Setup checklist#
- ☐ Publish a _mta-sts TXT record with an id value you will change on each policy update.
- ☐ Host a policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts.
- ☐ Start in mode: testing, then move to mode: enforce after reviewing TLS-RPT reports.
- ☐ Publish _smtp._tls TXT with rua=mailto: to receive TLS-RPT reports.
Audit checklist#
- ☐ Confirm you are not: listing MX hostnames that do not exactly match certificate names.
- ☐ Confirm you are not: forgetting to bump the id when the policy file changes, so caches never refresh.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
Does MTA-STS affect outbound mail?
Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.
Is DANE better than MTA-STS?
DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.