check_dane
Check DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp., validating their syntax, usage/selector/matching-type fields and DNSSEC backing on the MX host's zone. The record is reported as present but UNVERIFIED: there is no certificate probe for port 25/SMTP, so the pinned data is never compared against the certificate the mail server actually serves (the comparable capture-and-compare pipeline exists only for check_dane_https at port 443, and is itself currently kill-switched there — see that tool's description). Use when asked if SMTP mail servers publish DANE/TLSA pinning; this does not confirm the pin matches the live certificate. For HTTPS DANE at port 443, use check_dane_https instead. Part of the scan_domain audit.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain to check (e.g., example.com) | |
| format | No | Output verbosity. Auto-detected if omitted. | |
| force_refresh | No | Bypass cache and run a fresh check. Useful after DNS changes. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| score | Yes | ||
| passed | Yes | ||
| partial | No | ||
| category | Yes | ||
| findings | Yes | ||
| checkStatus | No | ||
| verdictWithheld | No |