Skip to content
MTA-STS and TLS-RPT

MTA-STS record missing: how to set it up

What MTA-STS does, why a missing or duplicate _mta-sts record leaves email open to downgrade attacks, and how to publish the record and policy file.

By the Domain Health Hub team · Updated

In short
  • MTA-STS (RFC 8461) tells other mail servers to deliver to you only over verified, encrypted connections.
  • It needs two parts: a TXT record at _mta-sts.<domain> and a policy file served over HTTPS.
  • No record, or more than one, means senders act as if you have no policy at all.

What the error means

Encryption between mail servers (STARTTLS) is optional by default: if a connection can't be encrypted, the sender delivers in plain text. MTA-STS lets a domain say “only deliver to my listed mail servers, with a valid certificate”. Senders find it through a TXT record at _mta-sts.<domain>, then fetch the policy file it announces.

We raise this when there's no such record, or when there's more than one. RFC 8461 says that if the number of records starting v=STSv1 isn't exactly one, senders must assume there's no policy.

Why it matters

Without MTA-STS, an attacker who can sit between two mail servers can strip the STARTTLS offer from the conversation, and the sender falls back to plain text without telling anyone. Or they can answer DNS with a mail server of their own. Either way your incoming email can be read or changed in transit.

How to confirm it

Look up TXT records at _mta-sts.<domain>. You should see exactly one, and the policy file should load at https://mta-sts.example.com/.well-known/mta-sts.txt (with your domain in place of example.com).

How to fix it

Publish the policy file first, in testing mode, then the TXT record. The order matters: a record pointing at a missing file is an error of its own.

mta-sts.txt
version: STSv1
mode: testing
mx: mail.example.com
max_age: 604800
_mta-sts.example.com TXT
v=STSv1; id=20261007T090000
id
Up to 32 letters and digits. Change it every time the policy file changes.
mode
testing to start, enforce once reports are clean.
max_age
How long senders cache the policy, in seconds. A week is a fair start.

Microsoft 365 and Google Workspace

Neither hosts the policy file for you. List the MX hosts your provider gives you (for example *.mail.protection.outlook.com for most Microsoft 365 tenants), and host the file on any web server that can serve mta-sts.<domain> over HTTPS without redirects.

More than one record

Delete every TXT record at _mta-sts.<domain> except the one whose id matches your current policy.

Questions

Does MTA-STS protect email I send?

No. It protects email sent to your domain, by telling other servers how to deliver to you. Your outgoing email is protected by the receiving domain's MTA-STS.

Do I need TLS-RPT too?

It's strongly recommended. TLS-RPT reports tell you when senders couldn't deliver securely, which is how you know it's safe to move to enforce.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial