DNS policy version
Validate a unique v=STSv1 record and a usable policy id.
Check the mail TLS policy file, MX patterns and failure reporting configuration.
Mail transport security
MTA-STS tells sending servers to require valid TLS and deliver only to MX hosts listed by the policy. It combines a DNS version record with a policy file served over HTTPS.
TLS-RPT provides aggregate reports about SMTP TLS failures. Together they support a measured move from observation to enforcement.
Validate a unique v=STSv1 record and a usable policy id.
Safely fetch the standard path and parse version, mode, mx and max_age.
Validate the TLSRPTv1 record and aggregate report URIs.
Opportunistic TLS can fall back to plaintext. MTA-STS reduces downgrade opportunities, while TLS-RPT makes certificate, routing and negotiation failures visible.
Require supporting senders to validate certificates and match approved MX hosts.
Use testing mode and aggregate reports to correct certificates or routing.
Check the DNS id, HTTPS file and reporting record together.
Policy requests are restricted to public HTTPS targets with per-hop redirect validation, private-address blocking, timeouts and a response-size limit.
Read _mta-sts and _smtp._tls records in parallel.
Request the standard well-known path on the mta-sts subdomain.
Validate STSv1, mode, MX patterns, max_age and TLS-RPT rua.
Separate unavailable files, testing mode, missing reports and syntax errors.
Use https://mta-sts.example.com/.well-known/mta-sts.txt with a publicly trusted HTTPS certificate and a direct plain-text response.
Testing collects failures without requiring senders to stop delivery. Enforce asks supporting senders to defer or reject delivery when TLS or MX does not match the policy.
The id is a policy version signal. Changing it tells senders to fetch the HTTPS policy again.
No. They contain aggregate policy, connection and certificate failure information, not message bodies.
No. Results remain on the current page. A short server cache may reduce repeated DNS and HTTPS requests.
Continue with sender authentication, brand indicators and policy generation.