MTA-STS record missing: how to set it up
What MTA-STS does, why a missing or duplicate _mta-sts record leaves email open to downgrade attacks, and how to publish the record and policy file.
By the Domain Health Hub team · Updated
- MTA-STS (RFC 8461) tells other mail servers to deliver to you only over verified, encrypted connections.
- It needs two parts: a TXT record at _mta-sts.<domain> and a policy file served over HTTPS.
- No record, or more than one, means senders act as if you have no policy at all.
What the error means
Encryption between mail servers (STARTTLS) is optional by default: if a connection can't be encrypted, the sender delivers in plain text. MTA-STS lets a domain say “only deliver to my listed mail servers, with a valid certificate”. Senders find it through a TXT record at _mta-sts.<domain>, then fetch the policy file it announces.
We raise this when there's no such record, or when there's more than one. RFC 8461 says that if the number of records starting v=STSv1 isn't exactly one, senders must assume there's no policy.
Why it matters
Without MTA-STS, an attacker who can sit between two mail servers can strip the STARTTLS offer from the conversation, and the sender falls back to plain text without telling anyone. Or they can answer DNS with a mail server of their own. Either way your incoming email can be read or changed in transit.
How to confirm it
Look up TXT records at _mta-sts.<domain>. You should see exactly one, and the policy file should load at https://mta-sts.example.com/.well-known/mta-sts.txt (with your domain in place of example.com).
How to fix it
Publish the policy file first, in testing mode, then the TXT record. The order matters: a record pointing at a missing file is an error of its own.
version: STSv1 mode: testing mx: mail.example.com max_age: 604800
v=STSv1; id=20261007T090000
- id
- Up to 32 letters and digits. Change it every time the policy file changes.
- mode
- testing to start, enforce once reports are clean.
- max_age
- How long senders cache the policy, in seconds. A week is a fair start.
Microsoft 365 and Google Workspace
Neither hosts the policy file for you. List the MX hosts your provider gives you (for example *.mail.protection.outlook.com for most Microsoft 365 tenants), and host the file on any web server that can serve mta-sts.<domain> over HTTPS without redirects.
More than one record
Delete every TXT record at _mta-sts.<domain> except the one whose id matches your current policy.
Questions
Does MTA-STS protect email I send?
No. It protects email sent to your domain, by telling other servers how to deliver to you. Your outgoing email is protected by the receiving domain's MTA-STS.
Do I need TLS-RPT too?
It's strongly recommended. TLS-RPT reports tell you when senders couldn't deliver securely, which is how you know it's safe to move to enforce.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.