MTA-STS Record Checker
Ensure emails are encrypted in transit – validate your MTA-STS policy instantly and fix configuration issues in seconds.
Ensure emails are encrypted in transit – validate your MTA-STS policy instantly and fix configuration issues in seconds.
Type in your domain name
Sit back and let our tool query your DNS to fetch your MTA-STS policy file.
Read the summary, dig into detailed findings, and review suggested fixes.
Apply recommended changes, then rerun the check until status = Valid.
MTA-STS (Mail Transfer Agent Strict Transport Security) is an email security protocol that ensures emails are transmitted securely over encrypted (TLS) connections between mail servers. It helps prevent attackers from intercepting or tampering with messages during transit.
We help you host and manage your TLS certificates and MTA-STS policy web server, so you save time and effort!
You get real-time alerts if validation fails!
One dashboard for DMARC, TLS-RPT, and MTA-STS health checks.
Do I need MTA-STS to improve deliverability?
While MTA-STS mainly focuses on email security, it can also positively impact deliverability by ensuring that your domain is trusted and capable of secure communication. Mail servers that prefer secure connections are more likely to deliver messages reliably when MTA-STS is in place.
Where should my policy file be hosted?
Your MTA-STS policy file should be hosted at this URL: https://mta-sts.yourdomain.com/.well-known/mta-sts.txt
It must be accessible via HTTPS with a valid SSL/TLS certificate.
How long until changes take effect?
Once you update your MTA-STS policy, changes typically take effect after the max-age period defined in your policy file expires.
What does “policy mode: enforce / testing” mean?
Testing: This means that the MTA-STS policy is active but not strictly enforced. In this scenario, mail servers will report issues without rejecting emails.
Enforce: This means that the MTA-STS policy is fully active and requires all incoming mail to use a secure TLS connection to land in your inbox. Unencrypted emails will be rejected.