MTA-STS checker
MTA-STS (Mail Transfer Agent Strict Transport Security) is a standard that lets a domain publish, over DNS and HTTPS, which servers are allowed to receive its mail and require that connections use verified TLS. This tool checks the DNS record, fetches the policy file, and confirms it actually covers your live mail servers.
What this tool checks
First the DNS TXT record at _mta-sts. plus the domain, which only confirms a policy exists. Then the policy file itself at https://mta-sts.<domain>/.well-known/mta-sts.txt, read over HTTPS with certificate validation, the same way a real sending server would. Finally the policy's mx: list is checked against your domain's actual live MX records.
The three modes
none: the policy is published but disabled. Equivalent to not having one.testing: failures are reported over TLS-RPT, mail is still delivered on failure.enforce: a sender that cannot verify TLS to an allowed host refuses to deliver rather than fall back.
MTA-STS and Spamjadoo
Spamjadoo checks the receiving domain's MTA-STS policy before relaying outbound mail and refuses to downgrade a connection the policy requires to be encrypted and verified, closing the gap that opportunistic STARTTLS alone leaves open to an active network attacker.
Questions people ask
- Why does MTA-STS need both DNS and an HTTPS file?
- The DNS record only announces that a policy exists and gives an id used to detect updates. The policy itself, the mode and the list of allowed MX hosts, lives in a file fetched over HTTPS from mta-sts.<domain>, so it cannot be forged by whoever controls DNS resolution alone.
- What does mode: testing actually do?
- Nothing to delivery. Senders that honour MTA-STS report failures (via TLS-RPT) without refusing the connection. It is the safe way to find every legitimate MX host and TLS gap before mode: enforce can reject mail on a mistake.
- My MX host is not covered by the policy, what do I fix?
- Either the mx: lines in the policy file are missing your current MX hostnames (often after a provider migration), or wildcards were used incorrectly. Update the policy file to list every host your MX records point to, then bump the id in the DNS record.