Skip to main content
    EmailToolBox LogoEmailToolBox
    HomeAll ToolsSuper Lookup
    Email Health CheckEmail DeliverabilityEmail Blacklist CheckerEmail Header AnalyzerSPF CheckerDKIM CheckerDMARC CheckerMX Lookup
    View All Tools
    SPF CheckerDKIM CheckerDMARC CheckerSPF GeneratorDMARC GeneratorBIMI CheckerMTA-STS Checker
    Guides
    中文
    EmailToolBox LogoEmailToolBox
    HomeAll ToolsSuper Lookup
    Email Health CheckEmail DeliverabilityEmail Blacklist CheckerEmail Header AnalyzerSPF CheckerDKIM CheckerDMARC CheckerMX Lookup
    View All Tools
    SPF CheckerDKIM CheckerDMARC CheckerSPF GeneratorDMARC GeneratorBIMI CheckerMTA-STS Checker
    Guides
    中文
    1. Home
    2. Tools
    3. MTA-STS Lookup

    MTA-STS Checker

    Check Mail Transfer Agent Strict Transport Security records

    MTA-STS (Mail Transfer Agent Strict Transport Security) enables mail service providers to declare their ability to receive TLS-secured connections and to specify whether sending SMTP servers should refuse to deliver to MX hosts that do not offer TLS with a trusted server certificate.
    Domain Lookup
    Enter a domain name to check its MTA-STS DNS records and policy configuration

    Try examples:

    Ready to Check MTA-STS Records

    Enter a domain name above to check its MTA-STS DNS records and policy configuration.

    About This Tool

    This page provides original, human-reviewed information about MTA-STS policy lookups, explaining the well-known policy file, enforce versus testing modes, and how MTA-STS enforces TLS for inbound SMTP.

    What is MTA-STS?

    MTA-STS (Mail Transfer Agent Strict Transport Security) is an email security standard that enables mail service providers to declare their ability to receive TLS-secured connections and to specify whether sending SMTP servers should refuse to deliver to MX hosts that do not offer TLS with a trusted server certificate.

    Key Components:

    • DNS TXT Record:Published at _mta-sts.domain.com to advertise MTA-STS support
    • Policy File:Hosted at https://mta-sts.domain.com/.well-known/mta-sts.txt
    • Mode:Can be "enforce", "testing", or "none"
    • Max Age:How long the policy should be cached

    How MTA-STS Works:

    1. Sending mail server checks for _mta-sts.domain.com TXT record
    2. If found, fetches the policy file from https://mta-sts.domain.com/.well-known/mta-sts.txt
    3. Validates that the receiving MX servers support TLS and have valid certificates
    4. Enforces the policy based on the specified mode
    Setting Up MTA-STS

    Step 1: Create DNS TXT Record

    _mta-sts.example.com. IN TXT "v=STSv1; id=20240101T000000;"

    The "id" should be updated whenever you change your policy file.

    Step 2: Create Policy File

    Host a policy file at https://mta-sts.example.com/.well-known/mta-sts.txt

    version: STSv1
    mode: enforce
    mx: mail.example.com
    mx: backup-mail.example.com
    max_age: 604800

    Step 3: Configure HTTPS

    Ensure mta-sts.example.com has a valid TLS certificate and serves the policy file over HTTPS.

    Start with mode "testing" to monitor without enforcement, then switch to "enforce" when ready.
    Common MTA-STS Issues

    Policy File Not Accessible

    The policy file at https://mta-sts.domain.com/.well-known/mta-sts.txt is not reachable.

    Solution: Ensure HTTPS is properly configured and the file exists.

    Certificate Mismatch

    MX servers don't have valid TLS certificates matching their hostnames.

    Solution: Ensure all MX hosts have proper TLS certificates.

    Policy ID Mismatch

    The policy ID in DNS doesn't match recent policy changes.

    Solution: Update the DNS TXT record ID when modifying the policy.

    Mode Configuration

    Choosing the right mode for your deployment stage.

