Email Authentication

MX hosts in the MTA-STS policy check

Whether every mail server in your MX records is listed in your MTA-STS policy, so senders will deliver to it.

Check this on your own domain now. It is free with a DomainGuard account and works on any domain. The check reads only what your domain publishes, and gives you a report you can send to whoever runs your website.

What we look at

We compare each MX host with the mx: lines of your MTA-STS policy file. A line starting with *. covers exactly one more label (mail.example.com, not a.mail.example.com).

Why it matters to your business

In enforce mode, a sending server refuses to deliver to any MX the policy does not list. A backup MX added later, or a move to a new mail provider, can stop mail without anyone noticing.

How to fix it

  1. Add an mx: line for the missing host to https://mta-sts.yourdomain/.well-known/mta-sts.txt, or remove the MX record if it is no longer used.
  2. Change the id= value in the _mta-sts TXT record so senders fetch the new policy.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Read the help article