Inbound MX STARTTLS probe

Most checks read what your message brought with it. This one actively connects to your domain's primary MX and tests whether mail sent to you can be encrypted.

What this check does

JoltMx opens a real SMTP connection to the sender domain's primary MX on port 25 and walks through the start of a delivery, observing:

  • The server's greeting (a healthy 220).
  • Whether it advertises STARTTLS in its EHLO response.
  • Whether the TLS handshake succeeds, and on which protocol.
  • The certificate - validity, expiry, and whether it matches the MX hostname.

It's entirely best-effort. Outbound port 25 is often filtered between networks, so an unreachable MX is reported as Info, not a failure. The probe is also SSRF-guarded: it resolves the MX to a concrete public address, refuses anything that isn't globally routable (loopback, private, link-local, etc.), and connects to that vetted IP - never re-resolving a name an attacker could rebind.

Why it matters

This tests the receiving side of your domain. If your MX doesn't offer STARTTLS, mail sent to you travels in the clear, and senders enforcing MTA-STS or DANE will refuse to deliver at all. An expired or mismatched certificate causes the same strict-TLS senders to bounce - even though opportunistic TLS would still "work."

How the diagnostic grades it

ResultSeverityWhat it means
Inbound MX TLSPassSTARTTLS works with a valid certificate.
Does not offer STARTTLSWarningMail to you is unencrypted; strict-TLS senders refuse delivery.
STARTTLS advertised but refusedWarningThe server lists STARTTLS but fails to start it.
Certificate has expiredWarningStrict-TLS senders refuse an expired certificate. Renew it.
Certificate has issuesWarningValidation failed (wrong name or untrusted chain). Fix the certificate.
MX rejected the connectionWarningThe MX answered with something other than a 220 greeting.
Could not be probedInfoPort 25 was filtered, or the MX resolves to a non-public address - not necessarily a problem.

How to fix it

  • Enable STARTTLS on your inbound MX.
  • Use a certificate that matches the MX hostname and chains to a trusted CA, and keep it renewed.
  • Pair it with MTA-STS so senders enforce TLS to you.

Related checks

TLS in transit · MTA-STS · MX records

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free