Live DNS check · same engine as the full SecLens score

DANE checker

DANE binds MX certificates to DNS with TLSA records, but only if DNSSEC is actually validating. This checker looks up TLSA for each mail host, reports usage, selector, and matching type, and whether a trusted resolver set the AD bit. A TLSA record without DNSSEC is an unsigned claim, not a pin.

Public assessments are free. No account. The full 0–100 stack is included below the focused result.

4.23%
of mail-enabled Top-1M domains publish TLSA for at least one MX
1.11%
reach a fully valid DANE state

Figures from the July 2026 Top-1M study.

FAQ

Common questions

What is a DANE TLSA check?

For each MX host, SecLens looks up TLSA at _25._tcp.<mxhost> and reads usage, selector, and matching type. The recommended pin is 3 1 1 (DANE-EE, SPKI, SHA-256). Full credit also needs DNSSEC validation on that answer.

Why does DANE require DNSSEC?

Without a validated DNSSEC chain, an on-path attacker can forge TLSA answers. SecLens reports whether a trusted resolver set the AD bit. It does not open SMTP or match a live certificate itself.

Is any TLSA record enough?

No. Coverage must include the MX hosts that actually receive mail, the record must parse, and DNSSEC must validate. Full-cert pins (3 0 1) also break on ordinary CA re-issuance unless you automate DNS updates.

Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.