Free Tool
DANE/TLSA Checker
Check DANE/TLSA records for your mail server. Verify DNS-based authentication for secure, encrypted email delivery.
Free instant check — no signup required
What is DANE?
DNS-based Authentication of Named Entities (DANE) is a security protocol that uses DNSSEC-signed TLSA records to bind TLS certificates to DNS names. For email, DANE allows domain owners to specify exactly which TLS certificate their mail server uses, providing strong protection against man-in-the-middle attacks and compromised certificate authorities.
Traditional TLS relies on certificate authorities (CAs) to vouch for a server's identity, but any CA can issue a certificate for any domain. DANE eliminates this weakness by publishing the expected certificate directly in DNS, secured by the DNSSEC chain of trust. A sending server can verify it is connecting to the authentic mail server without relying on the CA system.
DANE is widely deployed in countries like the Netherlands, Germany, and the Czech Republic, particularly among government and financial institutions. It works alongside MTA-STS and TLS-RPT to provide comprehensive email transport security. Organizations seeking the strongest possible email encryption guarantees should consider deploying DANE alongside these complementary standards.
Frequently Asked Questions
What is DANE for email?
How does DANE work with DNSSEC?
What is a TLSA record?
Do I need DNSSEC for DANE?
Should I implement DANE if I already have MTA-STS?
Need continuous DANE monitoring?
Get automatic alerts when your DANE/TLSA records change or break. Monitor DANE, SPF, DKIM, DMARC, and 60 blacklists.
Start Monitoring Free