/
What is DANE
DANE publishes a TLSA record that associates a TLS certificate or public key with the name where the record is found. For SMTP, RFC 7672 looks that record up at _25._tcp plus the mail host.
_25._tcp.mx.example.com. IN TLSA
RFC 7672's example query, for mx.example.com on port 25, is _25._tcp.mx.example.com. IN TLSA. Destinations that do not publish TLSA records continue to be sent with pre-DANE opportunistic TLS. The HTTP examples in RFC 6698 use _443._tcp.www.example.com.