Related Tools
Need Help?
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
About Our Tools
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
DANE (DNS-based Authentication of Named Entities) binds TLS to DNS using TLSA records, providing cryptographic assurance of the TLS certificate presented by the SMTP server. When combined with DNSSEC, DANE helps prevent downgrade attacks and ensures that opportunistic TLS upgrades are validated against known keys.
usage, selector, and matching.Typical TLSA records are published under _25._tcp.mail.example.com for SMTP on port 25. A common configuration is:
_25._tcp.mail.example.com. IN TLSA 3 1 1 <SHA-256 of public key>
Here, usage 3 indicates DANE-EE (end-entity), selector 1 selects the public key, and matching 1 is a SHA-256 digest.
openssl x509 -in cert.pem -noout -pubkey | openssl pkey -pubin -outform DER | openssl dgst -sha256
Enable DANE in Postfix:
smtpd_tls_security_level = dane
smtp_tls_security_level = dane
smtp_dns_support_level = dnssec
Restart the service and test outbound delivery. Use postfix logs to confirm that TLSA validation is applied for recipient domains with signed records.
DANE status lines and failures.Rotate certificates carefully and keep TLSA records in sync. Consider staging new records before rotating keys. Maintain DNSSEC health to avoid validation breakage.
DANE significantly strengthens SMTP TLS, reducing MITM risk and improving security posture for high-value mail flows.