check_tlsa_dane

shallow

ai.intodns/scanner · Verify this server

Read-only TLSA/DANE DNS record check. With no port, resolves MX hosts and validates their `_25._tcp` TLSA tuple syntax; with an explicit port, queries `_<port>._<protocol>.<domain>`. Returns parsed usage, selector, matching type, certificate data, syntax errors, and best-practice advisories. It does not fetch or cryptographically match the live service certificate, so pair it with check_smtp_tls for SMTP certificate evidence. Use before publishing DANE records or troubleshooting DANE handover. No auth or destructive actions.

100.0/100

1 trials · measured 8 days ago

check_tlsa_dane scores 100.0/100 on Vouch's measured behaviour index, from 1 real invocation trials against ai.intodns/scanner, measured 25 Aug 2026 under methodology v0.2.0. Every measured component scored 100.

Component breakdown

ComponentWeightValue
Reliability35%not applicable
Schema integrity25%100.0
Failure behaviour15%not applicable
Latency15%not applicable
Concurrency10%not applicable

Tool details

Transport
remote + stdio
Credential class
open
Category
Communication
Input schema
not declared
Output schema
not declared
Side-effect classification
unclassified

Score history

DayScoreTierMethodology
2026-08-25100.0shallowv0.2.0

Probe evidence

ProbeOutcomes
schema_integritypass: 1

Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.

Embed this score

Available for every tool, scored or not — not a verification perk. Always links back to this page.

Vouch score: check_tlsa_dane
[![Vouch score](https://vouch.tools/api/tools/2f4c7c98-3615-41d9-91e8-91f1476db3a7/badge.svg)](https://vouch.tools/tools/2f4c7c98-3615-41d9-91e8-91f1476db3a7)
check_tlsa_dane — Vouch