Free MTA-STS Checker & Generator

Check that your MTA-STS record, policy file and TLS-RPT record are set up and that the policy covers every mail server. Or generate all three below.

Check your MTA-STS setup

We look up the _mta-sts record, fetch your policy file over HTTPS, compare it with your MX records, and check TLS-RPT.

Generate MTA-STS records

List the MX hosts from your mailbox provider. The generator runs in your browser.

Understanding MTA-STS

What is MTA-STS?

MTA-STS (Mail Transfer Agent Strict Transport Security) tells other mail servers that your domain only accepts mail over TLS with a valid certificate. Without it, an attacker who can intercept the connection can strip encryption and read or redirect mail meant for you.

Does MTA-STS affect the email I send?

No. MTA-STS protects mail coming in to your domain. It is set up next to your MX records. Your sending reputation depends on SPF, DKIM and DMARC.

Should I start with testing or enforce?

Start with testing and a TLS-RPT record. Senders keep delivering but send you daily reports of TLS problems. Once a couple of weeks of reports come back clean, switch to enforce and update the id in the TXT record.

Why does the policy file need its own subdomain?

Senders fetch the policy from https://mta-sts.yourdomain.com/.well-known/mta-sts.txt, and the certificate on that host must be valid. Any static host works: a small web server, a CDN, or a service like GitHub Pages or Cloudflare.

What is TLS-RPT?

TLS Reporting (TLS-RPT) is a TXT record at _smtp._tls.yourdomain.com that names an address for reports. Senders that support it email you a daily summary of connections that failed TLS, so you find problems before you enforce.

Check which servers your policy has to cover with the MX lookup.

Own your email platform

Broadcast is self-hosted email marketing software. It watches your SPF, DKIM and DMARC records and tells you when one breaks. Pay once, run it on your own server.