MTA-STS and TLS-RPT for small businesses
How MTA-STS makes sure email to a domain arrives encrypted, how TLS-RPT reports problems, and how to switch both on safely.
By the Domain Health Hub team · Updated
- Email between servers is usually encrypted, but by default a sender will fall back to plain text if encryption fails.
- MTA-STS tells senders to insist on encryption for your domain. TLS-RPT asks them to report when it fails.
- Start MTA-STS in testing mode, read the TLS reports, then switch to enforce.
Why it matters
When one mail server hands a message to another, it tries to encrypt the connection. But if encryption fails, or someone in between strips it out, most senders quietly deliver the message unencrypted anyway. MTA-STS (RFC 8461) closes that gap.
How MTA-STS works
It takes two parts: a DNS record that says a policy exists, and the policy file itself.
v=STSv1; id=20260928
version: STSv1 mode: enforce mx: example-com.mail.protection.outlook.com max_age: 604800
- mode
- testing (report only), enforce (refuse unencrypted delivery) or none.
- mx
- Every mail server the domain uses. Wildcards such as *.example.net are allowed.
- max_age
- How long senders remember the policy, in seconds. A week is a sensible start.
- id
- Change it whenever the policy changes, so senders fetch the new one.
TLS-RPT
TLS-RPT (RFC 8460) is a single TXT record asking senders to email a daily report of successful and failed encrypted deliveries:
v=TLSRPTv1; rua=mailto:tls-reports@example.com
Like DMARC reports, they're machine-readable files. Domain Health Hub receives TLS reports at the same address as DMARC reports and shows them side by side.
Switching it on safely
- Publish TLS-RPT first, so you can see what happens.
- Publish an MTA-STS policy in testing mode, listing every MX host.
- Read the TLS reports for two to four weeks and fix any failures.
- Switch the policy to enforce and change the id.
- Whenever the mail provider changes, update the mx lines before the MX records.
Questions
Does MTA-STS protect email the client sends?
No. It protects mail coming in to the domain. Mail the client sends is protected by the receiving domain's own MTA-STS policy.
Why does MTA-STS need a website?
The policy is fetched over HTTPS from mta-sts.<domain>, so a valid certificate proves it really came from the domain owner. Hosted MTA-STS in Domain Health Hub serves the file and certificate for you.
Watch every client's domains, every day.
Reports read for you, and a monthly report card your clients will understand.