๐ Secure Bits ๐ก
๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ถ๐ ๐ณ๐ถ๐ป๐ฎ๐น๐น๐ ๐ฏ๐ฟ๐ถ๐ป๐ด๐ถ๐ป๐ด ๐ฎ ๐๐ก๐ฆ๐ฆ๐๐ ๐ฒ๐ป๐ฎ๐ฏ๐น๐ฒ๐บ๐ฒ๐ป๐ ๐๐ถ๐๐ฎ๐ฟ๐ฑ ๐๐ผ ๐๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ ๐ข๐ป๐น๐ถ๐ป๐ฒ.
This is a very welcome change. DANE is available in Microsoft 365 for almost a year now and yet the only way to date was to set it via PowerShell.
To give you some context, DANE (DNS-based Authentication of Named Entities) helps ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐ ๐ฆ๐ ๐ง๐ฃ communication against TLS downgrade and certificate spoofing attacks by validating certificates through DNSSEC.
But until now, enabling DANE properly was often:
– Too complicated
– Poorly documented (mainly in early stages)
Especially in hybrid or larger environments, many admins simply avoided it. That’s why Microsoft will announce ๐๐ก๐ฆ๐ฆ๐๐ ๐ฒ๐ป๐ฎ๐ฏ๐น๐ฒ๐บ๐ฒ๐ป๐ ๐๐ถ๐๐ฎ๐ฟ๐ฑ someday in the Q3 of 2026. It will be available in Exchange admin center.
๐ก๏ธ๐ง๐ต๐ถ๐ ๐๐ต๐ผ๐๐น๐ฑ ๐ต๐ฒ๐น๐ฝ ๐ฎ๐ฑ๐บ๐ถ๐ป๐:
– Validates DNS prerequisites
– Reduces configuration risk during MX transition
– Provision the customer-specific DNSSECโcapable mail flow endpoint (new MX)
๐ง Whatโs interesting here is that Microsoft is not just supporting DANE – theyโre now trying to make deployment way easier to support it’s adoption.
โ ๏ธ ๐๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐:
DANE still depends on properly configured DNSSEC and correct MX/TLS certificate alignment. A wizard wonโt fix broken DNS architecture.
But honestly – lowering the operational barrier is exactly what this technology needed.
๐ฌ Are you already using DANE for Exchange Online or still waiting for Microsoft to simplify deployment?
๐๐ถ๐ต๐ฉ๐ฐ๐ณ: Martin Strnad
