Guide · MTA-STS
Email between mail servers is usually encrypted – but only if both sides play along. An attacker can suppress encryption without anyone noticing. MTA-STS (SMTP MTA Strict Transport Security) prevents this: you specify that email to your domain is delivered only encrypted and only to your genuine mail servers.
MTA-STS has two parts: a TXT record at _mta-sts.your-company.com with a version ID, and a policy file at https://mta-sts.your-company.com/.well-known/mta-sts.txt. The policy names your mail servers and the mode. Sending servers fetch it over HTTPS, cache it for the specified time and from then on deliver only encrypted to the listed servers.
Good to know: Your mail server’s certificate must be valid and match the name in the MX record – otherwise email will no longer be delivered in enforce mode.
Create the subdomain mta-sts.your-company.com with a valid HTTPS certificate and publish the policy with mode: testing first.
Add _mta-sts.your-company.com with v=STSv1; id=20260101 and also set up TLS reporting so you can see errors.
Once the TLS reports have been error-free for a few weeks, switch to mode: enforce, increase max_age and change the id in the TXT record.
A faulty policy in enforce mode can block deliveries. That is why Mailsecurity24 checks record, policy and mail servers regularly and warns in good time:
Good to know: Senders cache a policy for the duration of max_age. Change the id in the TXT record after every update so they fetch the new version.
Free domain check
In seconds we check DMARC, SPF, DKIM, MX, MTA-STS, TLS reporting and BIMI for your domain – free and without signing up.
Both enforce encrypted delivery. DANE requires DNSSEC and stores certificate information in DNS. MTA-STS works without DNSSEC via a policy fetched over HTTPS. Both can be used in parallel.
Yes. Without MTA-STS, encryption between mail servers is optional: if an attacker suppresses STARTTLS, email is delivered unencrypted. MTA-STS makes encryption mandatory.
Always testing. Senders then report problems via TLS reports without deliveries failing. Only switch to enforce once the reports are error-free.
In testing mode nothing – senders only report the error. In enforce mode, email to your domain may be held back or rejected. That is why Mailsecurity24 warns you before it gets that far.
Try Mailsecurity24 free for 14 days. No payment details required.
