What this check does
JoltMx opens a real SMTP connection to the sender domain's primary MX on port 25 and walks through the start of a delivery, observing:
- The server's greeting (a healthy
220). - Whether it advertises STARTTLS in its EHLO response.
- Whether the TLS handshake succeeds, and on which protocol.
- The certificate - validity, expiry, and whether it matches the MX hostname.
It's entirely best-effort. Outbound port 25 is often filtered between networks, so an unreachable MX is reported as Info, not a failure. The probe is also SSRF-guarded: it resolves the MX to a concrete public address, refuses anything that isn't globally routable (loopback, private, link-local, etc.), and connects to that vetted IP - never re-resolving a name an attacker could rebind.
Why it matters
This tests the receiving side of your domain. If your MX doesn't offer STARTTLS, mail sent to you travels in the clear, and senders enforcing MTA-STS or DANE will refuse to deliver at all. An expired or mismatched certificate causes the same strict-TLS senders to bounce - even though opportunistic TLS would still "work."
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| Inbound MX TLS | Pass | STARTTLS works with a valid certificate. |
| Does not offer STARTTLS | Warning | Mail to you is unencrypted; strict-TLS senders refuse delivery. |
| STARTTLS advertised but refused | Warning | The server lists STARTTLS but fails to start it. |
| Certificate has expired | Warning | Strict-TLS senders refuse an expired certificate. Renew it. |
| Certificate has issues | Warning | Validation failed (wrong name or untrusted chain). Fix the certificate. |
| MX rejected the connection | Warning | The MX answered with something other than a 220 greeting. |
| Could not be probed | Info | Port 25 was filtered, or the MX resolves to a non-public address - not necessarily a problem. |
How to fix it
- Enable STARTTLS on your inbound MX.
- Use a certificate that matches the MX hostname and chains to a trusted CA, and keep it renewed.
- Pair it with MTA-STS so senders enforce TLS to you.