MTA-STS (Mail Transfer Agent Strict Transport Security) lets a domain declare that inbound mail must be delivered over TLS with a valid certificate. TLS-RPT provides reports on delivery failures caused by TLS problems.
Does MTA-STS affect outbound mail?
Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.
Is DANE better than MTA-STS?
DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.
Why does MTA-STS matter for deliverability?
Opportunistic TLS can be downgraded by an attacker in the network path. MTA-STS closes that hole and is increasingly a checkbox in security questionnaires.
What is the first step to get started with MTA-STS?
Publish a _mta-sts TXT record with an id value you will change on each policy update.
What is the most common MTA-STS mistake?
Listing MX hostnames that do not exactly match certificate names.