Settings
Result appears here after you select
{ } How to use
- Enter the host name of the service — mail.example.com for a mail server, www.example.com for a website.
- Set the port. 25 for SMTP, 443 for HTTPS.
- Select Process. Each record is decoded into its usage, selector and matching type.
{ } How it works
TLSA / DANE Lookup works on the text you provide. Adjust the options, then select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.
Inputs
- Host name — paste or type your input in the left panel (use Sample for an example)
- Port — a value (default: "443")
- Protocol — choose one — TCP, UDP (default: TCP)
Output
TXT text — copy or download it from the Output panel.
{ } Common uses
- Check that a mail server publishes DANE records before relying on them.
- Confirm a TLSA record still matches after renewing a certificate.
- Work out why a DANE-aware mail server is refusing to deliver.
{ } Limitations
- DANE only guarantees anything on a DNSSEC-signed zone. On an unsigned zone the TLSA records can be forged as easily as anything else — check the zone with the DNSSEC tool first.
- This reads the records. It cannot fetch the live certificate to check the two still match, because a browser cannot see a certificate — so a stale record after a renewal looks fine here and fails in practice.
- DANE is common for SMTP and rare for the web. No records is the normal answer for most host names.
{ } FAQ
Is my data uploaded to a server?
No. Everything runs locally in your browser — your files never leave your device.
Can I process more than one file at once?
This tool works on one input at a time.
Is this tool free?
Yes — it’s completely free and needs no sign-up.
What do usage 3 and selector 1 mean?
Usage 3 (DANE-EE) means the record names this exact certificate and it is trusted on its own, with no certificate authority involved. Selector 1 means the record covers only the public key rather than the whole certificate, which is what lets you renew a certificate without changing the record — as long as you keep the same key.
Why did my mail stop being delivered after a renewal?
Almost certainly because the new certificate has a new key and the TLSA record still holds the old fingerprint. A DANE-aware sender treats the mismatch as an attack and refuses. Publish the new record before switching, keep both live for a while, then remove the old one.
Should I be using DANE?
For a mail server on a DNSSEC-signed domain, it is a real improvement and widely supported. For a website it is not — no mainstream browser checks DANE, so records there protect nobody.