F FreeMailCheck
EMAIL INFRASTRUCTURE GUIDE

MTA-STS Setup Guide for Email Domains

MTA-STS is an email transport-security policy mechanism. A domain publishes a DNS TXT record and serves a policy document over HTTPS so supporting senders can learn how TLS delivery should be handled.

The MTA-STS DNS record

The policy discovery record is published under the _mta-sts hostname and includes the STSv1 version plus a policy identifier.

Changing the policy identifier signals that supporting senders should fetch a newer version of the HTTPS policy.

The HTTPS policy file

The policy file is served from the mta-sts hostname at the standardized well-known path. It contains the version, policy mode, accepted MX patterns and max_age.

The HTTPS delivery of this policy is an essential part of MTA-STS deployment.

Testing versus enforcing

Testing mode allows a domain to deploy and observe its policy before requesting enforcement behavior. Enforce mode represents the stronger policy state.

Administrators should ensure the listed MX hosts and certificate configuration are correct before depending on enforcement.

MTA-STS and TLS-RPT

TLS-RPT provides reporting about TLS delivery problems and can complement MTA-STS.

These technologies address transport security and are separate from message-authentication technologies such as SPF, DKIM and DMARC.

Free email diagnostics

FreeMailCheck provides free tools for SPF, DKIM, DMARC, DNS, SMTP, TLS, reverse DNS, email headers and sender compliance.

Browse all 61 tools →