Email Authentication

Mail server certificate check

Whether the certificate your mail server shows during STARTTLS is current, issued for its own name and trusted.

Check this on your own domain now. It is free with a DomainGuard account and works on any domain. The check reads only what your domain publishes, and gives you a report you can send to whoever runs your website.

What we look at

During the STARTTLS session we read the certificate each MX host presents and check its dates, whether a public CA issued it, and whether it names the MX host. With MTA-STS in enforce mode a problem here is graded higher, because senders then refuse to deliver.

Why it matters to your business

Most senders deliver over a bad certificate anyway, so this fails quietly. The ones that check, which includes any sender following your MTA-STS policy in enforce mode, will hold or bounce your mail instead.

How to fix it

  1. Install a certificate from a public CA (Let's Encrypt works) that lists the MX host name, and set it to renew automatically.
  2. Include the intermediate certificate in the chain the server sends.
  3. If you use MTA-STS in enforce mode, fix this first: senders are refusing mail until you do.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.