email_check_dane
Verify DANE/TLSA records for email servers by resolving MX hosts and querying TLSA records. Flags missing TLSA and DANE without DNSSEC to identify email encryption gaps.
Instructions
Check DANE/TLSA records for a domain's MX hosts. Resolves MX records, then queries TLSA records at _25._tcp. using raw DNS queries. Reports certificate usage, selector, and matching type fields. Flags missing TLSA records and DANE without DNSSEC.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | The domain to check DANE/TLSA records for (e.g. example.com) |