<28 April 2025>
In March 2022, Microsoft set up Outbound SMTP DANE with DNSSEC automatically. You didn't have to do anything for that yourself.
Inbound mail traffic (receiving e-mails), however, was a different story: there, it took until 2024 before Microsoft also made this functionality available.
In this article, we will explain step by step how to set up Inbound SMTP DANE and DNSSEC within Exchange Online.
<SMTP DANE>
SMTP DANE uses DNS to verify that the certificates used for email traffic are genuine and protects against TLS downgrade attacks.
<DNSSEC>
DNSSEC ensures that the DNS data itself cannot be manipulated en route, for example by a man-in-the-middle attack.
Microsoft offers this extra security free of charge to all Microsoft 365 users. You do not need to do anything for Outbound DANE, but you must activate Inbound DANE yourself.
<Step-by-step plan: Configuring Inbound SMTP DANE and DNSSEC in Exchange Online>
<Step 1>
Is your domain not signed? Enable DNSSEC at your registrar. Does your registrar not support it? Then it is wise to move your domain to a party that does.
Note: Wait for the old TTL to fully expire before proceeding.
<Step 3>
<Step 6>
<Step 7>
<Step 8>
<Step 9>
<Step 11>
Note: Microsoft hosts multiple TLSA records for better reliability. If at least one TLSA record validates, your configuration is correct.
<Conclusion>
With these steps, you will better secure incoming e-mail traffic in Exchange Online against spoofing and downgrade attacks. And the best part: it costs you nothing extra. Every organisation that is serious about e-mail security should take this step. Especially now that even with Microsoft 365 you are no longer dependent on just basic settings.
Want to know if your e-mail domain is really set up properly? Then do the check via internet.nl/test-mail.
If you set up SPF, DKIM, DMARC, DNSSEC and DANE perfectly, you will achieve 100% and receive a place in internet.nl's Hall of Fame. A great recognition for your e-mail security and an important step towards a stronger digital foundation.
Source: Based on the guide from alitajran.com: Inbound SMTP DANE and DNSSEC Exchange Online.
<cybersecurity consultant>