SMTP TLS Checker
Review a domain's mail servers, MTA-STS signal, and TLS reporting setup so you know what a real SMTP STARTTLS handshake check still needs to confirm.
Start Here
Enter a domain and run SMTP TLS Checker.
Review the SMTP TLS Checker Result
Review the status, warnings, and recommended actions shown in the result panel.
Ready When You Are
Run SMTP TLS Checker to see the SMTP TLS Checker result and next actions.
About SMTP TLS Checker
SMTP TLS is the encryption used while mail servers transfer email to each other. A browser tool can explain public DNS signals and the checks to perform, but a true STARTTLS handshake needs a server-side connection to the receiving mail server. The SMTP TLS checker is designed to show what can be checked from public records and what still needs confirmation. Read TLS and Secure Sending for the plain-language background.
Use the SMTP TLS checker when a delivery error mentions TLS, STARTTLS, certificate validation, or secure transport. The SMTP TLS result helps you separate DNS problems from server-side checks that need a mail administrator or email delivery service. If the domain also uses MTA-STS or TLS-RPT, review MTA-STS and TLS Reporting because those records can change how strictly TLS problems are handled.
What SMTP TLS Checker Checks
- MX mail server discovery
- MTA-STS DNS signal check
- TLS-RPT DNS signal check
- Clear STARTTLS handshake limitation in the browser
- Next steps for mail administrators
Questions
Why does this not open an SMTP connection directly?
Browsers cannot make raw SMTP STARTTLS connections to arbitrary mail servers. Mailrith can add a server-side SMTP TLS checker later using the same result model.
What should a full SMTP TLS check confirm?
A server-side check should confirm that each MX host accepts STARTTLS, presents a valid certificate, uses a matching hostname, and does not require insecure fallback.