Skip to content
Free, no sign-up

MTA-STS checker

Check a domain's MTA-STS record and policy file, whether the policy matches its real mail servers, and whether TLS reports are switched on.

What this checks

  • The _mta-sts TXT record, and that there's exactly one
  • The policy file at mta-sts.<domain>, fetched over HTTPS with a valid certificate
  • The mode (testing, enforce or none) and max_age
  • Whether every MX host matches one of the policy's mx lines
  • Whether a TLS-RPT record asks for reports on failures

An example, explained

Policy file at https://mta-sts.example.co.uk/.well-known/mta-sts.txt
version: STSv1
mode: enforce
mx: *.mail.protection.outlook.com
max_age: 604800
mode
testing reports problems only; enforce refuses unencrypted delivery.
mx
Each mail server allowed. *. matches exactly one extra label.
max_age
How long senders remember the policy, in seconds (604800 is a week).

What MTA-STS does, and where it goes wrong

Email between servers is usually encrypted, but by default a sender falls back to plain text if encryption fails, and an attacker in the middle can make it fail. MTA-STS lets a domain say: only deliver to these mail servers, over TLS with a valid certificate.

It takes three parts:

  • a TXT record at _mta-sts. with the domain, like v=STSv1; id=20261007, whose id changes whenever the policy does;
  • a policy file served over HTTPS at mta-sts. plus the domain, under /.well-known/mta-sts.txt, with a certificate valid for that name;
  • mx lines in the policy that match every real MX host.

Common problems

  • The policy can't be fetched: no web server on the mta-sts name, or a certificate that doesn't cover it. Senders then ignore MTA-STS.
  • An MX host isn't listed: in enforce mode, senders refuse to deliver to it. This bites after a move to a new mail provider.
  • Stuck in testing: fine while you watch the TLS reports, but it doesn't protect anything until it's enforced.

The awkward part is the web hosting, not the record: you need HTTPS on a name that has nothing to do with the website. Hosted MTA-STS serves the policy and its certificate for you. More in the MTA-STS and TLS-RPT guide.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

Do I need MTA-STS?

It protects incoming email from being downgraded to plain text in transit. It matters most for domains that receive sensitive email, and it's worth having on any domain that receives mail.

Should I start in testing or enforce?

Testing, with TLS-RPT switched on. Read the reports for a week or two, fix anything they show, then move to enforce and change the id in the TXT record.

Why does the policy need its own certificate?

Senders fetch it from mta-sts plus your domain over HTTPS and check the certificate, so the policy can't be faked. Your website's certificate only helps if it also covers that name.

Does this check connect to my mail servers?

No. The free checker reads DNS and fetches the policy file over HTTPS. It doesn't connect to mail servers on port 25.

Host MTA-STS without a web server.

Start a free 28-day trial: up to 3 domains, no card needed.