3606 45392.911528 x.x.x.x 193.252.22.65 TCP 76 45711 → 25 [SYN] Seq=0 Win=28720 Len=0 MSS=1436 SACK_PERM=1 TSval=4081822238 TSecr=0 WS=128
3607 45393.001178 193.252.22.65 x.x.x.x TCP 76 25 → 45711 [SYN, ACK] Seq=0 Ack=1 Win=4200 Len=0 MSS=1400 TSval=3352842904 TSecr=4081822238 SACK_PERM=1
3608 45393.001223 x.x.x.x 193.252.22.65 TCP 68 45711 → 25 [ACK] Seq=1 Ack=1 Win=28720 Len=0 TSval=4081822327 TSecr=3352842904
3609 45393.515996 193.252.22.65 x.x.x.x SMTP 105 S: 220 mwinf5c49 ME ESMTP server ready
3610 45393.516223 x.x.x.x 193.252.22.65 SMTP 90 C: EHLO mail.mydomain.com
3611 45393.607048 193.252.22.65 x.x.x.x SMTP 216 S: 250-mwinf5c49 hello [x.x.x.x], pleased to meet you | 250-HELP | 250-SIZE 44000000 | 250-ENHANCEDSTATUSCODES | 250-8BITMIME | 250-STARTTLS | 250 OK
3612 45393.607267 x.x.x.x 193.252.22.65 SMTP 78 C: STARTTLS
3613 45393.698344 193.252.22.65 x.x.x.x SMTP 98 S: 220 2.0.0 Ready to start TLS
3614 45393.722884 x.x.x.x 193.252.22.65 TLSv1 362 Client Hello
3615 45393.819399 193.252.22.65 x.x.x.x TLSv1 1516 Server Hello
3616 45393.819493 x.x.x.x 193.252.22.65 TCP 68 45711 → 25 [ACK] Seq=327 Ack=1664 Win=31924 Len=0 TSval=4081823146 TSecr=3352843722
3617 45393.819517 193.252.22.65 x.x.x.x TLSv1 1456 Certificate [TCP segment of a reassembled PDU]
3618 45393.819709 x.x.x.x 193.252.22.65 TCP 68 45711 → 25 [RST, ACK] Seq=327 Ack=3052 Win=34700 Len=0 TSval=4081823146 TSecr=3352843722
--------------------------------------------------------
Frame 3614: 362 bytes on wire (2896 bits), 362 bytes captured (2896 bits)
Linux cooked capture
Internet Protocol Version 4, Src: x.x.x.x , Dst: 193.252.22.65
Transmission Control Protocol, Src Port: 45711, Dst Port: 25, Seq: 33, Ack: 216, Len: 294
Secure Sockets Layer
| TLSv1 Record Layer: Handshake Protocol: Client Hello
| Content Type: Handshake (22)
| Version: TLS 1.0 (0x0301)
| Length: 289
| Handshake Protocol: Client Hello
| Handshake Type: Client Hello (1)
| Length: 285
| Version: TLS 1.2 (0x0303)
| Random: 108782fc4d635c8061fd6b75146cddd53a00fd412628bd4f...
| GMT Unix Time: Oct 15, 1978 12:19:08.000000000 EDT
| Random Bytes: 4d635c8061fd6b75146cddd53a00fd412628bd4f6a03c542...
