What is MTA-STS?
MTA-STS (SMTP MTA Strict Transport Security, RFC 8461) lets a domain tell sending mail servers that mail for it must be delivered over TLS with a valid certificate, and only to the MX hosts it lists. Its companion TLS-RPT (RFC 8460) asks senders to email you daily reports about TLS problems when delivering to your domain.
By Stephen Williams · Updated
Why STARTTLS isn't enough
Mail servers encrypt connections with STARTTLS, but only opportunistically. An attacker on the network path can strip the STARTTLS offer or present a bogus certificate, and most senders will fall back to delivering in plain text rather than bounce the message. MTA-STS closes that gap for senders that support it by publishing a policy that says "TLS with a valid certificate, or don't deliver".
How MTA-STS works
- A TXT record at
_mta-sts.yourdomain.comannounces that a policy exists and gives it anid. - The policy file is served over HTTPS at
https://mta-sts.yourdomain.com/.well-known/mta-sts.txt. - A supporting sender fetches and caches the policy for
max_ageseconds, and checks theidon later deliveries to see whether it changed. - When delivering, the sender only uses MX hosts that match the policy and requires TLS with a valid certificate. In
enforcemode it won't deliver otherwise.
Setting up MTA-STS
1. Turn on TLS reporting first
Reports tell you whether enforcing would break delivery, so publish TLS-RPT before anything else:
v=TLSRPTv1; rua=mailto:tls-reports@example.com2. Publish the policy file in testing mode
Host this plain-text file at https://mta-sts.example.com/.well-known/mta-sts.txt with a valid certificate for mta-sts.example.com:
version: STSv1
mode: testing
mx: mail.example.com
mx: *.mail.example.net
max_age: 86400| Field | Meaning |
|---|---|
version | Always STSv1. |
mode | enforce, testing or none (none is used to retire a policy). |
mx | One line per allowed MX host, exactly as in your MX records, or a wildcard such as *.mail.example.net that matches a single leftmost label. |
max_age | How long senders may cache the policy, in seconds. The maximum is 31557600 (about a year). |
3. Publish the _mta-sts TXT record
v=STSv1; id=20261008T000000;The id can be any short alphanumeric string, but it must change every time you edit the policy file, otherwise senders keep using their cached copy. A timestamp works well.
4. Move to enforce
After reports show successful TLS sessions from the senders you care about and no unexpected failures, change mode to enforce, raise max_age (for example to a week or more), and update the id.
TLS-RPT reports
TLS-RPT (RFC 8460) reports are JSON summaries, usually daily, listing successful and failed TLS sessions from a sending organization to your mail servers, with failure reasons such as certificate mismatches or STARTTLS not being offered. They are useful even without MTA-STS, because they reveal TLS problems on your inbound mail servers.
Sources
Frequently asked questions
What is the difference between MTA-STS and STARTTLS?
STARTTLS lets two mail servers upgrade a connection to TLS, but it is opportunistic: if the upgrade is blocked or the certificate is invalid, mail is usually sent unencrypted anyway. MTA-STS publishes a policy saying TLS with a valid certificate is required, so supporting senders refuse to deliver over a downgraded connection.
What does MTA-STS testing mode do?
In testing mode, senders still deliver mail when validation fails, but those that support TLS reporting send you reports about the failures. It lets you find problems before switching to enforce mode.
Is MTA-STS related to DMARC?
They solve different problems. DMARC, SPF and DKIM authenticate mail sent from your domain; MTA-STS and TLS-RPT protect mail sent to your domain while it travels between servers. A well-configured domain uses both.
Why does MTA-STS need a web server?
The policy is fetched over HTTPS from mta-sts.yourdomain.com, so the policy itself is protected by a valid web certificate instead of relying on DNS alone. The host must return the file with HTTP 200; redirects are not followed.