STARTTLS Readiness

SMTP TLS Checker

Review a domain's mail servers, MTA-STS signal, and TLS reporting setup so you know what a real SMTP STARTTLS handshake check still needs to confirm.

Step 1

Start Here

Enter a domain and run SMTP TLS Checker.

Uses public DNS. Recent DNS changes can take time to appear.

Step 2

Review the SMTP TLS Checker Result

Review the status, warnings, and recommended actions shown in the result panel.

Ready When You Are

Run SMTP TLS Checker to see the SMTP TLS Checker result and next actions.

About SMTP TLS Checker

SMTP TLS is the encryption used while mail servers transfer email to each other. A browser tool can explain public DNS signals and the checks to perform, but a true STARTTLS handshake needs a server-side connection to the receiving mail server. The SMTP TLS checker is designed to show what can be checked from public records and what still needs confirmation. Read TLS and Secure Sending for the plain-language background.

Use the SMTP TLS checker when a delivery error mentions TLS, STARTTLS, certificate validation, or secure transport. The SMTP TLS result helps you separate DNS problems from server-side checks that need a mail administrator or email delivery service. If the domain also uses MTA-STS or TLS-RPT, review MTA-STS and TLS Reporting because those records can change how strictly TLS problems are handled.

What SMTP TLS Checker Checks

  • MX mail server discovery
  • MTA-STS DNS signal check
  • TLS-RPT DNS signal check
  • Clear STARTTLS handshake limitation in the browser
  • Next steps for mail administrators

Questions

Why does this not open an SMTP connection directly?

Browsers cannot make raw SMTP STARTTLS connections to arbitrary mail servers. Mailrith can add a server-side SMTP TLS checker later using the same result model.

What should a full SMTP TLS check confirm?

A server-side check should confirm that each MX host accepts STARTTLS, presents a valid certificate, uses a matching hostname, and does not require insecure fallback.