What this check looks at
MTA-STS (SMTP MTA Strict Transport Security) lets a domain publish a policy that requires TLS for inbound mail. This check looks for the policy discovery record at _mta-sts.yourdomain.com and reports whether it's published.
Why it matters
Plain STARTTLS can be stripped by a man-in-the-middle, silently downgrading mail to plaintext. An MTA-STS policy closes that hole: compliant senders will only deliver to your MX over a valid TLS connection, and refuse rather than fall back to the clear. It's optional, but valuable for any domain handling sensitive mail.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| MTA-STS published | Pass | The domain protects inbound mail against TLS downgrade. |
| No MTA-STS policy | Info | Optional, but recommended. No penalty for not having it. |
How to fix it
Publishing MTA-STS takes two parts:
- A DNS record at
_mta-sts.yourdomain.com(v=STSv1; id=...). - A policy file served over HTTPS at
https://mta-sts.yourdomain.com/.well-known/mta-sts.txtlisting your MX hosts and a mode (start withtesting, then move toenforce).
Pair it with TLS-RPT so you get reports if a sender ever fails to reach you over TLS, and make sure your MX offers STARTTLS with a valid certificate first.