Email Authentication
DANE (TLSA) check
Whether the TLSA records published for your mail servers match the certificate they actually present.
Check this on your own domain now. It is free with a DomainGuard account and works on any domain. The check reads only what your domain publishes, and gives you a report you can send to whoever runs your website.
What we look at
We read the TLSA record at _25._tcp.<mx host> for each MX and compare it with the hash of the certificate, or its public key, that the server showed us. A mismatch only counts when the record is DNSSEC-signed, because senders ignore unsigned TLSA records.
Why it matters to your business
DANE tells sending servers exactly which certificate to expect. When the certificate changes and the record does not, every sender that checks DANE refuses to deliver to you until it is fixed.
How to fix it
- Publish a TLSA record for the current certificate (3 1 1 plus the SHA-256 of its public key is the usual one).
- When you renew, publish the new record before switching certificates, and keep the old one until its TTL has passed.
- If you no longer use DANE, remove the stale TLSA record.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
