Opens the print dialog of your browser. Choose "Save as PDF" as the printer there to get a file: the browser writes it, nothing is uploaded.
Share a snapshot of this report
A live report changes with every lookup, so a shared link to it would not show what you see now. A snapshot stores this report as our server observed it and gives it its own link for 30 days. It holds public lookup data only. Anyone with the link can open it; search engines are asked not to index it.
Findings
Note: No TXT record at _mta-sts.<domain>. Without it, senders do not look for a policy: MTA-STS is not in use.
Note: The policy file could not be fetched [NO_ADDRESS]. Senders that cannot fetch it keep using a cached policy, or deliver without one.
TXT record
Host name
_mta-sts.bbc.co.uk
No MTA-STS TXT record was found.
Policy file
URL
https://mta-sts.bbc.co.uk/.well-known/mta-sts.txt
No policy file could be read.
This check does not connect to the MX hosts, so it does not test whether they offer STARTTLS with a matching certificate.
LiveSource: Public DNS (1.1.1.1, 8.8.8.8) + one guarded HTTPS request to the policy hostObserved:
What MTA-STS is and what this tool checks
SMTP between mail servers encrypts opportunistically: if the receiving server does not offer STARTTLS, or someone on the path strips the offer, the message goes out in clear text. MTA-STS (RFC 8461) lets a domain tell sending servers "my MX hosts support TLS with a valid certificate; if you cannot get that, do not deliver". It has two parts: a TXT record at _mta-sts.<domain> that announces a policy and its version id, and the policy itself, a small text file at https://mta-sts.<domain>/.well-known/mta-sts.txt.
OrbitProbe reads the TXT record, requests the policy file the way a sending server must (HTTPS, certificate checked, redirects not followed), parses version, mode, mx and max_age, and then looks up the MX records of the domain to see whether each MX host matches one of the mx patterns in the policy.