DANE Checker
Check whether a domain's mail servers publish a DNSSEC-validated TLSA record for DANE.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the DANE Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan resolves the domain's MX records, then looks up a TLSA record for each mail server.
Read the result
Not configured, present but unvalidated, or fully validated – with a plain-English explanation.
What Your Result Means
DANE validatedPassA TLSA record exists for at least one mail server, and the resolver's response carried the AD flag – DNSSEC independently confirmed the record wasn't spoofed.
TLSA present, not validatedWarnA TLSA record exists, but without a validated DNSSEC chain it can be spoofed by anyone who can spoof DNS – it provides no real protection yet.
DANE not configuredInfoNo TLSA record found for this domain's mail servers. Not required, but it lets receivers require and verify TLS to this mail server instead of trusting whatever certificate shows up.
What Is DANE?
DANE (DNS-based Authentication of Named Entities) for SMTP, defined in RFC 7672, lets a domain publish – in DNS – exactly which TLS certificate or public key its mail server should present. A receiving mail server that supports DANE checks the certificate it actually gets against the TLSA record it finds in DNS, and can refuse to deliver mail (or refuse to fall back to plaintext) if they don't match.
A TLSA record is published at a fixed location: _25._tcp.<mail-server-hostname> – the 25 refers to SMTP's standard port.
How this checker works, honestly: it resolves the domain's MX records, looks up a TLSA record for each mail server, and checks the resolver's own AD (Authenticated Data) flag on that lookup – the same DNSSEC-validation signal this engine's DNSSEC checker relies on, not a re-implementation of DNSSEC's own signature-chain verification. It never opens a live connection to port 25.
Next Steps
Not DNSSEC-signed yet?
DANE can't provide real protection without it – check your domain's DNSSEC status first.
DNSSEC Checker →Checking mail-flow security generally?
MTA-STS is a more widely supported alternative for enforcing TLS to your mail servers.
MTA-STS Checker →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes.
Start free →Frequently Asked Questions
Is this DANE checker free?
Yes – check any domain for free, no signup required.
What is DANE, in plain terms?
A way to publish, in DNS, exactly which TLS certificate (or key) a mail server should present – so a receiving server can require and verify encrypted delivery instead of silently falling back to plaintext if something intercepts the connection.
Why does this need DNSSEC to actually matter?
Because the TLSA record itself is just a DNS record – without DNSSEC signing it, anyone able to spoof DNS responses to a receiving mail server could also spoof the TLSA record, defeating the whole point. DNSSEC is what makes the TLSA record trustworthy.
Does this tool make a live connection to my mail server?
No – it only queries DNS records (MX and TLSA), never opens a live SMTP connection.
How do I set up DANE?
You need DNSSEC enabled on your domain first, then a TLSA record published at _25._tcp.<your-mail-server> matching that server's actual TLS certificate. Most mail platforms and DNS hosts have their own setup guides for the exact values.