What checkemailsecurity.com is used for
Panotect helps organisations build email resilience and close the gaps before attackers find and exploit them.
Panotect uses this domain to measure how well an organisation's mail servers protect email while it travels between organisations (transport encryption, known as TLS). The connections come from:
emailcompliance.checkemailsecurity.com
They go to the mail servers of the domain being assessed. Each one reads what the server already tells every sender, then closes politely. The organisation receives a clear picture of how resilient its email encryption is, and what business threats can be reduced with transport security adjustments.
If you found these connections in your mail logs
They are part of a Panotect email assessment. They come only from the hosts listed below. Each identifies itself in the same way a well-run mail server does: its name resolves to its address, and the address resolves back to the name (forward-confirmed reverse DNS).
| Connecting host | Address | Port |
|---|---|---|
emailcompliance.checkemailsecurity.com | 188.40.192.61 | 25 |
Results are reused for a period, so a repeat assessment of the same domain usually opens no new connection.
Who asks for an assessment
Requested by the organisation
Most assessments are requested by someone responsible for an organisation's security or risk, such as a board member, a senior executive, the chief information security officer or a risk officer.
Requested by its security provider
Others are requested by the managed security services provider that looks after the organisation's systems, as part of the service it provides.
Peer group and regulator benchmarks
Some form part of benchmarks, which let constituent organisations or regulators compare email resilience across industry, sector or national peers.
If an assessment is unexpected, it may have been requested elsewhere in your organisation. Write to us and we will tell you which kind it is.
Why this matters beyond one organisation
Much of the email risk an organisation carries comes from the organisations it corresponds with: its suppliers, customers and partners. When any of them can be impersonated easily, or sends mail that can be read on the way, the risk reaches everyone who trusts their messages.
Each organisation that strengthens its email makes impersonation and interception harder for everyone it deals with. Benchmarks show where a sector stands, so the organisations in it can see what good looks like and improve together.
What happens on each connection
Each connection reads what your mail server publishes to every sender, then ends
with a polite goodbye (QUIT):
connect to port 25 <- 220 your server's greeting EHLO emailcompliance.checkemailsecurity.com <- 250 the capabilities your server advertises STARTTLS (only if your server offers it) <- 220 ready <encryption handshake: read the certificate and the agreed settings> QUIT <- 221 goodbye
- No message is sent and no mailbox is addressed: the commands that start a
delivery (
MAIL FROM,RCPT TO) are not used. - Some connections only read your server's greeting to confirm it answers, then close.
- One assessment may open a few connections to the same server, each offering a narrower choice of encryption settings, to find the weakest one it accepts.
What is recorded
Only what your server tells any sender that connects: its greeting, the capabilities it advertises, whether it offers encryption, which encryption versions and settings it agrees to, and the certificate it presents.
Why your server may count these as unsuccessful
Some mail servers count a connection as successful only when it delivers a message. These connections never deliver, so a counter like that will record them as unsuccessful. That reflects how they measure, not misuse.
Questions, timing or taking part
Write to measure-tls@checkemailsecurity.com with the host names or addresses and a timestamp. We can adjust timing and rate, and we will tell you whether the assessment was requested or is part of a benchmark.
If you would prefer your organisation not to be included, please tell us rather than blocking the connections. Taking part is best decided by whoever is accountable for security or risk, so we ask that the request comes from, or is confirmed by, them. Where an assessment was requested by someone else, such as your board or your security provider, we will put you in touch with them.
Text you can forward to the person who decides
Subject: An email security assessment of our domain Our mail servers are receiving connections from Panotect (checkemailsecurity.com). They measure how securely our mail servers encrypt email in transit: they connect, read what our servers tell every sender, and close. They do not send or receive mail and do not log in. Assessments like this are requested by someone responsible for an organisation's security or risk, by its managed security services provider, or as part of an industry or regulator benchmark that compares organisations with their peers. Could you confirm whether we requested this, and whether we want to take part? Panotect can tell us which kind of assessment it is. Their explanation: https://checkemailsecurity.com/