MTA-STS (Mail Transfer Agent Strict Transport Security) lets a domain declare that inbound mail must be delivered over TLS with a valid certificate. TLS-RPT provides reports on delivery failures caused by TLS problems.
A correct example#
version: STSv1
mode: enforce
mx: aspmx.l.google.com
mx: *.googlemail.com
max_age: 604800Every element is there for a reason, and each maps to one of the setup steps below.
What good looks like#
- Done: Publish a _mta-sts TXT record with an id value you will change on each policy update.
- Done: Host a policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts.
- Done: Start in mode: testing, then move to mode: enforce after reviewing TLS-RPT reports.
- Done: Publish _smtp._tls TXT with rua=mailto: to receive TLS-RPT reports.
What bad looks like#
- Seen in audits: Listing MX hostnames that do not exactly match certificate names.
- Seen in audits: Forgetting to bump the id when the policy file changes, so caches never refresh.
How to move from bad to good#
Work through the good list in order and re-verify after each change. Most teams find one or two items from the bad list already present; fixing those usually produces the largest improvement.
Frequently asked questions#
Does MTA-STS affect outbound mail?
Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.
Is DANE better than MTA-STS?
DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.