Glossary · DNS

MTA-STS

MTA-STS lets a domain require that mail sent to it travels over TLS with a valid certificate, preventing downgrade and interception attacks.

Server-to-server email encryption is opportunistic by default: an attacker in the path can strip it and read the mail. MTA-STS (RFC 8461) closes that gap with a TXT record at _mta-sts.yourdomain and a policy file served at https://mta-sts.yourdomain/.well-known/mta-sts.txt.

The policy lists your MX hosts and a mode: testing to observe, enforce to refuse delivery when TLS can't be verified. Pair it with TLS-RPT to get reports about failures.

version: STSv1
mode: enforce
mx: mx1.mailhost.example
max_age: 604800
The policy file

Business email that lands in the inbox.

Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.