Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Perform deep cryptographic validation of your DNS-based Authentication of Named Entities (DANE) deployment. Analyze TLSA records, verify DNSSEC trust chains, and ensure your mail server certificates map perfectly to prevent MitM and STARTTLS downgrade attacks.
DANE (RFC 6698) is a protocol that leverages DNSSEC to securely associate X.509 certificates or public keys with the domain names they represent. By publishing TLSA records in a DNSSEC-signed zone, domains can enforce explicit certificate validation rules, neutralizing threats posed by compromised Certificate Authorities (CAs) and pervasive monitoring. In the context of email (RFC 7672), DANE acts as an enforcement mechanism for SMTP STARTTLS, ensuring that MTAs only deliver messages over cryptographically authenticated and encrypted channels.
Legacy SMTP transport encryption relies on opportunistic STARTTLS, which is vulnerable to active interception and downgrade attacks. By coupling the X.509 certificate binding with a DNSSEC-secured TLSA record (RFC 6698, RFC 7672), DANE enforces explicit trust. It mathematically guarantees that connecting MTAs communicate only with the cryptographically intended server, bypassing vulnerabilities in the traditional public Certificate Authority (CA) infrastructure.
Failing to implement DNSSEC, which renders DANE TLSA records entirely untrusted., Neglecting to publish a new TLSA record before rotating the mail server's TLS certificate (causing a hard delivery failure)., Hashing the full certificate (Selector 0) instead of the SubjectPublicKeyInfo (Selector 1), leading to brittle configurations during renewals..
The checker resolves the MX records for the target domain and extracts the mail server hostnames.
It queries the DNS for TLSA records at the specific port and protocol (e.g., _25._tcp.mx1.example.com).
It performs a recursive DNSSEC validation, traversing from the root zone down to the TLSA record to ensure cryptographic integrity.
The tool establishes a STARTTLS connection to the target mail server, retrieving the presented X.509 certificate and public key.
Deep analysis of your TLSA records, verifying usage types (0-3), selectors (0-1), and matching types (0-2) against the deployed certificate.
End-to-end traversal of your DNSSEC delegation path from the root zone to ensure the cryptographic integrity of the TLSA response.
Probes the target MTA to verify the presented X.509 certificate mathematically matches the SHA-256 or SHA-512 hash defined in the TLSA record.
Detects pre-published TLSA records for seamless certificate rotation without breaking DANE constraints.
Validates the full TLS handshake, Server Name Indication, and intermediate CA chains presented during MTA connection.
Ensures absolute alignment with RFC 6698, RFC 7671, and RFC 7672, flagging protocol deviations and suboptimal configurations.
Don't let DNSSEC misconfigurations or TLSA mismatches cause permanent email delivery failures. Use our enterprise-grade DANE checker to verify your cryptographic bindings today.