Exchange Online – DNSSEC enablement wizard?

๐Ÿ”’ Secure Bits ๐Ÿ’ก

๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—ถ๐˜€ ๐—ณ๐—ถ๐—ป๐—ฎ๐—น๐—น๐˜† ๐—ฏ๐—ฟ๐—ถ๐—ป๐—ด๐—ถ๐—ป๐—ด ๐—ฎ ๐——๐—ก๐—ฆ๐—ฆ๐—˜๐—– ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐˜„๐—ถ๐˜‡๐—ฎ๐—ฟ๐—ฑ ๐˜๐—ผ ๐—˜๐˜…๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ข๐—ป๐—น๐—ถ๐—ป๐—ฒ.

This is a very welcome change. DANE is available in Microsoft 365 for almost a year now and yet the only way to date was to set it via PowerShell.

To give you some context, DANE (DNS-based Authentication of Named Entities) helps ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐—ฆ๐— ๐—ง๐—ฃ communication against TLS downgrade and certificate spoofing attacks by validating certificates through DNSSEC.

But until now, enabling DANE properly was often:

– Too complicated

– Poorly documented (mainly in early stages)

Especially in hybrid or larger environments, many admins simply avoided it. That’s why Microsoft will announce ๐——๐—ก๐—ฆ๐—ฆ๐—˜๐—– ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐˜„๐—ถ๐˜‡๐—ฎ๐—ฟ๐—ฑ someday in the Q3 of 2026. It will be available in Exchange admin center.

๐Ÿ›ก๏ธ๐—ง๐—ต๐—ถ๐˜€ ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ต๐—ฒ๐—น๐—ฝ ๐—ฎ๐—ฑ๐—บ๐—ถ๐—ป๐˜€:

– Validates DNS prerequisites

– Reduces configuration risk during MX transition

– Provision the customer-specific DNSSECโ€‘capable mail flow endpoint (new MX)

๐Ÿง  Whatโ€™s interesting here is that Microsoft is not just supporting DANE – theyโ€™re now trying to make deployment way easier to support it’s adoption.

โš ๏ธ ๐—œ๐—บ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—ป๐˜:

DANE still depends on properly configured DNSSEC and correct MX/TLS certificate alignment. A wizard wonโ€™t fix broken DNS architecture.

But honestly – lowering the operational barrier is exactly what this technology needed.

๐Ÿ’ฌ Are you already using DANE for Exchange Online or still waiting for Microsoft to simplify deployment?

๐˜ˆ๐˜ถ๐˜ต๐˜ฉ๐˜ฐ๐˜ณ: Martin Strnad