Skip to content

Home Topics Email Authentication MTA-STS and TLS-RPT

Email Authentication · MTA-STS and TLS-RPT

2 common MTA-STS mistakes and how to fix them

Short answer

The most common MTA-STS mistakes are: listing MX hostnames that do not exactly match certificate names; forgetting to bump the id when the policy file changes, so caches never refresh.

Opportunistic TLS can be downgraded by an attacker in the network path. MTA-STS closes that hole and is increasingly a checkbox in security questionnaires.

Mistake 1: Listing MX hostnames that do not exactly match certificate names#

Why it hurts: this undermines MTA-STS at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Publish a _mta-sts TXT record with an id value you will change on each policy update.

Mistake 2: Forgetting to bump the id when the policy file changes, so caches never refresh#

Why it hurts: this undermines MTA-STS at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Host a policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts.

Frequently asked questions#

Does MTA-STS affect outbound mail?

Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.

Is DANE better than MTA-STS?

DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on MTA-STS and TLS-RPT