{"id":7002,"date":"2024-11-02T18:47:54","date_gmt":"2024-11-02T17:47:54","guid":{"rendered":"https:\/\/warpnet.nl\/?p=7002"},"modified":"2026-01-07T09:58:33","modified_gmt":"2026-01-07T08:58:33","slug":"dane-en-dnssec-voor-exchange-online","status":"publish","type":"post","link":"https:\/\/warpnet.nl\/en\/blog\/dane-en-dnssec-voor-exchange-online\/","title":{"rendered":"Configure DANE and DNSSEC for Exchange Online."},"content":{"rendered":"<p class=\"has-medium-font-size\">Looking for ways to improve the security of your e-mail traffic? Microsoft announced in October full support for the email security standard DANE on Exchange Online. This also gave existing Exchange Online customers the ability to enable the additional security options.<\/p>\n\n\n\n<p>As of early 2022, Microsoft is already offering support for <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/releasing-outbound-smtp-dane-with-dnssec\/ba-p\/3100920\" data-type=\"link\" data-id=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/releasing-outbound-smtp-dane-with-dnssec\/ba-p\/3100920\" target=\"_blank\" rel=\"noopener\">DANE on outgoing mail<\/a>, but the <a href=\"https:\/\/learn.microsoft.com\/nl-nl\/purview\/how-smtp-dane-works\" target=\"_blank\" rel=\"noopener\">support on incoming mail <\/a>has been a while in coming. Although this option has now become available, much of the configuration cannot be put through Microsoft's web portal, instead it must be done using various PowerShell cmdlets.<\/p>\n\n\n\n<p>To configure SMTP DANE with DNSSEC for incoming mail on Exchange Online, there are a number of steps that need to be completed:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Update the Time To Live (TTL) value of the existing MX record to the lowest possible value. Then wait at least the length of the previous TTL value before implementing the next step. If the previous TTL value was at, say, '3600 seconds' or '1 hour' before it was changed, you should wait at least 1 hour before performing step 2.<\/li>\n\n\n\n<li>Connect to Exchange Online via the <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/exchange\/connect-exchangeonline?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">Connect-ExchangeOnline cmdlet<\/a> by entering in PowerShell the command <code>Connect-ExchangeOnline<\/code> execute.<\/li>\n\n\n\n<li>To use SMTP DANE with DNSSEC, DNSSEC must first be enabled. This can be done using the <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/exchange\/enable-dnssecforverifieddomain?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">Enable-DnssecForVerifiedDomain cmdlet<\/a>. For <em>warpnet.co.uk<\/em> the command looks like this:<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">&gt; Enable-DnssecForVerifiedDomain -DomainName \"warpnet.co.uk\"\n\nDnssecMxValue Result ErrorData\n------------- ------ ---------\nwarpnet-en.s-v1.mx.microsoft Success<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use the <strong>DnssecMxValue<\/strong> value to create a new MX record on the domain. Make sure it gets a priority value of 20 and uses the lowest possible TTL value.<\/li>\n\n\n\n<li>Verify that the newly configured incoming mail server is working correctly by using the <a href=\"https:\/\/testconnectivity.microsoft.com\/tests\/O365InboundSmtp\/input\" target=\"_blank\" rel=\"noopener\">Inbound SMTP Email Test<\/a> from Microsoft. Unfolding the test steps reveals whether the new Mail Exchanger on the domain is <strong>mx.microsoft<\/strong> works correctly as shown in the screenshot below.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"565\" src=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.24.52-1024x565.png\" alt=\"\" class=\"wp-image-7003\" style=\"width:542px;height:auto\" srcset=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.24.52-1024x565.png 1024w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.24.52-300x166.png 300w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.24.52-768x424.png 768w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.24.52-18x10.png 18w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.24.52.png 1348w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Delete the old MX record which ends in <em>mail.protection.outlook.com<\/em>, <em>mail.eo.outlook.com<\/em> or <em>mail.protection.outlook.de<\/em>. Next, the TTL value of the MX record ending in mx.microsoft can be changed to 3600 seconds or 1 hour.<\/li>\n\n\n\n<li>Verify that everything is working correctly by running the <em>DNSSEC Validation <\/em>test in the <a href=\"https:\/\/testconnectivity.microsoft.com\/tests\/O365DaneValidation\/input\" target=\"_blank\" rel=\"noopener\">Remote Connectivity Analyzer<\/a> from Microsoft for the domain as shown in the screenshot below.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"972\" height=\"308\" src=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.30.39.png\" alt=\"\" class=\"wp-image-7004\" style=\"width:370px;height:auto\" srcset=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.30.39.png 972w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.30.39-300x95.png 300w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.30.39-768x243.png 768w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.30.39-18x6.png 18w\" sizes=\"(max-width: 972px) 100vw, 972px\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Once DNSSEC is enabled, SMTP DANE can also be used on the incoming mail server. To configure this, the <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/exchange\/enable-smtpdaneinbound?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">Enable-SmtpDaneInbound cmdlet<\/a>. For <em>warpnet.co.uk<\/em> the command looks like this:<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">&gt; Enable-SmtpDaneInbound -DomainName \"warpnet.co.uk\"\n\nResult ErrorData\n------ ---------\nSuccess<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Verify that both DNSSEC and SMTP DANE records (TLSA) are correctly configured by <em>DANE Validation (including DNSSEC) <\/em>test in the <a href=\"https:\/\/testconnectivity.microsoft.com\/tests\/O365DaneValidation\/input\" target=\"_blank\" rel=\"noopener\">Remote Connectivity Analyzer<\/a> from Microsoft for the domain as shown in the screenshot.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"158\" src=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-1024x158.png\" alt=\"\" class=\"wp-image-7005\" style=\"width:791px;height:auto\" srcset=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-1024x158.png 1024w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-300x46.png 300w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-768x118.png 768w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-1536x237.png 1536w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-18x3.png 18w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25-1920x296.png 1920w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.41.25.png 1998w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"\/><\/figure>\n\n\n\n<p>The configuration for SMTP DANE with DNSSEC on the incoming mail server of Exchange Online should now be successfully implemented. Optionally you can use the e-mail test of <a href=\"https:\/\/internet.nl\/\" target=\"_blank\" rel=\"noopener\">internet.co.uk<\/a>. This also shows possible other areas of improvement regarding the use of IPv6, DMARC, DKIM and SPF as shown in the following screenshot.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"574\" src=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.43.16-1024x574.png\" alt=\"\" class=\"wp-image-7006\" style=\"width:476px;height:auto\" srcset=\"https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.43.16-1024x574.png 1024w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.43.16-300x168.png 300w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.43.16-768x431.png 768w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.43.16-18x10.png 18w, https:\/\/warpnet.nl\/wp-content\/uploads\/2024\/11\/Screenshot-2024-11-02-at-18.43.16.png 1344w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"\/><\/figure>","protected":false},"excerpt":{"rendered":"<p>Looking for ways to improve the security of your e-mail traffic? Microsoft announced in October full support for the email security standard DANE on Exchange Online.<\/p>","protected":false},"author":9,"featured_media":7090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[14],"tags":[],"class_list":["post-7002","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"acf":[],"_links":{"self":[{"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/posts\/7002","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/comments?post=7002"}],"version-history":[{"count":9,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/posts\/7002\/revisions"}],"predecessor-version":[{"id":9752,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/posts\/7002\/revisions\/9752"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/media\/7090"}],"wp:attachment":[{"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/media?parent=7002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/categories?post=7002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/warpnet.nl\/en\/wp-json\/wp\/v2\/tags?post=7002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}