MTA-STS (SMTP MTA Strict Transport Security) allows receiving domains to publish a policy that tells sending servers to require TLS and validate the MX hosts against your policy, reducing TLS downgrade and misconfiguration risks. This guide shows how to host the policy on Cloudflare and publish the required DNS records.
mta-sts.example.com serving HTTPS with a trusted certificate./.well-known/mta-sts.txt.mta-sts.example.com pointing to your origin (Pages, Workers, or web server).mta-sts.example.com.Place a text file at https://mta-sts.example.com/.well-known/mta-sts.txt with contents like:
version: STSv1
mode: testing
mx: mail1.example.com
mx: mail2.example.com
max_age: 86400
Use mode: testing initially; switch to enforce once validated. Ensure the file is served with Content-Type: text/plain.
Create a TXT record at _mta-sts.example.com:
_mta-sts.example.com. IN TXT "v=STSv1; id=2025-10-22"
Increment the id whenever the policy changes to signal senders to re-fetch.
Create a TXT record at _smtp._tls.example.com to collect TLS reports:
_smtp._tls.example.com. IN TXT "v=TLSRPTv1; rua=mailto:tlsrpt@example.com"
curl -s https://mta-sts.example.com/.well-known/mta-sts.txtdig TXT _mta-sts.example.com +shortopenssl s_client -connect mail1.example.com:25 -starttls smtp -servername mail1.example.com -showcertsmta-sts.example.com./.well-known/mta-sts.txt path.mx: entries match the hostnames in your MX records.Once validated, set mode: enforce and monitor TLS-RPT to catch delivery issues early.