MTA-STS check

STARTTLS is opportunistic - an attacker on the network can strip it and force plaintext. MTA-STS is how a domain tells senders "always use TLS to reach me, and refuse if you can't."

What this check looks at

MTA-STS (SMTP MTA Strict Transport Security) lets a domain publish a policy that requires TLS for inbound mail. This check looks for the policy discovery record at _mta-sts.yourdomain.com and reports whether it's published.

Why it matters

Plain STARTTLS can be stripped by a man-in-the-middle, silently downgrading mail to plaintext. An MTA-STS policy closes that hole: compliant senders will only deliver to your MX over a valid TLS connection, and refuse rather than fall back to the clear. It's optional, but valuable for any domain handling sensitive mail.

How the diagnostic grades it

ResultSeverityWhat it means
MTA-STS publishedPassThe domain protects inbound mail against TLS downgrade.
No MTA-STS policyInfoOptional, but recommended. No penalty for not having it.

How to fix it

Publishing MTA-STS takes two parts:

  • A DNS record at _mta-sts.yourdomain.com (v=STSv1; id=...).
  • A policy file served over HTTPS at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts and a mode (start with testing, then move to enforce).

Pair it with TLS-RPT so you get reports if a sender ever fails to reach you over TLS, and make sure your MX offers STARTTLS with a valid certificate first.

Related checks

TLS-RPT · Inbound MX STARTTLS · TLS in transit

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free