Skip to content

Home Topics Email Authentication MTA-STS and TLS-RPT

Email Authentication · MTA-STS and TLS-RPT

Advanced MTA-STS: edge cases, scale, and monitoring

Short answer

At scale, MTA-STS problems come from change: new vendors, DNS edits, volume spikes, and forwarding. The fix is treating it as monitored infrastructure with owners, alerts, and a change process, not a one-time setup.

This guide assumes MTA-STS is already deployed and passing. It covers what breaks at scale and how mature teams operate it.

Edge cases that break a working setup#

  • Listing MX hostnames that do not exactly match certificate names.
  • Forgetting to bump the id when the policy file changes, so caches never refresh.
  • Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
  • Acquisitions and rebrands that introduce domains nobody audited.
  • Vendors silently changing their sending infrastructure.

Operating it as infrastructure#

  1. Assign an owner for each sending domain and each vendor relationship.
  2. Put DNS records under version control or a change-review process.
  3. Alert on authentication pass rate drops and reputation changes, not just outages.
  4. Run a quarterly audit against the setup steps below.
  5. Document runbooks for the three most common failures.

Reference: the baseline setup#

  1. Publish a _mta-sts TXT record with an id value you will change on each policy update.
  2. Host a policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts.
  3. Start in mode: testing, then move to mode: enforce after reviewing TLS-RPT reports.
  4. Publish _smtp._tls TXT with rua=mailto: to receive TLS-RPT reports.
Example MTA-STS policy
version: STSv1
mode: enforce
mx: aspmx.l.google.com
mx: *.googlemail.com
max_age: 604800

Frequently asked questions#

Does MTA-STS affect outbound mail?

Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.

Is DANE better than MTA-STS?

DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on MTA-STS and TLS-RPT