EML

MTA-STS & TLS-RPT Checker

Check whether a domain forces other mail servers to use encrypted, verified connections, and catch policy mistakes before they bounce mail.

The tool tries to read https://mta-sts.example.com/.well-known/mta-sts.txt itself. Most servers block that for browsers, so if nothing appears, open the link and paste the text here.
Queries go straight from your browser to the resolver you pick.

How it works

MTA-STS has three parts. A TXT record at _mta-sts.yourdomain.com announces that a policy exists and carries an id. The policy itself is a short text file served over HTTPS from mta-sts.yourdomain.com. An optional TLS-RPT record at _smtp._tls.yourdomain.com says where to send failure reports.

This tool checks the record syntax, confirms the policy host resolves, validates the policy file and compares its mx: lines with your real MX records, which is the mistake that most often causes mail to bounce after switching to enforce mode.

Policy lineMeaning
version: STSv1Required. The only valid version.
modeenforce, testing or none.
mxA mail server allowed to receive your mail. One per line; *.example.com matches one label.
max_ageSeconds senders may cache the policy. At most 31557600; a week or more is recommended.

Your mail servers also need valid certificates. Check them with the SSL Certificate Checker, review your MX records with the MX Record Lookup, and see the rest of your email setup in the Email Health Check.

Frequently asked

What is MTA-STS?

MTA-STS (Mail Transfer Agent Strict Transport Security) lets a domain tell other mail servers to deliver its mail only over a verified TLS connection to its listed servers. Without it, a network attacker can strip encryption from server-to-server email and read or alter the message.

Is MTA-STS the same as DANE?

They solve the same problem differently. DANE publishes certificate details in DNS and requires DNSSEC. MTA-STS relies on a policy file on an HTTPS web server and does not need DNSSEC, which is why it is easier to adopt. Large receivers such as Gmail honour MTA-STS.

What is the difference between testing and enforce mode?

In testing mode, sending servers still deliver mail even when the TLS checks fail, but they report the failure through TLS-RPT. In enforce mode they refuse to deliver. Start with testing, read the reports for a few weeks, then switch to enforce.

Why does the tool not always read my policy file?

Browsers only let a web page read another site's file when that site allows it, and policy hosts rarely do. When the automatic read fails, open the link shown and paste the policy text into the box. Everything is still checked in your browser.

Do I need to update the id when I change the policy?

Yes. Senders cache your policy and only look for a new one when the id in the _mta-sts TXT record changes. Change the id (a timestamp works well) every time you edit the policy file.

What is TLS-RPT?

TLS-RPT (TLS Reporting) is a TXT record at _smtp._tls that tells senders where to email daily summaries of TLS failures when delivering to you. It is the feedback loop that makes MTA-STS safe to roll out.