MTA-STS: forcing TLS on every email destined for your inbox.
Published 2026-05-13 · Last updated 2026-05-13 · Vantyris editorial
MTA-STS (Mail Transfer Agent Strict Transport Security) does for email what HSTS does for web traffic. It tells sending mail servers that yours requires TLS, so they must refuse to deliver in plain text. Without it, an attacker on the network path between your customer's mail server and yours can downgrade the connection and read every email in transit. Adoption is still low (around 15% of UK domains in 2026). Setting it up is a five-minute job, and it puts your email security ahead of most of your peers.
What this means for your business
- Mail between servers has historically been delivered in plain text, upgrading 'opportunistically' to TLS when both sides support it. An attacker sitting on the network can simply strip the TLS negotiation, and the receiving server delivers anyway.
- MTA-STS adds two things. A DNS record at
_mta-sts.<yourdomain>announces that the policy exists, and a policy file served over HTTPS athttps://mta-sts.<yourdomain>/.well-known/mta-sts.txtsets the rules (which MX hosts to trust, how long to enforce). Sending servers fetch and cache the policy, then refuse to deliver to your domain in plain text for as long as it's cached. - The companion TLS-RPT record asks receiving servers to report TLS failures back to you, so you find out if mail is being dropped instead of just delivering insecurely.
How to fix
Publish two records: an MTA-STS policy file at a well-known HTTPS URL on a subdomain, plus a DNS TXT record pointing at it. Start in 'testing' mode for a month, then move to 'enforce'.
- Create the
mta-stssubdomain and host the policy file. At your DNS provider, pointmta-sts.<yourdomain>to your web host. At your web host, serve a file at/.well-known/mta-sts.txtwith contents like:version: STSv1mode: testingmx: mx.yourdomain.commax_age: 86400Replace themxvalue with your actual MX host (look at your domain's MX record). - Add the DNS TXT record. At
_mta-sts.<yourdomain>, publish a TXT record likev=STSv1; id=2026052500;. The id is any string you change whenever you update the policy. - Verify the policy is reachable. Open
https://mta-sts.<yourdomain>/.well-known/mta-sts.txtin a browser. It should return your policy as plain text. If it 404s or shows the wrong content, fix the web-host config first. - Add a TLS-RPT record for failure reporting. At
_smtp._tls.<yourdomain>, publish a TXT record:v=TLSRPTv1; rua=mailto:tls-rpt@yourdomain.com. You'll receive daily aggregate reports from major mail providers when TLS fails. - Watch for a month, then switch to enforce mode. After 30 days of clean TLS-RPT reports, change the policy file from
mode: testingtomode: enforce. Bump the id in the DNS TXT record so sending servers refresh their cache.
Owner: Your DNS administrator + your web host (the policy file needs to live on HTTPS). · Time: 20 minutes for the initial setup, then a 30-day watch period before enforcing.
Common gotchas
- The policy file must be served over HTTPS with a valid certificate. A self-signed or expired cert breaks MTA-STS for every sending server.
- Don't skip the 30-day testing period. If your MX record changes (a provider switch) or your TLS cert expires, you've blocked your own inbound mail.
- MTA-STS protects inbound mail (people emailing your domain). Outbound mail (you emailing others) is the recipient's responsibility, and you can't make them publish MTA-STS for theirs.
- If subdomains of yours receive mail too, decide whether MTA-STS should cover them. The policy covers only the host you publish it for. It doesn't extend to other hosts automatically.
How to verify the fix
Use Hardenize (hardenize.com) or Mecsa (mecsa.jrc.ec.europa.eu) for free MTA-STS + TLS-RPT validation. Or run a Vantyris scan, whose Email category checks both.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Is MTA-STS worth the effort if my email is hosted by Google or Microsoft?
Yes. Their outbound mail is fine without you doing anything. But MTA-STS protects INBOUND mail, the messages other companies send TO you. Without MTA-STS that path is still open to downgrade, wherever your mailbox lives.
How is MTA-STS different from DANE?
DANE uses DNSSEC to bind TLS certificate fingerprints to mail hosts. It's more cryptographically rigorous but depends on DNSSEC, which few SMEs have turned on. MTA-STS is the HTTPS-based alternative. It's easier to deploy and slightly less rigorous, and it's the pragmatic consensus standard today.
What if my sending counterparty doesn't support MTA-STS?
Only senders that fetch and honour the policy enforce it. Google and Microsoft do, and so do most other major mail providers. Smaller mail servers may not, and those connections still happen in plain text. Adoption is a one-way ratchet. The more senders honour it, the more of your mail is protected.
References
- RFC 8461: MTA-STS IETF RFC
- RFC 8460: SMTP TLS Reporting IETF RFC
- Google: MTA-STS configuration Vendor
Related explainers
- What is DMARC, and why every business with a domain needs one.
- DKIM: the cryptographic signature that completes your email authentication trio.
- SPF records, explained: the first line of defence against email spoofing.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris