MTA-STS checker

Look up the _mta-sts TXT record, fetch the policy file over HTTPS, compare its mx patterns with the MX hosts the domain really publishes and check max_age against the 31,557,600-second limit.

What MTA-STS is and what this tool checks

SMTP between mail servers encrypts opportunistically: if the receiving server does not offer STARTTLS, or someone on the path strips the offer, the message goes out in clear text. MTA-STS (RFC 8461) lets a domain tell sending servers "my MX hosts support TLS with a valid certificate; if you cannot get that, do not deliver". It has two parts: a TXT record at _mta-sts.<domain> that announces a policy and its version id, and the policy itself, a small text file at https://mta-sts.<domain>/.well-known/mta-sts.txt.

OrbitProbe reads the TXT record, requests the policy file the way a sending server must (HTTPS, certificate checked, redirects not followed), parses version, mode, mx and max_age, and then looks up the MX records of the domain to see whether each MX host matches one of the mx patterns in the policy.

Reading the result

mode: enforce means senders that support MTA-STS refuse to deliver to an MX host that fails TLS or is not listed in the policy. mode: testing delivers anyway and only reports the failure, which is the right first step. mode: none withdraws the policy. max_age is how long, in seconds, a sender may cache the policy; a week or more is common once the policy is stable, and the maximum is 31557600 (about one year).

The most common real fault is a policy that no longer matches the MX records: mail was moved to a new provider, the MX records were changed, and the policy file still lists the old hosts. In enforce mode that blocks delivery from every sender that honours MTA-STS. This is why the tool names each MX host that no pattern covers.

The id in the TXT record is only a version marker. Senders re-fetch the policy file when the id changes, so change it every time you edit the file.

What the check cannot tell you

It does not connect to your MX hosts, so it does not test whether they really offer STARTTLS with a certificate that matches. It does not know which senders support MTA-STS. And a query that fails is shown as "could not be checked", not as "no MTA-STS": a timeout is not evidence of absence. Pair MTA-STS with TLS-RPT so that senders tell you about failures before you switch to enforce.

How to use this tool

  1. Enter the domain. Type or paste a domain name such as example.com. A full URL works too: the scheme, path and a leading www are removed.
  2. Run the check. The tool reads the TXT record at _mta-sts.<domain>, fetches the policy file from mta-sts.<domain> over HTTPS and looks up the MX records.
  3. Compare policy and MX hosts. Check the mode and max_age, and make sure every MX host is covered by an mx pattern of the policy.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • TXT recorddig _mta-sts.example.com TXT +short
  • Policy filecurl -s https://mta-sts.example.com/.well-known/mta-sts.txt
  • MX hosts to compare withdig example.com MX +short
  • Windowsnslookup -type=TXT _mta-sts.example.com

FAQ

How do I check whether a domain has MTA-STS?

Enter the domain above. The tool looks up the TXT record at _mta-sts.<domain>, fetches https://mta-sts.<domain>/.well-known/mta-sts.txt and shows both, with every problem it finds.

What does an MTA-STS TXT record look like?

v=STSv1; id=20260101T000000. The v tag must come first, and id is up to 32 letters and digits. Change the id whenever you change the policy file.

Should I use testing or enforce?

Start with testing together with a TLS-RPT record, read the reports for a few weeks, and move to enforce once they show no failures for your legitimate MX hosts.

Why does the tool say an MX host is not covered?

The host name in your MX record does not match any mx line of the policy. A wildcard such as *.example.com matches exactly one label, so it covers mx1.example.com but not a.b.example.com or example.com itself.

Does the policy file need a special web server?

It needs HTTPS on the host mta-sts.<domain> with a certificate valid for that name, a 200 answer without redirects, and the content type text/plain. Any static host can do that.