DANE Record Validator API

POST

Catch invalid DANE and TLSA configurations before deployment.

DANE Record Validator validates DANE/TLSA DNS records used for certificate authentication, providing security analysis and best practice recommendations.

Try it — live request, no key required

Request
POSTapi.apiverve.com/v1/danevalidator
Body
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "raw_record": "_443._tcp.example.com. 86400 IN TLSA 3 1 1 0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF",
    "parsed": {
      "name": "_443._tcp.example.com.",
      "port": 443,
      "protocol": "tcp",
      "hostname": "example.com",
      "ttl": 86400,
      "class": "IN",
      "usage": 3,
      "selector": 1,
      "matching": 1,
      "certificate_data": "0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF",
      "certificate_data_length": 64
    },
    "interpretation": {
      "usage": {
        "name": "DANE-EE",
        "description": "Domain-issued certificate",
        "full_description": "Certificate must exactly match the provided association data (most common)"
      },
      "selector": {
        "name": "SPKI",
        "description": "SubjectPublicKeyInfo",
        "full_description": "Match against the Subject Public Key Info (recommended)"
      },
      "matching": {
        "name": "SHA-256",
        "description": "SHA-256 hash",
        "full_description": "SHA-256 hash of the selected content (recommended)"
      },
      "security_level": "Recommended",
      "recommendation": "This is the recommended DANE configuration (DANE-EE + SPKI + SHA-256)"
    },
    "validation": {
      "is_valid": true,
      "certificate_data_format": "Valid hexadecimal",
      "certificate_data_length_valid": true
    }
  }
}

About the DANE Record Validator API

Includes validation of certificate data format, length verification, and security level assessment with recommendations for optimal DANE configuration.

What people use it for

DANE Configuration
Validate DANE/TLSA record configuration to ensure proper certificate association and DNS security implementation
Authentication Audit
Audit DNS-based authentication of named entities (DANE) for email servers and web services security compliance
Security Scanning
Build DNS security scanning tools that validate TLSA records for certificate pinning and trust anchor verification
Certificate Pinning
Verify certificate pinning implementation using TLSA records to protect against man-in-the-middle attacks and CA compromise

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

Other ways to use DANE Record Validator

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the DANE Record Validator API.

Read the docs →
What parts of a DANE or TLSA record does the validator check?
It validates the overall record structure, including the domain name, port, protocol, and DNS parameters like usage, selector, and matching type. It also verifies that the certificate association data is valid hexadecimal and meets length requirements.
Do I get the security analysis and recommendations on the Free plan?
No, detailed interpretation and security recommendations are premium fields. The Free plan validates record syntax and format, while any paid plan unlocks human-readable field explanations, security level ratings, and best practice recommendations.
How far does the Starter plan go for validating DANE records?
Each validation costs 2 credits, allowing up to 100,000 validations per month on the Starter plan. That works out to about $0.30 per 1,000 checks, while the Free plan includes 100 validations each month.
How does the API flag corrupted or malformed certificate data?
The response reports validation checks specifically for certificate data format and length. If the certificate string is not proper hexadecimal or has an incorrect length for the matching type, the validation flags report false.
Does it support custom port and transport protocol combinations?
Yes. It extracts and parses standard TLSA service prefixes, handling custom port numbers alongside both TCP and UDP protocol specifications.

Ready to build with DANE Record Validator? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs