SSL & Certificates

TLSA / DANE Lookup

Read the TLSA records that pin which certificate a service is allowed to present.

Host name

Settings

Output

Result appears here after you select

{ } How to use

  1. Enter the host name of the service — mail.example.com for a mail server, www.example.com for a website.
  2. Set the port. 25 for SMTP, 443 for HTTPS.
  3. Select Process. Each record is decoded into its usage, selector and matching type.

{ } How it works

TLSA / DANE Lookup works on the text you provide. Adjust the options, then select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.

Inputs

  • Host name — paste or type your input in the left panel (use Sample for an example)
  • Port — a value (default: "443")
  • Protocol — choose one — TCP, UDP (default: TCP)

Output

TXT text — copy or download it from the Output panel.

{ } Common uses

  • Check that a mail server publishes DANE records before relying on them.
  • Confirm a TLSA record still matches after renewing a certificate.
  • Work out why a DANE-aware mail server is refusing to deliver.

{ } Limitations

  • DANE only guarantees anything on a DNSSEC-signed zone. On an unsigned zone the TLSA records can be forged as easily as anything else — check the zone with the DNSSEC tool first.
  • This reads the records. It cannot fetch the live certificate to check the two still match, because a browser cannot see a certificate — so a stale record after a renewal looks fine here and fails in practice.
  • DANE is common for SMTP and rare for the web. No records is the normal answer for most host names.

{ } FAQ

Is my data uploaded to a server?

No. Everything runs locally in your browser — your files never leave your device.

Can I process more than one file at once?

This tool works on one input at a time.

Is this tool free?

Yes — it’s completely free and needs no sign-up.

What do usage 3 and selector 1 mean?

Usage 3 (DANE-EE) means the record names this exact certificate and it is trusted on its own, with no certificate authority involved. Selector 1 means the record covers only the public key rather than the whole certificate, which is what lets you renew a certificate without changing the record — as long as you keep the same key.

Why did my mail stop being delivered after a renewal?

Almost certainly because the new certificate has a new key and the TLSA record still holds the old fingerprint. A DANE-aware sender treats the mismatch as an attack and refuses. Publish the new record before switching, keep both live for a while, then remove the old one.

Should I be using DANE?

For a mail server on a DNSSEC-signed domain, it is a real improvement and widely supported. For a website it is not — no mainstream browser checks DANE, so records there protect nobody.