What is MagicDANE?

Skip to main content
Du bist hier:
Drucken

What is MagicDANE?

What is MagicDANE?

MagicDANE is a system developed by FireStorm that automatically creates and manages DANE/TLSA records for all hosted domains. DANE (DNS-based Authentication of Named Entities) protects email connections from man-in-the-middle attacks.

The Problem

In a normal email transmission via SMTP, TLS (encryption) is supported but not enforced. An attacker can position themselves between sender and recipient and:

  • Downgrade the encryption (downgrade attack)
  • Present a forged certificate
  • Read or modify emails

The Solution: DANE/TLSA

DANE publishes the fingerprint (hash) of the mail server certificate as a TLSA record in DNS. Because the DNS zone is signed with DNSSEC, this entry cannot be forged. The sending mail server can verify:

  • Whether the receiving server has the correct certificate
  • Whether the connection must be encrypted
  • Whether no intermediary is manipulating the connection

What makes MagicDANE special?

With most hosters, TLSA records must be created manually and updated with every certificate change. In practice, almost nobody does this.

MagicDANE solves this:

  • Fully automatic: TLSA records are created without any customer action
  • External mail servers: Works even if your mail server is with another provider — MagicDANE detects the server automatically
  • Certificate changes: Records are automatically updated
  • Free: MagicDANE is included with every domain at FireStorm

No other Swiss hoster offers this level of automation.

Check your domain

You can verify if DANE is active for your domain using our DANE Checker.

Check DANE now

Related Post