What MTA-STS is and what this tool checks
SMTP between mail servers encrypts opportunistically: if the receiving server does not offer STARTTLS, or someone on the path strips the offer, the message goes out in clear text. MTA-STS (RFC 8461) lets a domain tell sending servers "my MX hosts support TLS with a valid certificate; if you cannot get that, do not deliver". It has two parts: a TXT record at _mta-sts.<domain> that announces a policy and its version id, and the policy itself, a small text file at https://mta-sts.<domain>/.well-known/mta-sts.txt.
OrbitProbe reads the TXT record, requests the policy file the way a sending server must (HTTPS, certificate checked, redirects not followed), parses version, mode, mx and max_age, and then looks up the MX records of the domain to see whether each MX host matches one of the mx patterns in the policy.
Reading the result
mode: enforce means senders that support MTA-STS refuse to deliver to an MX host that fails TLS or is not listed in the policy. mode: testing delivers anyway and only reports the failure, which is the right first step. mode: none withdraws the policy. max_age is how long, in seconds, a sender may cache the policy; a week or more is common once the policy is stable, and the maximum is 31557600 (about one year).
The most common real fault is a policy that no longer matches the MX records: mail was moved to a new provider, the MX records were changed, and the policy file still lists the old hosts. In enforce mode that blocks delivery from every sender that honours MTA-STS. This is why the tool names each MX host that no pattern covers.
The id in the TXT record is only a version marker. Senders re-fetch the policy file when the id changes, so change it every time you edit the file.
What the check cannot tell you
It does not connect to your MX hosts, so it does not test whether they really offer STARTTLS with a certificate that matches. It does not know which senders support MTA-STS. And a query that fails is shown as "could not be checked", not as "no MTA-STS": a timeout is not evidence of absence. Pair MTA-STS with TLS-RPT so that senders tell you about failures before you switch to enforce.