MTA-STS policy invalid or missing MX
How to fix an MTA-STS policy file that can't be parsed, or that leaves out one of your mail servers, before it causes delivery failures in enforce mode.
By the Domain Health Hub team · Updated
- The policy file needs version: STSv1, a mode, at least one mx: line and max_age.
- Every MX host must match an mx: line. A wildcard covers exactly one label.
- In enforce mode, an MX host missing from the policy is one senders refuse to deliver to.
What the error means
The policy file loads, but either it doesn't follow the format in RFC 8461, or it doesn't list every mail server in the domain's MX records. A valid file has one key and value per line:
version: STSv1 mode: enforce mx: example-com.mail.protection.outlook.com mx: *.backup.example.net max_age: 1209600
- version
- Must be STSv1.
- mode
- enforce, testing or none.
- mx
- One line per mail server pattern. Repeat the key for each one.
- max_age
- Seconds to cache the policy, up to 31557600.
Why it matters
A file that can't be parsed is no policy at all, so you lose the protection. A missing MX host is worse once you enforce: senders will refuse to deliver to a server the policy doesn't name, so email that would have gone to it is delayed and eventually bounces. In testing mode it only shows up in TLS-RPT reports.
How to confirm it
Compare the mx: lines with the domain's MX records. Each MX host must match a line exactly, or through a wildcard such as *.example.net, which covers one label only. Check spelling of the keys and that each line uses a colon.
How to fix it
Correct the file, then change the id in the _mta-sts TXT record so senders fetch the new version instead of their cached copy.
Microsoft 365
Most tenants' MX is a host under mail.protection.outlook.com, so mx: *.mail.protection.outlook.com covers it. Check your actual MX record first: newer set-ups can use a different host.
Google Workspace
List each host your MX records use. For the classic set, mx: aspmx.l.google.com and mx: *.aspmx.l.google.com cover them all; if your MX is smtp.google.com, list that.
Questions
Does *.example.com match mail.eu.example.com?
No. In MTA-STS a wildcard matches only the leftmost label, so *.example.com matches mail.example.com but not mail.eu.example.com.
What's the largest max_age?
31557600 seconds, about a year. Long values are fine once you're confident, but changes then take longer to reach senders that haven't seen the new id.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.