Skip to main content
WebTools

MTA-STS checker

Check whether a domain asks other mail servers to use secure, verified connections when they deliver its email.

Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.

What we check

MTA-STS (RFC 8461) has two parts, and both must be right:

We read the policy's mode, max_age and mx lines, and compare every MX server of the domain with the mx patterns. A pattern such as *.mail.example.com matches exactly one extra label.

Rolling out safely

  1. Publish the policy with mode: testing and a TLS-RPT record, so you receive reports.
  2. When reports show no problems, change to mode: enforce and update the id in the DNS record.
  3. Raise max_age to a week or more.

Frequently asked questions

What is MTA-STS?

Mail Transfer Agent Strict Transport Security (RFC 8461). A domain publishes a policy saying its mail servers support encrypted connections with valid certificates, so sending servers refuse to deliver over an insecure or intercepted connection.

What do enforce, testing and none mean?

"enforce": senders that support MTA-STS won't deliver unless the connection is secure and the server is listed. "testing": they still deliver, but report problems (with TLS-RPT). "none": the policy is being withdrawn.

Why must the policy not redirect?

RFC 8461 says senders must not follow redirects when fetching the policy, so a redirect means senders can't read it. Serve the file directly from https://mta-sts.<your domain>/.well-known/mta-sts.txt.

What does the MX check mean?

Every mail server in your MX records must match an "mx" line in the policy. In enforce mode, senders refuse to deliver to a server that doesn't match, so mail could be lost.

What should max_age be?

How long senders may keep the policy, in seconds. Once everything works, a week or more (604800) is common; the maximum is about a year. Under a day gives little protection.

  • TLS-RPT Checker

    Check where other mail servers send reports when they can't make a secure connection to a domain's mail servers.

  • MX Lookup

    See which mail servers receive email for a domain, in priority order, with each server's addresses.

  • SSL Certificate Checker

    Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.

  • DMARC Checker

    Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.

  • SPF Checker

    Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.

  • Website Health Check

    Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.