Guide · MTA-STS

Set up and monitor MTA-STS

Email between mail servers is usually encrypted – but only if both sides play along. An attacker can suppress encryption without anyone noticing. MTA-STS (SMTP MTA Strict Transport Security) prevents this: you specify that email to your domain is delivered only encrypted and only to your genuine mail servers.

How does MTA-STS work?

MTA-STS has two parts: a TXT record at _mta-sts.your-company.com with a version ID, and a policy file at https://mta-sts.your-company.com/.well-known/mta-sts.txt. The policy names your mail servers and the mode. Sending servers fetch it over HTTPS, cache it for the specified time and from then on deliver only encrypted to the listed servers.

Good to know: Your mail server’s certificate must be valid and match the name in the MX record – otherwise email will no longer be delivered in enforce mode.

Set up MTA-STS in three steps

1. Publish the policy

Create the subdomain mta-sts.your-company.com with a valid HTTPS certificate and publish the policy with mode: testing first.

2. Set the TXT records

Add _mta-sts.your-company.com with v=STSv1; id=20260101 and also set up TLS reporting so you can see errors.

3. Switch to enforce

Once the TLS reports have been error-free for a few weeks, switch to mode: enforce, increase max_age and change the id in the TXT record.

Common MTA-STS mistakes

A faulty policy in enforce mode can block deliveries. That is why Mailsecurity24 checks record, policy and mail servers regularly and warns in good time:

Good to know: Senders cache a policy for the duration of max_age. Change the id in the TXT record after every update so they fetch the new version.

Free domain check

Is your domain protected against email spoofing?

In seconds we check DMARC, SPF, DKIM, MX, MTA-STS, TLS reporting and BIMI for your domain – free and without signing up.

  • No sign-up
  • Result in seconds
  • We do not store your domain

Frequently asked questions about MTA-STS

Both enforce encrypted delivery. DANE requires DNSSEC and stores certificate information in DNS. MTA-STS works without DNSSEC via a policy fetched over HTTPS. Both can be used in parallel.

Yes. Without MTA-STS, encryption between mail servers is optional: if an attacker suppresses STARTTLS, email is delivered unencrypted. MTA-STS makes encryption mandatory.

Always testing. Senders then report problems via TLS reports without deliveries failing. Only switch to enforce once the reports are error-free.

In testing mode nothing – senders only report the error. In enforce mode, email to your domain may be held back or rejected. That is why Mailsecurity24 warns you before it gets that far.

Ready for secure email?

Try Mailsecurity24 free for 14 days. No payment details required.