Email Authentication
Mail server encryption (STARTTLS) check
Whether your mail servers offer encryption to the servers delivering email to you, or take every message in plain text.
Check this on your own domain now. It is free with a DomainGuard account and works on any domain. The check reads only what your domain publishes, and gives you a report you can send to whoever runs your website.
What we look at
From our own server we connect to each of your MX hosts on port 25, the way a sending mail server does, say hello and ask for STARTTLS. We stop there: we never offer a message. Microsoft 365, Google Workspace and the other big mailbox providers are skipped, because they always offer it.
Why it matters to your business
Without STARTTLS, every email sent to you crosses the internet readable by anyone on the path: contracts, invoices, password resets. Most senders encrypt when they can, so a server that never offers it is the only thing standing in the way.
How to fix it
- Turn on TLS for incoming mail on the server (Postfix: smtpd_tls_security_level = may with a certificate and key; Exchange and most hosted panels have a switch).
- Install a certificate from a public CA that covers the MX host name.
- Run the checkup again to confirm STARTTLS is offered.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