| Session ID Length: 0
| Cipher Suites Length: 172
| Cipher Suites (86 suites)
| Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c)
| Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (0xc024)
| Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a)
| Cipher Suite: TLS_DH_DSS_WITH_AES_256_GCM_SHA384 (0x00a5)
| Cipher Suite: TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 (0x00a3)
| Cipher Suite: TLS_DH_RSA_WITH_AES_256_GCM_SHA384 (0x00a1)
| Cipher Suite: TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x009f)
| Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 (0x006b)
| Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 (0x006a)
| Cipher Suite: TLS_DH_RSA_WITH_AES_256_CBC_SHA256 (0x0069)
| Cipher Suite: TLS_DH_DSS_WITH_AES_256_CBC_SHA256 (0x0068)
| Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x0039)
| Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA (0x0038)
| Cipher Suite: TLS_DH_RSA_WITH_AES_256_CBC_SHA (0x0037)
| Cipher Suite: TLS_DH_DSS_WITH_AES_256_CBC_SHA (0x0036)
| Cipher Suite: TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA (0x0088)
| Cipher Suite: TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA (0x0087)
| Cipher Suite: TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA (0x0086)
| Cipher Suite: TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA (0x0085)
| Cipher Suite: TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 (0xc032)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02e)
| Cipher Suite: TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 (0xc02a)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 (0xc026)
| Cipher Suite: TLS_ECDH_RSA_WITH_AES_256_CBC_SHA (0xc00f)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA (0xc005)
| Cipher Suite: TLS_RSA_WITH_AES_256_GCM_SHA384 (0x009d)
| Cipher Suite: TLS_RSA_WITH_AES_256_CBC_SHA256 (0x003d)
| Cipher Suite: TLS_RSA_WITH_AES_256_CBC_SHA (0x0035)
| Cipher Suite: TLS_RSA_WITH_CAMELLIA_256_CBC_SHA (0x0084)
| Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b)
| Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (0xc023)
| Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009)
| Cipher Suite: TLS_DH_DSS_WITH_AES_128_GCM_SHA256 (0x00a4)
| Cipher Suite: TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 (0x00a2)
| Cipher Suite: TLS_DH_RSA_WITH_AES_128_GCM_SHA256 (0x00a0)
| Cipher Suite: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x009e)
| Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (0x0067)
| Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 (0x0040)
| Cipher Suite: TLS_DH_RSA_WITH_AES_128_CBC_SHA256 (0x003f)
| Cipher Suite: TLS_DH_DSS_WITH_AES_128_CBC_SHA256 (0x003e)
| Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x0033)
| Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA (0x0032)
| Cipher Suite: TLS_DH_RSA_WITH_AES_128_CBC_SHA (0x0031)
| Cipher Suite: TLS_DH_DSS_WITH_AES_128_CBC_SHA (0x0030)
| Cipher Suite: TLS_DHE_RSA_WITH_SEED_CBC_SHA (0x009a)
| Cipher Suite: TLS_DHE_DSS_WITH_SEED_CBC_SHA (0x0099)
| Cipher Suite: TLS_DH_RSA_WITH_SEED_CBC_SHA (0x0098)
| Cipher Suite: TLS_DH_DSS_WITH_SEED_CBC_SHA (0x0097)
| Cipher Suite: TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA (0x0045)
| Cipher Suite: TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA (0x0044)
| Cipher Suite: TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA (0x0043)
| Cipher Suite: TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA (0x0042)
| Cipher Suite: TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 (0xc031)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02d)
| Cipher Suite: TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 (0xc029)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 (0xc025)
| Cipher Suite: TLS_ECDH_RSA_WITH_AES_128_CBC_SHA (0xc00e)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA (0xc004)
| Cipher Suite: TLS_RSA_WITH_AES_128_GCM_SHA256 (0x009c)
| Cipher Suite: TLS_RSA_WITH_AES_128_CBC_SHA256 (0x003c)
| Cipher Suite: TLS_RSA_WITH_AES_128_CBC_SHA (0x002f)
| Cipher Suite: TLS_RSA_WITH_SEED_CBC_SHA (0x0096)
| Cipher Suite: TLS_RSA_WITH_CAMELLIA_128_CBC_SHA (0x0041)
| Cipher Suite: TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (0xc012)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA (0xc008)
