MTA-STS check
← All help articles · Health-check results
MTA-STS (RFC 8461) lets a domain require that other mail servers only deliver to it over TLS with a valid certificate, closing a gap opportunistic STARTTLS leaves open (a downgrade attacker can just strip STARTTLS since it's unauthenticated by default). This check looks for the _mta-sts.yourdomain.com DNS TXT record and, if present, fetches the policy file over HTTPS to validate it.
Its companion, TLS-RPT, is what tells you whether that enforcement is actually being respected in practice.
References
- RFC 8461