Jump to content

myNCSC finding update Name does not match host alt3.aspmx.l.google.com.


Recommended Posts

Posted
I noticed Gmail went down ever so briefly this morning. I suspect its new cert day for Google and someone messed up (or not.... certs a a pain at any level).
Posted

Yup, also getting hammered with emails about it from mailcheck.

 

Assuming Google have messed up and mailcheck will take a while to catch up once it's fixed.

  • Thanks 1
Posted
NCSC need to seriously tone it down - by all means let me know but repeatedly spamming the life out of me is going to lead to me completely unsubcribing.
Posted

This doesn't sound like a Google issue to me, it has more of a DNS ring to it.

Are you all using the same DNS provider by any chance? and are they proxying your records?

 

What happens when you

 dig MX 

Posted

NCSC say the issue is with them and not Google.

 

I have suggested they stop notifying everyone every thirty minutes until they fix their known issue.

Posted

I'm getting a bunch of these, all related to aspmx4.googlemail.com I'm assuming I just ignore these until Google sort their mess?

 

 

New findings detected (2 Urgent):

 

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

 

 

Findings no longer detected (2 Urgent):

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

Posted

Just a heads up, you appear to be using Google's very old (10 year ish) MX DNS entries, albeit same errors as us all.

 

I'm getting a bunch of these, all related to aspmx4.googlemail.com I'm assuming I just ignore these until Google sort their mess?

 

New findings detected (2 Urgent):

 

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

 

 

Findings no longer detected (2 Urgent):

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

• Urgent | Mail Check | TLS

Asset: xxxxxxxx.com

Certificate host mismatch. The certificate Subject Alternative Name does not match host aspmx4.googlemail.com. (Host: aspmx4.googlemail.com.).

  • Thanks 1
Posted

seems to be new customers (2023 onwards) are using different smtp mx records but it doesn't matter as either should work fine. we arent seeing any issues with mail flow

https://apps.google.com/supportwidget/articlehome?hl=en&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F174125%3Fhl%3Den&assistant_event=welcome&assistant_id=gsuitemxrecords-gixvmm&product_context=174125&product_name=UnuFlow&trigger_context=a

Posted (edited)

A update from NCSC

 

Good afternoon,

We are reaching out to provide an important update about recent Google TLS Certificate notifications that some of our users have experienced.Over the last two days you may have received notifications regarding TLS Certificates such as;Certificate host mismatches, specifically where the certificate Subject Alternative Name does not align with the host (e.g., alt3.aspmx.l.google.com)The root certificate invalid2.invalid is not from a trusted certificate authorityPlease disregard both email notifications and findings in the MyNCSC and Mail Check dashboard.These findings are being caused as Mail Check is incorrectly registering TLS certificate failures due to a change in the way that Google are responding to our checks.We are taking immediate action to disable the incorrect notifications and are developing a long term solution for this issue. We will keep you up to date with further communication.Thank you for your patience and understanding.

Edited by mason1
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...