mastodon.nl/@internet_nl/116563691424080742
Here’s a list of the internet.nl errors with the current July 2026 version of Mailcow:
… TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 insufficient
… TLS_RSA_WITH_CAMELLIA_256_CBC_SHA insufficient
… TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 insufficient
… TLS_RSA_WITH_CAMELLIA_128_CBC_SHA insufficient
… TLS_RSA_WITH_ARIA_256_GCM_SHA384 insufficient
… TLS_RSA_WITH_ARIA_128_GCM_SHA256 insufficient
… TLS_RSA_WITH_AES_256_GCM_SHA384 insufficient
… TLS_RSA_WITH_AES_256_CCM_8 insufficient
… TLS_RSA_WITH_AES_256_CCM insufficient
… TLS_RSA_WITH_AES_256_CBC_SHA256 insufficient
… TLS_RSA_WITH_AES_256_CBC_SHA insufficient
… TLS_RSA_WITH_AES_128_GCM_SHA256 insufficient
… TLS_RSA_WITH_AES_128_CCM_8 insufficient
… TLS_RSA_WITH_AES_128_CCM insufficient
… TLS_RSA_WITH_AES_128_CBC_SHA256 insufficient
… TLS_RSA_WITH_AES_128_CBC_SHA insufficient
… TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA insufficient
… TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA insufficient
… TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA insufficient
… TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA insufficient
… TLS_DHE_RSA_WITH_AES_256_CCM_8 insufficient
… TLS_DHE_RSA_WITH_AES_256_CBC_SHA insufficient
… TLS_DHE_RSA_WITH_AES_128_CCM_8 insufficient
… TLS_DHE_RSA_WITH_AES_128_CBC_SHA insufficient
… TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 phase out
… TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 phase out
… TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 phase out
… TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 phase out
… TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 phase out
… TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 phase out
… TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 phase out
… TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 phase out
… TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 phase out
… TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 phase out
… TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 phase out
… TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 phase out
… TLS_DHE_RSA_WITH_AES_256_CCM phase out
… TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 phase out
… TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 phase out
… TLS_DHE_RSA_WITH_AES_128_CCM phase out
… TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 phase out
Cipher suite order preference is not set to descending order of their security levels:
Cipher suite preferred by server Expected preferred cipher suite
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
Mail server supports insufficiently secure parameters for Diffie-Hellman key exchange: DH-2048
Mail server supports one or more insufficiently secure hash functions for key exchange: SHA1
The public key of at least one of your mail server certificates is based on a signing algorithm with parameters that should be phased out as they are weaker:
YR1: RSAPublicKey-2048
… phase out
Mail server domains does not have an active DANE scheme for a reliable rollover of certificate keys.