Glossary · DNS
MTA-STS lets a domain require that mail sent to it travels over TLS with a valid certificate, preventing downgrade and interception attacks.
Server-to-server email encryption is opportunistic by default: an attacker in the path can strip it and read the mail. MTA-STS (RFC 8461) closes that gap with a TXT record at _mta-sts.yourdomain and a policy file served at https://mta-sts.yourdomain/.well-known/mta-sts.txt.
The policy lists your MX hosts and a mode: testing to observe, enforce to refuse delivery when TLS can't be verified. Pair it with TLS-RPT to get reports about failures.
version: STSv1
mode: enforce
mx: mx1.mailhost.example
max_age: 604800Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.