Exchange Online supports inbound SMTP DANE with DNSSEC for eligible accepted domains. To enable it safely, first lower the domain’s MX-record TTL, enable DNSSEC in Exchange Online, publish the Microsoft-generated MX target, validate DNS and mail flow, make that target the authoritative MX route, and then enable inbound DANE. The PowerShell commands are only part of the change: DNSSEC delegation, MX priority, TLSA records, MTA-STS policy, and any inbound gateway all need to be checked.
What inbound SMTP DANE changes
DNSSEC and DANE address different parts of the mail-delivery trust problem. DNSSEC uses cryptographic signatures to help a validating resolver detect altered DNS answers, including a forged MX response. DANE for SMTP uses DNSSEC-authenticated TLSA records to associate a mail server’s TLS certificate or public key with the domain’s DNS data. Together, they can help protect SMTP delivery against MX tampering, STARTTLS downgrade attacks, and interception by an impersonating server. DANE strengthens TLS authentication and policy; it does not replace TLS. See Microsoft’s explanation of how SMTP DANE works, the SMTP DANE standard, and the DNSSEC overview.
Inbound is not outbound
Inbound SMTP DANE protects the route external senders use to deliver messages to your Exchange Online domain. You enable it for an accepted domain that you manage. Outbound SMTP DANE is separate: Exchange Online can use DANE when sending to external domains that publish valid DNSSEC and TLSA data; Microsoft says outbound DANE is enabled by default on its side and requires no customer configuration there. Enabling inbound DANE does not make every outbound destination use DANE, nor does it guarantee that every message on either path is DANE-protected. See Microsoft’s outbound transit-security report documentation.
Check prerequisites before changing DNS
Microsoft’s documented procedure is intended for a verified, healthy accepted domain in Microsoft 365. You need Exchange Online PowerShell access and sufficient permissions to run the relevant cmdlets, plus control over the domain’s authoritative DNS zone. Confirm that your DNS provider supports DNSSEC and the required MX-record workflow; check separately whether you can manage TLSA records if your DNS design requires it.
#1 Best Overall
- Compatibility: fixed base compact routers, allowing quick attachment to the router mounting base.
- Adjustable design: Adjustable edge guides for precise routing of various workpieces, easy positioning adjustment, compact fixing, and we have designed two scale units for easier observation and improved accuracy.
- Compatible with most models: This DNP618 straight edge guide works perfect for DW6913 Router Edge Guide, PORTER-CABLE 450 &451, DCW600B 20V Max XR CORDLESS ROUTER, DWP611PK, DNP612 Plunge Base, DWP611 COMPACT ROUTER
- Versatile Application: Suitable for edge routing, trimming, and other woodworking tasks requiring a fixed base router. Secure Fit: Ensures a snug and stable fit on the router base for controlled and consistent routing operations.
- Durable Construction: Crafted from high-quality materials to withstand the rigors of regular workshop use.
- Record every current MX target, preference, and TTL, and identify the authoritative DNS provider.
- Map inbound filtering gateways, smart hosts, connectors, and other devices that receive or relay mail.
- Check whether the domain publishes an MTA-STS policy and identify its current mode and
max_age. - Review any fallback or secondary MX design. Microsoft’s procedure assumes the existing MX is priority 0 or 10 and no fallback or secondary MX is in use; extra MX records can complicate validation and route mail to an endpoint that does not provide the intended DANE protection.
- Assign an owner to keep certificate or public-key changes coordinated with TLSA records over time.
Microsoft documents self-service or viral-sign-up domains and the default onmicrosoft.com domain as unsupported for inbound SMTP DANE with DNSSEC. For domains where Microsoft name servers are authoritative, check current Microsoft guidance and tenant-specific behavior rather than assuming support. The configuration also depends on DNS provider capabilities and the complete mail-routing design, not just the Exchange Online tenant.
Understand the DNS and MX migration
The safe order matters. The Microsoft-generated DNSSEC MX target is introduced temporarily at priority 20 while the existing route remains available for validation. After DNSSEC and mail flow are confirmed, the generated target becomes the highest-priority route—normally priority 0—and the legacy Exchange Online MX is removed. Only then should you enable inbound SMTP DANE.
| Stage | MX state | Purpose |
|---|---|---|
| Before migration | Existing MX target and preference | Capture the current route and reduce its TTL before changing it. |
| Validation | Existing MX retained; Microsoft-generated mx.microsoft target added at priority 20 |
Validate the DNSSEC-enabled route without prematurely removing the existing route. |
| Final state | Microsoft-generated target at priority 0; legacy Exchange Online MX removed | Make the DNSSEC-enabled route the authoritative inbound destination. |
For MX records, a lower preference number means higher priority. Do not guess the generated hostname: use the exact DnssecMxValue returned for your domain.
