Skip to main content
EmailToolBox LogoEmailToolBox
HomeAll ToolsSuper Lookup
Email Health CheckEmail DeliverabilityEmail Blacklist CheckerEmail Header AnalyzerSPF CheckerDKIM CheckerDMARC CheckerMX Lookup
View All Tools
SPF CheckerDKIM CheckerDMARC CheckerSPF GeneratorDMARC GeneratorBIMI CheckerMTA-STS Checker
Guides
中文

Related Tools

MX Lookup
Check mail servers
Email Blacklist Checker
Check IP reputation
DNS Lookup
DNS record queries
SPF Checker
Validate SPF records
DMARC Checker
Check and analyze DMARC records
Email Header Analyzer
Analyze email headers
DKIM Checker
Verify DKIM signatures
WHOIS Lookup
Domain registration info
SMTP Test
Test SMTP connectivity
SSL Certificate Lookup
Check SSL certificates
DNS Propagation Checker
Check DNS propagation
Ping Test
Test network connectivity
Traceroute
Trace network path
Subnet Calculator
Calculate IP subnets
What Is My IP
Check your IP address

Need Help?

Our tools are designed to be intuitive, but if you need assistance, we're here to help.

DocumentationContact Support

About Our Tools

Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.

Free to UseNo RegistrationReal-time Results
EmailToolBox LogoEmailToolBox

EmailToolBox is a free suite of email testing, deliverability and domain diagnostics tools. Check your email health, validate SPF/DKIM/DMARC, look up DNS records and monitor blacklist status in seconds - no signup required.

  • Free to use
  • No signup required
  • Instant results
  • Real-time DNS checks
  • Privacy-focused

Email Diagnostics

  • Email Health Check
  • Email Deliverability
  • Email Blacklist Checker
  • Email Header Analyzer
  • Email Verifier
  • HTML Email Validator
  • Email Preview Simulator
  • Spam Test
  • Email Health Report

Email Authentication

  • SPF Checker
  • DKIM Checker
  • DMARC Checker
  • DMARC Report Analyzer
  • SPF Generator
  • DMARC Generator
  • BIMI Checker
  • MTA-STS Checker

DNS & Infrastructure

  • MX Lookup
  • DNS Lookup
  • TXT Record Lookup
  • CNAME Record Lookup
  • NS Lookup
  • DNS Propagation
  • PTR/rDNS Record Lookup
  • SMTP Test
  • WHOIS Lookup

Resources

  • Email Guides
  • All Tools
  • FAQ
  • Contact Us
  • About
  • Privacy Policy
  • Terms of Service

Friend Links

  • Favicon Generator
  • Email Testing tools
  • Morse Code Translator
  • Password Remover
  • Regex Cheat Sheet
  • free barcode generator
  • Free Online PDF Tools
  • fast chart
  • refnet
  • world market hours

© 2026 EmailToolBox - Email Testing, Deliverability & Domain Diagnostics. All rights reserved.

    1. Home
    2. Guides
    3. How to Configure MTA-STS in Cloudflare
    Categories
    Related Guides

    How to set up SPF records

    Complete SPF record setup guide, including syntax explanation and best practices

    DANE SMTP Configuration Guide

    Configure DANE for SMTP with TLSA records to enforce secure delivery

    Cloudflare DMARC Setup Guide

    Publish and validate DMARC records in Cloudflare DNS

    How to Configure MTA-STS in Cloudflare

    Set up MTA-STS policy with Cloudflare for secure SMTP delivery
    2 min read
    Updated 2025-10-22
    Tutorials
    mta-stscloudflaresmtptls

    How to Configure MTA-STS in Cloudflare

    MTA-STS (SMTP MTA Strict Transport Security) allows receiving domains to publish a policy that tells sending servers to require TLS and validate the MX hosts against your policy, reducing TLS downgrade and misconfiguration risks. This guide shows how to host the policy on Cloudflare and publish the required DNS records.

    What You Need

    • A hostname mta-sts.example.com serving HTTPS with a trusted certificate.
    • Ability to host a plain text file at /.well-known/mta-sts.txt.
    • Access to Cloudflare DNS for publishing TXT records.

    1) Set up mta-sts host

    1. Create a DNS record for mta-sts.example.com pointing to your origin (Pages, Workers, or web server).
    2. Disable the Cloudflare proxy (set to DNS-only / grey cloud) to ensure end-to-end TLS with your certificate.
    3. Install an SSL/TLS certificate that covers mta-sts.example.com.

    2) Serve the policy file

    Place a text file at https://mta-sts.example.com/.well-known/mta-sts.txt with contents like:

    version: STSv1
    mode: testing
    mx: mail1.example.com
    mx: mail2.example.com
    max_age: 86400
    

    Use mode: testing initially; switch to enforce once validated. Ensure the file is served with Content-Type: text/plain.

    3) Publish the MTA-STS TXT record

    Create a TXT record at _mta-sts.example.com:

    _mta-sts.example.com. IN TXT "v=STSv1; id=2025-10-22"
    

    Increment the id whenever the policy changes to signal senders to re-fetch.

    4) (Optional) Enable TLS-RPT

    Create a TXT record at _smtp._tls.example.com to collect TLS reports:

    _smtp._tls.example.com. IN TXT "v=TLSRPTv1; rua=mailto:tlsrpt@example.com"
    

    5) Verify configuration

    • Fetch policy: curl -s https://mta-sts.example.com/.well-known/mta-sts.txt
    • Check TXT: dig TXT _mta-sts.example.com +short
    • Validate MX TLS: openssl s_client -connect mail1.example.com:25 -starttls smtp -servername mail1.example.com -showcerts

    Cloudflare Tips

    • For Cloudflare Pages, deploy a simple static site that serves the policy path; add a custom domain mta-sts.example.com.
    • Avoid caching or redirects that alter /.well-known/mta-sts.txt path.
    • Keep the proxy off for the mta-sts host to present your origin certificate directly.

    Troubleshooting

    • Policy not reachable: confirm DNS, TLS certificate, and that the path is exact.
    • MX mismatch: ensure the mx: entries match the hostnames in your MX records.
    • Sender refuses enforce: check TLS chain, hostname matches, and ensure modern TLS versions are supported.

    Once validated, set mode: enforce and monitor TLS-RPT to catch delivery issues early.

    Was this guide helpful?

    How to Configure MTA-STS in Cloudflare - EmailToolBox