What MTA-STS is and what this tool checks
SMTP between mail servers encrypts opportunistically: if the receiving server does not offer STARTTLS, or someone on the path strips the offer, the message goes out in clear text. MTA-STS (RFC 8461) lets a domain tell sending servers "my MX hosts support TLS with a valid certificate; if you cannot get that, do not deliver". It has two parts: a TXT record at _mta-sts.<domain> that announces a policy and its version id, and the policy itself, a small text file at https://mta-sts.<domain>/.well-known/mta-sts.txt.
OrbitProbe reads the TXT record, requests the policy file the way a sending server must (HTTPS, certificate checked, redirects not followed), parses version, mode, mx and max_age, and then looks up the MX records of the domain to see whether each MX host matches one of the mx patterns in the policy.