Enable inbound SMTP DANE step by step
1. Lower the MX TTL and wait
At your authoritative DNS provider, reduce the existing MX record’s TTL to the lowest supported value, but not below 30 seconds. Wait at least the previous TTL before changing the route, so cached copies of the old record have time to expire. For example, if the former TTL was 3,600 seconds, wait about one hour after lowering it. Resolver caching can last longer in practice, so monitor public DNS rather than assuming every sender has updated immediately.
2. Enable DNSSEC for the verified domain in Exchange Online
Connect to Exchange Online PowerShell, then run:
Enable-DnssecForVerifiedDomain -DomainName contoso.com
Replace contoso.com with your accepted domain. The command returns a domain-specific DnssecMxValue, for example:
Rank #2
- Precision Centering: centering tool Achieve precise centering when changing or adjusting sub bases, ensuring accurate alignment of the router's tool, enhancing overall precision for woodworking tasks.
- Versatility: The router centering pin is compatible with DEWALT router bases and works seamlessly with most 1/4-inch routers. Tailored specifically for fixed base compact routers, it offers flexibility and adaptability for a wide range of woodworking tasks. Designed to meet the demands of diverse projects, this product provides a versatile solution for woodworking enthusiasts.
- Robust Construction: for dewalt router accessories Crafted with a silver steel pin and durable plastic cone, the product ensures sturdiness and durability, making it well-suited for frequent use in woodworking projects.
- User-Friendly Design: Easy to use with a straightforward process – simply insert the guide pin into the router collet, place the cone onto the pin, and tighten the screws on the sub base. The product is designed for user convenience, saving setup time.
- Quick Setup: The product's simplicity allows for a quick setup, enabling users to carry out woodworking tasks more efficiently. Ideal for scenarios where sub bases need frequent changes or adjustments.
Result DnssecMxValue
------ -------------
Success contoso-com.o-v1.mx.microsoft
The example hostname is illustrative only; publish the exact value returned for your domain. See the Enable-DnssecForVerifiedDomain cmdlet reference.
3. Add the generated MX record at priority 20
In the authoritative DNS zone, create an MX record using the returned DnssecMxValue exactly, with preference 20 and a low TTL during migration. Keep the existing Exchange Online MX active for the validation phase. Do not construct or alter the generated target yourself.
4. Validate DNSSEC and the mail route
Use Microsoft’s Remote Connectivity Analyzer and independent public DNS checks. Confirm that the generated MX is visible, resolves correctly, and passes DNSSEC validation; check that the mail exchanger is reachable, offers SMTP STARTTLS, and presents a valid certificate. Also verify that no unintended MX has equal or higher preference. Send a test message through the actual inbound path, including any gateway or connector.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
5. Make the generated MX authoritative
Once validation succeeds, set the Microsoft-generated mx.microsoft MX record to priority 0 and remove the legacy Exchange Online MX target, which may end in mail.protection.outlook.com, mail.eo.outlook.com, or mail.protection.outlook.de, depending on the domain. Confirm that no competing MX record has the same priority. After the migration is stable, return the TTL to a normal operational value; 3,600 seconds is one example, not a Microsoft requirement.
6. Enable inbound SMTP DANE
After DNSSEC enablement and the MX migration are complete, run:
Rank #3
- Compatibility: Compatible with DCW600B 20V Max XR CORDLESS ROUTER, DWP611 COMPACT ROUTER, DWP611PK, and DNP612.
- Quality Material:Made of a steel pin and durable plastic cone that allow for precise centering when changing or adjusting sub-bases.
- Easy Installation: Simply place pin in router collet, place cone on pin and tighten screws on sub base. Easy to use and quick to setup.
- Tip: Works on both 1/4" and 1/2" collets by flipping the pin over.
- Thank you for choosing our products! We prioritize your satisfaction above all else. If you encounter any issues with your purchase.please contact us immediately-we will resolve your problem and provide a satisfactory solution within 24 hours.
Enable-SmtpDaneInbound -DomainName contoso.com
This enables inbound SMTP DANE for the specified accepted domain. See the Enable-SmtpDaneInbound cmdlet reference.
7. Check TLSA publication and status
Allow time for the TLSA records to appear. Microsoft says propagation can take approximately 15–30 minutes; DNS caching and resolver behavior may extend the time observed from a particular network. Microsoft publishes multiple TLSA records for reliability and notes that it is expected that some may fail validation: at least one valid TLSA record is sufficient for the configuration to be considered successful. Inspect the published records with the Remote Connectivity Analyzer and independent DNS tools; a successful PowerShell command by itself does not prove that public DNS and mail delivery are correct.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsCheck service status with:
Get-DnssecStatusForVerifiedDomain -DomainName contoso.com
Get-SmtpDaneInboundStatus -DomainName contoso.com
These report DNSSEC and inbound SMTP DANE status in Exchange Online. See the DNSSEC status cmdlet and SMTP DANE status cmdlet.
