What is MTA-STS?
MTA-STS (Mail Transfer Agent Strict Transport Security, RFC 8461) is a standard that lets a domain publish a policy stating which mail servers are authorised to receive its mail and whether connections to them must use verified TLS. A DNS TXT record at _mta-sts.domain announces that a policy exists; the policy itself is a text file fetched over HTTPS from mta-sts.domain/.well-known/mta-sts.txt, which cannot be forged by controlling DNS alone.
The two parts
A sender checking MTA-STS does two lookups: the DNS TXT record, which only signals that a policy exists and carries an id used to detect updates, and the policy file itself, fetched over HTTPS with normal certificate validation. Both must succeed and agree for the policy to apply.
mode: enforce
mx: mail.example.com
mx: *.backup.example.net
max_age: 604800
Policy modes
none disables an existing policy without deleting it. testing reports failures over TLS-RPT without refusing mail, the safe way to validate a policy before it can reject anything. enforce refuses delivery to a connection that cannot verify TLS to an allowed host, closing the gap that opportunistic STARTTLS leaves open to an active attacker who strips TLS or reroutes the connection.
Why plain STARTTLS is not enough
SMTP negotiates TLS opportunistically: if a connection cannot negotiate it, or an attacker on the network forges the response that would offer it, the message is sent in plaintext anyway, silently. MTA-STS in enforce mode makes that downgrade visible and refusable instead of invisible and successful.
MTA-STS and Spamjadoo
Spamjadoo checks the receiving domain’s MTA-STS policy before relaying outbound mail and will not deliver over a connection the policy requires to be encrypted and verified. Pair it with TLS-RPT to find out when a receiver’s policy actually caught something.
Last reviewed 12 September 2026 by Spamjadoo engineering.