SSL/PKI DNS Check Tool

Verify your complete SSL/TLS security stack (CAA, TLSA, and DNSSEC) instantly to troubleshoot certificate issuance and DANE validation.

How to troubleshoot SSL/TLS issuance and DANE errors

If your auto-renewing SSL certificate (like Let's Encrypt) suddenly fails, or strict mail servers refuse to deliver emails to your domain over TLS, your DNS-based PKI (Public Key Infrastructure) configuration might be misconfigured. Enter your domain, port, and protocol above to run a comprehensive check on the three pillars of DNS security.

Interpreting your SSL/PKI DNS results

  • CAA (Certificate Authority Authorization): If your CA is failing to issue a certificate, check the CAA results. If a record exists but your CA (e.g., letsencrypt.org) is not explicitly listed, they are legally blocked from issuing the SSL certificate.
  • TLSA (DANE Bindings): If the TLSA hash does not match your current live certificate, clients enforcing DANE will reject the connection as a potential Man-in-the-Middle attack. Always update TLSA hashes before installing a new certificate.
  • DNSSEC (Chain of Trust): DNSSEC must return a valid, signed chain. If DNSSEC is broken (resulting in a SERVFAIL) or simply disabled, your TLSA records become invalid, as DANE strictly requires a cryptographically secure DNS response.

SSL and PKI DNS check

This use case combines CAA, TLSA, and DNSSEC checks to validate the DNS side of your TLS and PKI setup. CAA controls which certificate authorities can issue certificates for your domain, TLSA provides DANE bindings for certificates, and DNSSEC ensures DNS responses are validated. Together these records strengthen your TLS posture.

Misconfigurations in any of these records can break issuance or validation. A missing CAA entry can block certificate renewal. A stale TLSA record can cause DANE failure. Missing or incorrect DS records can make DNSSEC validation fail. Use this check before certificate renewals or security audits.

If you need related checks, try SSL certificate check lookup and DNSSEC lookup check tool.

Yes. TLSA relies on DNSSEC validation. Without DNSSEC, TLSA records should not be trusted.

CAA records may block the CA. Update CAA to include the correct issuer or remove restrictive entries.

Recalculate the TLSA data for the new certificate or key and publish it. Old TLSA data will fail validation.

Authorize only the CAs you actually use, and add issuewild if you need wildcard certificates.

It indicates a chain of trust problem, such as mismatched DS and DNSKEY or expired signatures.

No, but it adds extra security for environments that validate DANE.