Skip to content

What is MTA-STS? (SMTP MTA Strict Transport Security)

MTA-STS (SMTP MTA Strict Transport Security, RFC 8461) lets a domain that receives email publish a policy telling sending servers to deliver to it only over TLS with a valid certificate and only to the listed MX hosts, which stops attackers downgrading or redirecting mail in transit.

The problem it solves

SMTP between mail servers upgrades to TLS with STARTTLS, but the upgrade is opportunistic: if the offer is stripped from the conversation, or the certificate is invalid, most senders fall back to plaintext and deliver anyway. An attacker on the network path can use that to read or redirect mail. MTA-STS (RFC 8461) lets the receiving domain publish a policy that says “only deliver to these MX hosts, and only over valid TLS”.

The two parts

A TXT record at _mta-sts.yourdomain.com announces that a policy exists and carries an id that you change whenever the policy changes:

_mta-sts.yourdomain.com. TXT "v=STSv1; id=20260929T000000"

The policy itself is a small text file served over HTTPS at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt:

version: STSv1
mode: enforce
mx: mx1.yourdomain.com
mx: *.yourdomain.com
max_age: 604800

mode is none, testing or enforce. In testing, senders deliver as before but report failures; in enforce, they refuse to deliver to an MX that does not match the list or cannot present a valid certificate. max_age is how long, in seconds, senders cache the policy.

Pair it with TLS-RPT

TLS reporting (RFC 8460) is a TXT record at _smtp._tls.yourdomain.com such as v=TLSRPTv1; rua=mailto:tls-reports@yourdomain.com. Senders that support it send you a daily JSON summary of successful and failed TLS sessions. Run in testing mode with TLS-RPT for a couple of weeks, read the reports, and only then switch to enforce.

What MTA-STS does not do

MTA-STS protects mail coming in to your domain. It does nothing for authentication of the mail you send — that is the job of SPF, DKIM and DMARC. It is worth setting up on any domain that receives mail, but it is not a sending requirement.

Frequently asked questions

What records does MTA-STS need?

A TXT record at _mta-sts.yourdomain.com such as "v=STSv1; id=20260929T000000", and a policy file served over HTTPS at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt listing the mode, the allowed MX hosts and max_age. Change the id whenever the policy file changes.

What is the difference between testing and enforce mode?

In testing mode, senders still deliver when TLS or MX validation fails, but report the failure if you publish TLS-RPT. In enforce mode, they refuse to deliver instead. Start in testing, read the TLS-RPT reports, and switch to enforce once they are clean.

Does MTA-STS help my outbound email get delivered?

No. MTA-STS protects mail sent to your domain. The deliverability of the mail you send depends on SPF, DKIM, DMARC and your sending reputation.

Related terms

EU-hosted email with auth done for you

PostStack publishes SPF, DKIM, and DMARC automatically and runs entirely on EU infrastructure. 3,000 emails/month free.