MTA-STS & TLS-RPT Checker

MTA-STS & TLS-RPT Checker

Check the mail TLS policy file, MX patterns and failure reporting configuration.

Example: Results are not written to the database

Mail transport security

What are MTA-STS and TLS-RPT?

MTA-STS tells sending servers to require valid TLS and deliver only to MX hosts listed by the policy. It combines a DNS version record with a policy file served over HTTPS.

TLS-RPT provides aggregate reports about SMTP TLS failures. Together they support a measured move from observation to enforcement.

What the checker reviews

STS

DNS policy version

Validate a unique v=STSv1 record and a usable policy id.

HTTPS

Policy file

Safely fetch the standard path and parse version, mode, mx and max_age.

RPT

TLS failure reporting

Validate the TLSRPTv1 record and aggregate report URIs.

Why check mail TLS policy?

Opportunistic TLS can fall back to plaintext. MTA-STS reduces downgrade opportunities, while TLS-RPT makes certificate, routing and negotiation failures visible.

Reduce downgrade risk

Require supporting senders to validate certificates and match approved MX hosts.

Find failures before enforcement

Use testing mode and aggregate reports to correct certificates or routing.

Verify the whole deployment

Check the DNS id, HTTPS file and reporting record together.

How does the checker fetch safely?

Policy requests are restricted to public HTTPS targets with per-hop redirect validation, private-address blocking, timeouts and a response-size limit.

  1. 01

    Query both TXT hosts

    Read _mta-sts and _smtp._tls records in parallel.

  2. 02

    Fetch the policy safely

    Request the standard well-known path on the mta-sts subdomain.

  3. 03

    Parse required fields

    Validate STSv1, mode, MX patterns, max_age and TLS-RPT rua.

  4. 04

    Prioritize deployment fixes

    Separate unavailable files, testing mode, missing reports and syntax errors.

MTA-STS and TLS-RPT FAQ

Where must the MTA-STS policy file be hosted?

Use https://mta-sts.example.com/.well-known/mta-sts.txt with a publicly trusted HTTPS certificate and a direct plain-text response.

What is the difference between testing and enforce?

Testing collects failures without requiring senders to stop delivery. Enforce asks supporting senders to defer or reject delivery when TLS or MX does not match the policy.

Why update the DNS id after a policy change?

The id is a policy version signal. Changing it tells senders to fetch the HTTPS policy again.

Do TLS-RPT reports contain message content?

No. They contain aggregate policy, connection and certificate failure information, not message bodies.

Are results stored in a database?

No. Results remain on the current page. A short server cache may reduce repeated DNS and HTTPS requests.