MTA-STS policy file not found: fixes
Why senders can't fetch your MTA-STS policy file, from certificate errors to redirects, and how to serve it correctly at the mta-sts subdomain.
By the Domain Health Hub team · Updated
- The policy file must load from https://mta-sts.<domain>/.well-known/mta-sts.txt.
- It needs a valid certificate for mta-sts.<domain>, a 200 response, and no redirects.
- Until senders can fetch it, the _mta-sts record does nothing.
What the error means
The domain has an MTA-STS TXT record, so senders go to fetch the policy file, and the fetch fails. Section 3.3 of RFC 8461 is strict about this request: it must be HTTPS to the mta-sts host, the certificate must be valid for that name, the answer must be a 200, and redirects must not be followed. The file should be served as text/plain.
https://mta-sts.example.com/.well-known/mta-sts.txt
Common causes
- No DNS
- mta-sts.<domain> doesn't exist, so there's nothing to connect to.
- Certificate
- The certificate is for another name (often the main website's), expired, or self-signed.
- Redirect
- The host sends visitors to https://www.<domain> or a login page.
- Wrong path
- The file isn't at /.well-known/mta-sts.txt, so the server answers 404.
How to confirm it
Open the policy URL in a browser. You should see the file as plain text, the address bar shouldn't change, and there should be no certificate warning. Our checker shows the exact error it got.
How to fix it
Point mta-sts.<domain> at a web host that can serve the file, issue a certificate for that exact name (Let's Encrypt is fine), and turn off any redirect rule for that host.
Cloudflare DNS
If you serve the file yourself behind Cloudflare's proxy, check no redirect rule or page rule sends the mta-sts host anywhere else. If the host points at our hosted policy, set its CNAME to DNS only: proxying it breaks our certificate.
Questions
Can I redirect mta-sts to my main website?
No. RFC 8461 says senders must not follow redirects when fetching the policy, so a redirect means no policy.
Does an unreachable policy stop my email?
No. Senders that can't fetch a policy deliver as if you had none. Ones that cached an earlier policy keep using it until it expires.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.