TLSA
TLSA records (RFC 6698, RFC 7671/7672) pin a certificate or its public key in DNS so that TLS clients can verify a server independently of certificate authorities (DANE). Paste a certificate and this generator computes the digest locally in your browser.
DNSSEC is a prerequisite. DANE only works in DNSSEC-signed zones –
without validation, clients cannot trust the TLSA record, and this security check rates
a TLSA record without DNSSEC as a failure.
For SMTP the record name is
_25._tcp.<MX hostname> – the host is
the MX host name (e.g. mx1.example.net), not the mail
domain. For a key rollover, publish a second record with the new key alongside the old
one before switching (RFC 7671 §8.1).
Runs entirely in your browser. Record Studio · Verify the result with the domain security check