A TLSA record pins your mail server’s TLS certificate in DNS so a sending server either reaches the right key over SMTP or refuses to deliver — and its most common form, 3 1 1, is the heart of DANE (DNS-Based Authentication of Named Entities, RFC 6698; for mail, RFC 7672). This guide shows you how to generate a TLSA record with OpenSSL, publish it, verify it resolves and validates, and fix ...