When accessing any of the Mailfence services, the transmission of data between your device program and our servers in Brussels-Belgium is always encrypted and protected by SSL/TLS – for which each website has a (Public Key) Certificate that is verified by a trusted Certificate Authority (CA).
A modern browser should automatically check the validity of the Mailfence SSL/TLS certificate and alert you if it detects something untrustworthy. In case an adversary succeeds in spoofing Mailfence (using a rogue SSL/TLS certificate), you will still be able to detect such an (AiTM) attack by manually checking Mailfence SSL/TLS certificate fingerprints.
The Mailfence SSL/TLS certificate fingerprints [valid until February 10th, 2025, 11:23 AM (Central European Summer Time)] are:
SHA1 fingerprint:
78:4E:B8:EE:0D:CE:4C:D3:2F:3D:83:AF:D9:AE:19:37:50:9C:A0:F8
SHA-256 fingerprint:
DA:4C:71:2B:70:0A:8E:34:8E:69:54:BC:60:A2:28:68:61:85:D7:C5:80:A4:15:35:94:AD:80:B9:7B:3D:C3:50
If this matches what you see in your browser, then you know you are communicating with the right Mailfence website/service and using the correct public key to encrypt your sensitive information and only Mailfence can decrypt it.
Last updated: November 2024
Next update date: February 2025
Guidelines:
- For Chrome:
- Click on the green padlock in the address bar.
- Click on the Certificate.
- In General, verify that the Fingerprints (SHA1 & SHA-256) matches the one’s above.
- For Firefox:
- Click on the lock button in front of the URL and click on the Arrow on the right side of the dropdown.
- Click on Connection Secure.
- Click on More Information.
- Go to Security and click on View Certificate.
- Verify that the Fingerprints (SHA1 & SHA-256) matches the one’s above.
- For Safari:
- Click on the lock button in front of the URL.
- Select Show Certificate, in Details scroll to the bottom of the page.
- Verify that the Fingerprints (SHA1 & SHA-256) matches the one’s above.
Note: Make sure, in your browser, you are looking at the leaf certificate (mailfence.com, *.mailfence.com). This certificate does not cover blog.mailfence.com and kb.mailfence.com domain names.
For further assistance, feel free to drop us an email at support@mailfence.com
At Mailfence – a secure and private email service, we believe in following good security practices, to contribute in providing you a secure and private email solution. Learn more about who we are.