Handle MTA-STS during the transition
MTA-STS and DANE provide different trust mechanisms and can coexist, but cached policy and MX changes need to be coordinated. If your domain has an MTA-STS policy, Microsoft’s procedure calls for temporarily switching it to testing, changing the policy ID, and waiting for the previous max_age to expire before the MX/DNSSEC/DANE migration. After validating the new route and mail flow, return the policy to enforce and change the policy ID again. Do not leave an old enforced policy in place while changing its assumptions about the mail route.
| Mechanism | Trust mechanism | Main purpose |
|---|---|---|
| Opportunistic TLS | SMTP STARTTLS negotiation | Encrypts when available, but can be vulnerable to downgrade. |
| MTA-STS | HTTPS-hosted policy and publicly trusted certificates | Lets domains publish a policy requiring TLS and authenticated servers. |
| DANE for SMTP | DNSSEC-authenticated TLSA records | Binds SMTP TLS identity to authenticated DNS data. |
| DNSSEC | Cryptographic signatures on DNS data | Enables validation that DNS answers, including TLSA records, have not been altered. |
DANE relies on DNSSEC for trustworthy TLSA data; MTA-STS instead relies on HTTPS and public certificate-authority trust. Neither method means every sender will apply the policy unless its delivery software supports and validates it. See Microsoft’s DANE and MTA-STS guidance.
Rank #4
- 【model】DNP618 Router Edge Guide
- 【Compatibility】 fixed base compact routers, allowing quick attachment to the router mounting base.
- 【Compatible with most models】 This DNP618 straight edge guide works perfect for DWP611PK, DNP612 Plunge Base,DWP611 COMPACT ROUTER DW6913 DCW600B 20V Max XR CORDLESS ROUTER etc.
- 【Versatile Application】 DNP618 Edge Guide for Fixed-Base Compact Routers Quickly installs onto fixed-base compact routers, the DNP618 is a router edge guide accessory designed specifically for fixed-base compact routers. It allows for precise positioning when performing tasks such as inlays, mortises, and other router applications
- 【Adjustable design】Adjustable edge guides for precise routing of various workpieces, easy positioning adjustment, compact fixing, and we have designed two scale units for easier observation and improved accuracy.
Troubleshoot validation failures and non-delivery reports
Microsoft’s documented error codes may be refined over time. The leading digit indicates whether the reported condition is temporary (4) or permanent (5); use the full diagnostic detail and verify DNS before deciding which component failed.
| Code | Reported meaning | What to check |
|---|---|---|
4/5.7.321 |
starttls-not-supported |
Confirm STARTTLS is available on the receiving endpoint and that the message is reaching the intended server. |
4/5.7.322 |
certificate-expired |
Renew the SMTP server certificate and confirm the endpoint presents the valid certificate. |
4/5.7.323 |
tlsa-invalid |
Check that the published TLSA data matches the certificate or key presented by the SMTP endpoint. |
4/5.7.324 |
dnssec-invalid |
Investigate DNSSEC signing, delegation, DS data, and resolver validation. |
4/5.4.312 |
Generic DNS query failure reported in some DNSSEC failure scenarios | Check DNSSEC and MX resolution; this code alone does not establish the precise cause. |
Microsoft’s DANE guidance describes the error conditions. The HTMD article also summarizes the NDR codes.
MX priority or duplicate-record errors
If the generated MX exists but is not highest priority, or Exchange Online reports a priority mismatch, check the numeric preferences in public DNS. The final generated MX should be the sole priority-0 record. Remove unintended competing records and allow caches to expire before rechecking. Duplicate MX records with the same preference can cause different senders to select different servers.
DNSSEC delegation failures
A zone can appear signed while validation still fails if the parent-zone DS record does not match the active DNSSEC key, or if authoritative servers publish inconsistent DNSKEY or RRSIG data. Check the registrar’s DS record and the authoritative zone with your DNS provider before changing DNSSEC state; avoid disabling and re-enabling it as a first diagnostic step.
TLSA mismatch or certificate rollover
A tlsa-invalid result can mean the TLSA record does not match the certificate or public key served by the SMTP endpoint. Include TLSA updates in certificate renewal and rollover procedures, and test the new records and certificate while the previous configuration is still available where your certificate and DNS design permit it. Removing an old certificate before the corresponding DNS and endpoint state are correct can disrupt delivery.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- PRECISION ROUTING CONTROL Achieve clean, straight and accurate cuts every time. This DNP618 edge guide keeps your router perfectly aligned along edges for professional woodworking results.
