Opportunistic TLS can be downgraded by an attacker in the network path. MTA-STS closes that hole and is increasingly a checkbox in security questionnaires.
Mistake 1: Listing MX hostnames that do not exactly match certificate names#
Why it hurts: this undermines MTA-STS at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Publish a _mta-sts TXT record with an id value you will change on each policy update.
Mistake 2: Forgetting to bump the id when the policy file changes, so caches never refresh#
Why it hurts: this undermines MTA-STS at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Host a policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing your MX hosts.
Frequently asked questions#
Does MTA-STS affect outbound mail?
Only when the recipient domain publishes a policy. Your own policy protects mail coming to you.
Is DANE better than MTA-STS?
DANE requires DNSSEC and is stronger, but MTA-STS is easier to adopt. Microsoft and Google both support MTA-STS.