DANE binds MX certificates to DNS with TLSA records, but only if DNSSEC is actually validating. This checker looks up TLSA for each mail host, reports usage, selector, and matching type, and whether a trusted resolver set the AD bit. A TLSA record without DNSSEC is an unsigned claim, not a pin.
Public assessments are free. No account. The full 0–100 stack is included below the focused result.
Figures from the July 2026 Top-1M study.
For each MX host, SecLens looks up TLSA at _25._tcp.<mxhost> and reads usage, selector, and matching type. The recommended pin is 3 1 1 (DANE-EE, SPKI, SHA-256). Full credit also needs DNSSEC validation on that answer.
Without a validated DNSSEC chain, an on-path attacker can forge TLSA answers. SecLens reports whether a trusted resolver set the AD bit. It does not open SMTP or match a live certificate itself.
No. Coverage must include the MX hosts that actually receive mail, the record must parse, and DNSSEC must validate. Full-cert pins (3 0 1) also break on ordinary CA re-issuance unless you automate DNS updates.
Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.