MTA-STS checker
Check whether a domain asks other mail servers to use secure, verified connections when they deliver its email.
Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.
What we check
MTA-STS (RFC 8461) has two parts, and both must be right:
- The DNS record at
_mta-sts.<domain>:v=STSv1; id=…, exactly once. - The policy file at
https://mta-sts.<domain>/.well-known/mta-sts.txt: served with a valid certificate for that name, astext/plain, with an HTTP 200 answer and no redirects.
We read the policy's mode, max_age and mx lines, and compare every MX server of the domain with the mx patterns. A pattern such as *.mail.example.com matches exactly one extra label.
Rolling out safely
- Publish the policy with
mode: testingand a TLS-RPT record, so you receive reports. - When reports show no problems, change to
mode: enforceand update theidin the DNS record. - Raise
max_ageto a week or more.
Frequently asked questions
What is MTA-STS?
Mail Transfer Agent Strict Transport Security (RFC 8461). A domain publishes a policy saying its mail servers support encrypted connections with valid certificates, so sending servers refuse to deliver over an insecure or intercepted connection.
What do enforce, testing and none mean?
"enforce": senders that support MTA-STS won't deliver unless the connection is secure and the server is listed. "testing": they still deliver, but report problems (with TLS-RPT). "none": the policy is being withdrawn.
Why must the policy not redirect?
RFC 8461 says senders must not follow redirects when fetching the policy, so a redirect means senders can't read it. Serve the file directly from https://mta-sts.<your domain>/.well-known/mta-sts.txt.
What does the MX check mean?
Every mail server in your MX records must match an "mx" line in the policy. In enforce mode, senders refuse to deliver to a server that doesn't match, so mail could be lost.
What should max_age be?
How long senders may keep the policy, in seconds. Once everything works, a week or more (604800) is common; the maximum is about a year. Under a day gives little protection.
Related tools
-
TLS-RPT Checker
Check where other mail servers send reports when they can't make a secure connection to a domain's mail servers.
-
MX Lookup
See which mail servers receive email for a domain, in priority order, with each server's addresses.
-
SSL Certificate Checker
Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.
-
DMARC Checker
Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.
-
SPF Checker
Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.
-
Website Health Check
Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.