Skip to content

MTA-STS and TLS-RPT for small businesses

How MTA-STS makes sure email to a domain arrives encrypted, how TLS-RPT reports problems, and how to switch both on safely.

By the Domain Health Hub team · Updated

In short
  • Email between servers is usually encrypted, but by default a sender will fall back to plain text if encryption fails.
  • MTA-STS tells senders to insist on encryption for your domain. TLS-RPT asks them to report when it fails.
  • Start MTA-STS in testing mode, read the TLS reports, then switch to enforce.

Why it matters

When one mail server hands a message to another, it tries to encrypt the connection. But if encryption fails, or someone in between strips it out, most senders quietly deliver the message unencrypted anyway. MTA-STS (RFC 8461) closes that gap.

How MTA-STS works

It takes two parts: a DNS record that says a policy exists, and the policy file itself.

_mta-sts.example.com TXT
v=STSv1; id=20260928
https://mta-sts.example.com/.well-known/mta-sts.txt
version: STSv1
mode: enforce
mx: example-com.mail.protection.outlook.com
max_age: 604800
mode
testing (report only), enforce (refuse unencrypted delivery) or none.
mx
Every mail server the domain uses. Wildcards such as *.example.net are allowed.
max_age
How long senders remember the policy, in seconds. A week is a sensible start.
id
Change it whenever the policy changes, so senders fetch the new one.

TLS-RPT

TLS-RPT (RFC 8460) is a single TXT record asking senders to email a daily report of successful and failed encrypted deliveries:

_smtp._tls.example.com TXT
v=TLSRPTv1; rua=mailto:tls-reports@example.com

Like DMARC reports, they're machine-readable files. Domain Health Hub receives TLS reports at the same address as DMARC reports and shows them side by side.

Switching it on safely

  1. Publish TLS-RPT first, so you can see what happens.
  2. Publish an MTA-STS policy in testing mode, listing every MX host.
  3. Read the TLS reports for two to four weeks and fix any failures.
  4. Switch the policy to enforce and change the id.
  5. Whenever the mail provider changes, update the mx lines before the MX records.

Questions

Does MTA-STS protect email the client sends?

No. It protects mail coming in to the domain. Mail the client sends is protected by the receiving domain's own MTA-STS policy.

Why does MTA-STS need a website?

The policy is fetched over HTTPS from mta-sts.<domain>, so a valid certificate proves it really came from the domain owner. Hosted MTA-STS in Domain Health Hub serves the file and certificate for you.

Watch every client's domains, every day.

Reports read for you, and a monthly report card your clients will understand.

Start 28-day free trial