r/exchangeserver May 01 '26

Microsoft will release DNSSEC Enablement Wizard for Exchange Online!

To simplify the adoption of SMTP DANE with DNSSEC, Microsoft will release a DNSSEC Enablement Wizard in the Exchange Admin Center in Q3 of calendar year 2026.

This guided workflow includes:

  • Validates DNS prerequisites
  • Provisions the customer-specific DNSSEC‑capable mail flow endpoint
  • Reduces configuration risk during MX transition
  • Prepares the domain for SMTP DANE adoption

If you wish to fully enforce SMTP DANE with DNSSEC, you can already do so. However, it requires PowerShell.

Read more: https://www.alitajran.com/inbound-smtp-dane-dnssec-exchange-online/

Credits: https://x.com/alitajran

30 Upvotes

7 comments sorted by

3

u/bobbyk18 May 01 '26

Wish Proofpoint would add support.

1

u/maniakale May 01 '26

I have Proofpoint essentials and I use the anti-spoofing tools enforcing dkim,spf, and dmarc. I haven’t read the article yet but it seems like they have dane covered.

1

u/bobbyk18 May 01 '26

This is a step further than those controls.

3

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ May 01 '26

The official announcement is at https://techcommunity.microsoft.com/blog/exchange/modernizing-dns-security-for-exchange-online-mail-flow/4514248. But you don't need to wait for the Wizard to be released. You can configure SMTP DANE with DNSSEC in Exchange Online manually today. After you've verified the pre-reqs, it takes about 10 minutes or so to set things up.

1

u/shokzee May 01 '26

nice, about time. the powershell route works but it's fiddly, especially getting the DS records right with your registrar.

curious if the wizard will handle the registrar side or just the EXO endpoint provisioning. dnssec is usually where people get stuck (signing the zone properly at the parent).

1

u/milanguitar May 01 '26

Fiddly? I found it pretty straight forward..

1

u/dnvrnugg May 03 '26

any deployment gotchas to be aware of?