Free Tool
MTA-STS Checker
Verify your domain's MTA-STS configuration. Check DNS records and policy files to ensure encrypted email delivery.
Free instant check — no signup required
What is MTA-STS?
Mail Transfer Agent Strict Transport Security (MTA-STS) is a security mechanism defined in RFC 8461 that allows email domain owners to declare that their mail servers support TLS encryption and to specify a policy for how sending servers should handle messages when a secure connection cannot be established.
Without MTA-STS, SMTP email delivery is vulnerable to downgrade attacks where an attacker can strip the STARTTLS command from the connection, forcing email to be sent in plaintext. MTA-STS solves this by providing an out-of-band mechanism (via HTTPS) for receiving domains to advertise their TLS capability and enforce encryption requirements.
MTA-STS works alongside TLS-RPT (TLS Reporting), which provides visibility into TLS connection failures. Together, they help domain owners ensure that email to their domain is always encrypted in transit and quickly identify any delivery issues caused by TLS configuration problems.
Frequently Asked Questions
What is MTA-STS?
How does MTA-STS protect email?
How do I implement MTA-STS?
What's the difference between MTA-STS and STARTTLS?
Does MTA-STS affect email delivery?
Need continuous MTA-STS monitoring?
Get automatic alerts when your MTA-STS configuration changes or breaks. Monitor MTA-STS, SPF, DKIM, DMARC, and 60 blacklists.
Start Monitoring Free