| Cipher Suite: TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x0016)
| Cipher Suite: TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA (0x0013)
| Cipher Suite: TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA (0x0010)
| Cipher Suite: TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA (0x000d)
| Cipher Suite: TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA (0xc00d)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA (0xc003)
| Cipher Suite: TLS_RSA_WITH_3DES_EDE_CBC_SHA (0x000a)
| Cipher Suite: TLS_RSA_WITH_IDEA_CBC_SHA (0x0007)
| Cipher Suite: TLS_ECDHE_RSA_WITH_RC4_128_SHA (0xc011)
| Cipher Suite: TLS_ECDHE_ECDSA_WITH_RC4_128_SHA (0xc007)
| Cipher Suite: TLS_ECDH_RSA_WITH_RC4_128_SHA (0xc00c)
| Cipher Suite: TLS_ECDH_ECDSA_WITH_RC4_128_SHA (0xc002)
| Cipher Suite: TLS_RSA_WITH_RC4_128_SHA (0x0005)
| Cipher Suite: TLS_RSA_WITH_RC4_128_MD5 (0x0004)
| Cipher Suite: TLS_EMPTY_RENEGOTIATION_INFO_SCSV (0x00ff)
| Compression Methods Length: 1
| Compression Methods (1 method)
| Compression Method: null (0)
| Extensions Length: 72
| Extension: ec_point_formats (len=4)
| Type: ec_point_formats (11)
| Length: 4
| EC point formats Length: 3
| Elliptic curves point formats (3)
| Extension: supported_groups (len=10)
| Type: supported_groups (10)
| Length: 10
| Supported Groups List Length: 8
| Supported Groups (4 groups)
| Extension: signature_algorithms (len=32)
| Type: signature_algorithms (13)
| Length: 32
| Signature Hash Algorithms Length: 30
| Signature Hash Algorithms (15 algorithms)
| Extension: status_request (len=5)
| Type: status_request (5)
| Length: 5
| Certificate Status Type: OCSP (1)
| Responder ID list Length: 0
| Request Extensions Length: 0
| Extension: heartbeat (len=1)
| Type: heartbeat (15)
| Length: 1
| Mode: Peer allowed to send requests (1)
--------------------------------------------------------
Frame 3615: 1516 bytes on wire (12128 bits), 1516 bytes captured (12128 bits)
Linux cooked capture
Internet Protocol Version 4, Src: 193.252.22.65, Dst: x.x.x.x
Transmission Control Protocol, Src Port: 25, Dst Port: 45711, Seq: 216, Ack: 327, Len: 1448
Secure Sockets Layer
| TLSv1 Record Layer: Handshake Protocol: Server Hello
| Content Type: Handshake (22)
| Version: TLS 1.0 (0x0301)
| Length: 74
| Handshake Protocol: Server Hello
| Handshake Type: Server Hello (2)
| Length: 70
| Version: TLS 1.0 (0x0301)
| Random: 5fb0169d9379331e21cdb38c9767fc06d6d42b6eb097d53a...
| GMT Unix Time: Nov 14, 2020 12:40:45.000000000 EST
| Random Bytes: 9379331e21cdb38c9767fc06d6d42b6eb097d53aee6957e0...
| Session ID Length: 32
| Session ID: fb6c3a86977463b393a2f9eba58fe2fb3e31a171df221263...
| Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x0039)
| Compression Method: null (0)
--------------------------------------------------------
Frame 3617: 1456 bytes on wire (11648 bits), 1456 bytes captured (11648 bits)
Linux cooked capture
Internet Protocol Version 4, Src: 193.252.22.65, Dst: x.x.x.x
Transmission Control Protocol, Src Port: 25, Dst Port: 45711, Seq: 1664, Ack: 327, Len: 1388
[2 Reassembled TCP Segments (2749 bytes): #3615(1369), #3617(1380)]
Secure Sockets Layer
| TLSv1 Record Layer: Handshake Protocol: Certificate
| Content Type: Handshake (22)
| Version: TLS 1.0 (0x0301)
| Length: 2744
| Handshake Protocol: Certificate
| Handshake Type: Certificate (11)
| Length: 2740
| Certificates Length: 2737
| Certificates (2737 bytes)
| Certificate Length: 1555
| Certificate: 3082060f308204f7a003020102021003b0c2ea837bb77e76... (id-at-commonName=smtp-in.orange.fr,id-at-organizationalUnitName=Orange,id-at-organizationName=Orange,id-at-localityName=Paris,id-at-countryName=FR)
| signedCertificate
| algorithmIdentifier (sha256WithRSAEncryption)
| Padding: 0
| encrypted: 789d2ffdc506a7e2e89c957d0e3e1c2e5406b5077d5b970e...
| Certificate Length: 1176
| Certificate: 308204943082037ca003020102021001fda3eb6eca75c888... (id-at-commonName=DigiCert SHA2 Secure Server CA,id-at-organizationName=DigiCert Inc,id-at-countryName=US)
| signedCertificate
| algorithmIdentifier (sha256WithRSAEncryption)
| Padding: 0
| encrypted: 233edf4bd23142a5b67e425c1a44cc69d168b45d4be00421...