- WIDE COMPATIBILITY Designed for DEWALT DCW600B, DWP611, DWP611PK, and DNP612 plunge base. Also fits DW6913 edge guide and Porter-Cable 450 & 451 routers.
- QUICK & EASY ATTACHMENT Tool-free or fast setup design allows you to attach the guide quickly to your router base, saving time on every project.
- FULLY ADJUSTABLE DESIGN Easily adjust the distance from the edge for different cutting widths. Ideal for trimming, grooving, and edge-routing tasks.
- DURABLE & STABLE CONSTRUCTION Built with high-quality materials for long-lasting use. Provides stable guidance and reduces vibration for smoother operation.
Third-party inbound gateways
If a filtering gateway receives internet mail before relaying it to Exchange Online, treat internet-to-gateway and gateway-to-Exchange as separate SMTP paths. Confirm with the gateway vendor whether it supports the DNSSEC/DANE validation behavior required for the relevant path, and update its smart host if it must relay to the new Microsoft-generated MX target. Do not assume the legacy mail.protection.outlook.com target remains appropriate after migration. Test connectors, message flow, and TLS behavior end to end.
Roll back in a controlled way
If inbound DANE validation is causing mail-flow problems, disable that feature for the domain:
Disable-SmtpDaneInbound -DomainName contoso.com
See the Disable-SmtpDaneInbound cmdlet reference. If DNSSEC itself is unhealthy and is causing problems, the corresponding Exchange Online command is:
Disable-DnssecForVerifiedDomain -DomainName contoso.com
See the Disable-DnssecForVerifiedDomain cmdlet reference.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Identify whether the failure is in SMTP DANE, DNSSEC, MX routing, the gateway, or more than one layer before changing records.
- Disable the affected Exchange Online feature as appropriate, then correct the DNS provider’s signing, delegation, or record configuration.
- Verify valid MX resolution and test the route with the Remote Connectivity Analyzer and a real message.
- Restore the intended MX records, TTL, MTA-STS mode and policy ID, and gateway smart-host settings for the chosen recovery state.
- Re-enable DNSSEC or DANE only after the relevant DNS and SMTP checks pass.
Decide whether the operational trade-off fits
Inbound DANE is a good fit when your organization controls its authoritative DNS, can reliably manage DNSSEC delegation, has a straightforward MX design, and can coordinate certificate changes with TLSA data. It adds a stronger DNS-backed check to SMTP TLS, but also makes mail availability depend on correct DNSSEC and TLSA operations.
- Consider enabling it when protection from forged MX responses and downgrade attacks is a priority, DNSSEC operations are mature, and all gateways and connectors can be tested.
- Delay it if registrar DS management is uncertain, DNSSEC is unstable, certificate renewals are automated without TLSA updates, or multiple legacy MX providers are difficult to coordinate.
- Verify provider capability before committing: DNSSEC support alone does not guarantee convenient DS management, TLSA record publishing, logging, or automation.
DANE can be attractive when DNSSEC operations are mature and DNS-based TLS identity binding is desired. MTA-STS may fit better when HTTPS hosting and public certificate-authority validation are easier for the organization to operate. They are not mutually exclusive, but their policy state and cache behavior must be managed together.
Operational checklist
- Before: confirm the accepted domain is healthy, identify the authoritative DNS provider, record MX values and TTLs, map gateways, review MTA-STS, and designate certificate/TLSA ownership.
- During: lower the MX TTL to at least 30 seconds, wait out the previous TTL, enable DNSSEC, publish the exact returned MX at priority 20, and validate DNSSEC and mail flow.
- Cutover: make the generated MX priority 0, remove the legacy Exchange Online MX, verify there is no competing priority-0 record, and enable SMTP DANE.
- After: check status cmdlets, public TLSA records, SMTP STARTTLS and certificate validation, real inbound delivery, and gateway-to-Exchange flow; restore a normal TTL when stable.
- Ongoing: include TLSA and endpoint checks in certificate rotation and DNS change procedures, and monitor delivery errors that indicate DNSSEC, TLSA, or STARTTLS failures.
Availability context
Inbound SMTP DANE with DNSSEC is now documented by Microsoft as an Exchange Online capability; old roadmap dates are historical, not current availability guidance. Microsoft’s original announcement anticipated inbound general availability in July 2023, while an earlier projection had pointed to June 2024. Those dates describe rollout planning at the time, not a current activation requirement. See the original Exchange Team announcement and the outbound DANE announcement.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




