DMARC Analyzer

MTA-STS check

← All help articles · Health-check results

MTA-STS (RFC 8461) lets a domain require that other mail servers only deliver to it over TLS with a valid certificate, closing a gap opportunistic STARTTLS leaves open (a downgrade attacker can just strip STARTTLS since it's unauthenticated by default). This check looks for the _mta-sts.yourdomain.com DNS TXT record and, if present, fetches the policy file over HTTPS to validate it.

Its companion, TLS-RPT, is what tells you whether that enforcement is actually being respected in practice.

References