Email Authentication

MTA-STS check

MTA-STS tells other mail servers they must use encryption when delivering to you, closing off downgrade and interception attacks.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We look for the _mta-sts TXT record and the policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt, and read its mode.

Why it matters to your business

Email between servers is only encrypted if both sides agree to it, and an attacker in the middle can quietly strip that agreement. MTA-STS makes encryption mandatory for mail sent to you, which matters most for businesses that receive contracts, health or financial information by email.

How to fix it

  1. Publish a policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt listing your MX hosts, starting with mode: testing.
  2. Add a TXT record at _mta-sts.yourdomain: v=STSv1; id=20260101.
  3. Add TLS-RPT so you hear about failures, then move the policy to mode: enforce.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Read the help article