MTA-STS 检测
检查邮件传输代理严格传输安全(MTA-STS)记录
试试示例:
准备好检查 MTA-STS 记录
Enter a domain name above to check its MTA-STS DNS records and policy configuration.
本页提供关于 MTA-STS 策略查询的原创、经人工审校的内容,解释 well-known 策略文件、enforce 与 testing 模式,以及 MTA-STS 如何为入站 SMTP 强制 TLS。
MTA-STS (Mail Transfer Agent Strict Transport Security) is an email security standard that enables mail service providers to declare their ability to receive TLS-secured connections and to specify whether sending SMTP servers should refuse to deliver to MX hosts that do not offer TLS with a trusted server certificate.
核心组成部分:
- DNS TXT 记录:发布在 _mta-sts.domain.com,用于通告 MTA-STS 支持
- 策略文件:托管在 https://mta-sts.domain.com/.well-known/mta-sts.txt
- 模式:可以是 "enforce"(强制执行)、"testing"(测试)或 "none"(无)
- 最大缓存时间:策略应被缓存的时间
MTA-STS 的工作原理:
- 发送邮件服务器检查 _mta-sts.domain.com 的 TXT 记录
- 如果找到,则从 https://mta-sts.domain.com/.well-known/mta-sts.txt 获取策略文件
- 验证收件 MX 服务器是否支持 TLS 且具有有效证书
- 根据指定的模式执行策略
第 1 步:创建 DNS TXT 记录
The "id" should be updated whenever you change your policy file.
第 2 步:创建策略文件
Host a policy file at https://mta-sts.example.com/.well-known/mta-sts.txt
第 3 步:配置 HTTPS
Ensure mta-sts.example.com has a valid TLS certificate and serves the policy file over HTTPS.
策略文件无法访问
The policy file at https://mta-sts.domain.com/.well-known/mta-sts.txt is not reachable.
解决方案:确保 HTTPS 配置正确且文件存在。
证书不匹配
MX servers don't have valid TLS certificates matching their hostnames.
解决方案:确保所有 MX 主机都有正确的 TLS 证书。
策略 ID 不匹配
The policy ID in DNS doesn't match recent policy changes.
解决方案:修改策略时更新 DNS TXT 记录 ID。
模式配置
Choosing the right mode for your deployment stage.
Solution: Use "testing" for monitoring, "enforce" for active protection.
MTA-STS 策略缓存持续多久?
策略文件中的 max_age 值决定发送服务器缓存你策略的时间。常见值为 86400(1 天)到 604800(1 周)。
“enforce”和“testing”模式有什么区别?
“testing”模式允许在不阻止邮件投递的情况下监控策略违规。“enforce”模式会主动拒收不符合策略的邮件。
如果已有 DANE,还需要 MTA-STS 吗?
MTA-STS 和 DANE 用途相似但工作方式不同。MTA-STS 更易于实施,且不需要 DNSSEC,因此被更广泛采用。
如何监控 MTA-STS 合规性?
在 MTA-STS 之外实施 TLS-RPT(TLS 报告),以接收关于 TLS 连接失败和策略违规的报告。
MX 主机名中可以使用通配符吗?
可以。你可以在 MTA-STS 策略中使用 "*.mail.example.com" 等通配符,用一条记录匹配多台 MX 服务器。
