TLS Policy

MTA-STS Checker

Check the DNS signal for MTA-STS and see the policy URL your mail administrator should verify before enforcing secure inbound mail delivery.

Step 1

Start Here

Enter a domain and run MTA-STS Checker.

Uses public DNS. Recent DNS changes can take time to appear.

Step 2

Review the MTA-STS Checker Result

Review the status, warnings, and recommended actions shown in the result panel.

Ready When You Are

Run MTA-STS Checker to see the MTA-STS Checker result and next actions.

About MTA-STS Checker

MTA-STS helps receiving mail servers tell senders that inbound email should use encrypted transport. It uses a DNS TXT record and a policy file hosted on a specific HTTPS path. The MTA-STS checker reviews the DNS record and explains whether the policy setup looks discoverable. For the complete concept, read MTA-STS and TLS Reporting.

MTA-STS is mainly an inbound security feature. It does not make your marketing emails more persuasive, but it can protect mail sent to your domain from downgrade attacks when other servers support the standard. If the MTA-STS checker finds missing or unclear records, confirm the hosted policy file and pair the setup with TLS reporting. The TLS and Secure Sending guide explains where transport encryption fits in email delivery.

What MTA-STS Checker Checks

  • MTA-STS TXT lookup at _mta-sts.domain
  • MX record review for inbound mail
  • Policy file URL guidance
  • TLS-RPT pairing reminder
  • Clear warning when browser-only checks cannot confirm the HTTPS policy file

Questions

Does this prove my MTA-STS policy file is correct?

Not fully. Browser pages often cannot fetch policy files on arbitrary domains because of web security rules. The MTA-STS checker shows the DNS signal and the exact policy URL to verify with a server-side check.

Is MTA-STS required for Mailrith campaigns?

Usually no. For campaigns, first check secure delivery settings, SPF, DKIM, DMARC, alignment, permission, and list quality.