    Solution: Use "testing" for monitoring, "enforce" for active protection.

    Frequently Asked Questions

    How long does MTA-STS policy caching last?

    The max_age value in your policy file determines how long sending servers cache your policy.Common values are 86400 (1 day) to 604800 (1 week).

    What's the difference between "enforce" and "testing" modes?

    "Testing" mode allows monitoring of policy violations without blocking email delivery."Enforce" mode actively rejects emails that don't comply with the policy.

    Do I need MTA-STS if I have DANE?

    MTA-STS and DANE serve similar purposes but work differently. MTA-STS is easier to implementand doesn't require DNSSEC, making it more widely adopted.

    How do I monitor MTA-STS compliance?

    Implement TLS-RPT (TLS Reporting) alongside MTA-STS to receive reports about TLS connectionfailures and policy violations.

    Can I use wildcards in MX hostnames?

    Yes, you can use wildcards like "*.mail.example.com" in your MTA-STS policy to matchmultiple MX servers with a single entry.

    Related Tools

    MX Lookup
    Check mail servers
    Email Blacklist Checker
    Check IP reputation
    DNS Lookup
    DNS record queries
    SPF Checker
    Validate SPF records
    DMARC Checker
    Check and analyze DMARC records
    Email Header Analyzer
    Analyze email headers
    DKIM Checker
    Verify DKIM signatures
    WHOIS Lookup
    Domain registration info
    SMTP Test
    Test SMTP connectivity
    SSL Certificate Lookup
    Check SSL certificates
    DNS Propagation Checker
    Check DNS propagation
    Ping Test
    Test network connectivity
    Traceroute
    Trace network path
    Subnet Calculator
    Calculate IP subnets
    What Is My IP
    Check your IP address

    Related Guides

    How to Configure MTA-STS in Cloudflare
    Cloudflare MTA-STS Configuration: Complete SMTP TLS Enforcement Guide
    AWS MTA-STS Configuration: Enterprise SMTP TLS Enforcement on AWS
    MTA-STS Policy Examples and Testing

    Need Help?

    Our tools are designed to be intuitive, but if you need assistance, we're here to help.

    DocumentationContact Support

    About Our Tools

    Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.

    Free to UseNo RegistrationReal-time Results
    EmailToolBox LogoEmailToolBox

    EmailToolBox is a free suite of email testing, deliverability and domain diagnostics tools. Check your email health, validate SPF/DKIM/DMARC, look up DNS records and monitor blacklist status in seconds - no signup required.

    • Free to use
    • No signup required
    • Instant results
    • Real-time DNS checks
    • Privacy-focused

    Email Diagnostics

    • Email Health Check
    • Email Deliverability
    • Email Blacklist Checker
    • Email Header Analyzer
    • Email Verifier
    • HTML Email Validator
    • Email Preview Simulator
    • Spam Test
    • Email Health Report

    Email Authentication

    • SPF Checker
    • DKIM Checker
    • DMARC Checker
    • DMARC Report Analyzer
    • SPF Generator
    • DMARC Generator
    • BIMI Checker
    • MTA-STS Checker

    DNS & Infrastructure

    • MX Lookup
    • DNS Lookup
    • TXT Record Lookup
    • CNAME Record Lookup
    • NS Lookup
    • DNS Propagation
    • PTR/rDNS Record Lookup
    • SMTP Test
    • WHOIS Lookup

    Resources

    • Email Guides
    • All Tools
    • FAQ
    • Contact Us
    • About
    • Privacy Policy
    • Terms of Service

    Friend Links

    • Favicon Generator
    • Email Testing tools
    • Morse Code Translator
    • Password Remover
    • Regex Cheat Sheet
    • free barcode generator
    • Free Online PDF Tools
    • fast chart
    • refnet
    • world market hours

    © 2026 EmailToolBox - Email Testing, Deliverability & Domain Diagnostics. All rights reserved.

    MTA-STS Lookup - Free Mail Transport Security Check - EmailToolBox