Implement validation of DANE/TLSA resource records for DNSSEC enabled sites and configurable actions in case of failed validation (in case a TLSA resource record has been found but does not match the certificate)
Reference: http://tools.ietf.org/html/rfc6698 (DNS-Based Authentication of Named Entities (DANE) / Transport Layer Security (TLS) Protocol: TLSA)