Check TLSA records instantly across global resolvers to validate your DANE configuration and TLS certificate pins.
TLSA records are used to cryptographically bind a TLS/SSL certificate to a domain name using DANE. Enter your domain name above to query its active TLSA records. Note: TLSA records are queried using a specific port and protocol format (e.g., _443._tcp.www.example.com or _25._tcp.mail.example.com). Ensure you query the exact hostname string.
3 1 1). These dictate how the client should verify the certificate (e.g., checking the exact public key vs the full certificate, using SHA-256 vs SHA-512).Learn how TLSA records prevent rogue Certificate Authorities from issuing fake SSL certificates, and decode the exact meaning of the Usage, Selector, and Matching Type numbers.
Read the TLSA Record Wiki