MTA-STS Checker

Check MTA-STS and TLS-RPT for a domain: DNS record, policy file, mode and MX coverage.

What is MTA-STS?

MTA-STS (RFC 8461) lets a domain tell sending mail servers to always use encrypted, certificate-validated TLS when delivering mail to it, preventing downgrade attacks. It needs a TXT record at _mta-sts.domain and a policy file at https://mta-sts.domain/.well-known/mta-sts.txt; the checker validates both.

Example policy

version: STSv1
mode: enforce
mx: mail.example.com
max_age: 604800

Start with mode: testing, add TLS-RPT to receive reports, then switch to enforce.

Frequently asked questions

What is TLS-RPT?

A TXT record at _smtp._tls.domain where senders report TLS failures.

Why must I change the id?

Senders cache the policy; a new id tells them to fetch the updated file.

Is it free?

Yes.