Skip to content

Home Topics Email Authentication MTA-STS and TLS-RPT

Email Authentication · MTA-STS and TLS-RPT

MTA-STS for beginners: a plain-English guide

Short answer

MTA-STS (Mail Transfer Agent Strict Transport Security) lets a domain declare that inbound mail must be delivered over TLS with a valid certificate. TLS-RPT provides reports on delivery failures caused by TLS problems. If you are starting from zero: Publish a _mta-sts TXT record with an id value you will change on each policy update.

The one-sentence version#

MTA-STS (Mail Transfer Agent Strict Transport Security) lets a domain declare that inbound mail must be delivered over TLS with a valid certificate. TLS-RPT provides reports on delivery failures caused by TLS problems.

Why you should care#

Opportunistic TLS can be downgraded by an attacker in the network path. MTA-STS closes that hole and is increasingly a checkbox in security questionnaires.

The mental model#

Think of MTA-STS as a contract between you and the mailbox providers receiving your mail. You publish or configure something they can check; they check it on every message; the result feeds their decision about where your message lands. Everything below is about making that check pass consistently.

Your first setup, step by step#

  1. Publish a _mta-sts TXT record with an id value you will change on each policy update.
  2. Host a policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts.
  3. Start in mode: testing, then move to mode: enforce after reviewing TLS-RPT reports.
  4. Publish _smtp._tls TXT with rua=mailto: to receive TLS-RPT reports.
Example MTA-STS policy
version: STSv1
mode: enforce
mx: aspmx.l.google.com
mx: *.googlemail.com
max_age: 604800

Words you will see#

  • Mailbox provider: Gmail, Microsoft, Yahoo, Apple, and the corporate gateways that decide where mail lands.
  • Authentication: proof that a message is from who it says it is (SPF, DKIM, DMARC).
  • Reputation: the provider's running score of your domain and IP.
  • Placement: whether a message reaches the inbox, spam, or is rejected.

Common mistakes#

  • Listing MX hostnames that do not exactly match certificate names.
  • Forgetting to bump the id when the policy file changes, so caches never refresh.

Frequently asked questions#

Does MTA-STS affect outbound mail?

Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.

Is DANE better than MTA-STS?

DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on MTA-STS and TLS-RPT