ė.email

MTA-STS · RFC 8461 — TLS-RPT · RFC 8460

MTA-STS and TLS-RPT: is TLS required, and who hears when it fails

Type a domain to read the record that announces its MTA-STS policy and the record that says where senders report TLS failures. Both are explained; the policy file itself is not fetched.

The MTA-STS and TLS-RPT checker

Try

The domain you type goes to two DNS-over-HTTPS operators, Google Public DNS and Cloudflare, straight from your browser, and to nobody else. It is not stored, and it is not put in this page's address. If you type an email address, only the part after the @ is used.

MTA-STS

_mta-sts.<domain> · TXT

Not checked yet

Whether an MTA-STS policy is announced, its version id, and whether the policy host exists.

TLS-RPT

_smtp._tls.<domain> · TXT

Not checked yet

Where the domain asks senders to report deliveries that failed over TLS.

What MTA-STS is

Mail between servers is encrypted only when both sides agree to it at the moment of delivery, and an attacker in the path can remove the offer. MTA-STS lets a domain declare that its mail hosts support TLS with a certificate senders can verify, and tell senders what to do when that fails (RFC 8461). It has two parts: a TXT record at _mta-sts.<domain> that announces the policy, and the policy itself, a small text file served over HTTPS.

_mta-sts.example.com. IN TXT "v=STSv1; id=20160831085700Z;"

The example record of RFC 8461 §3.1.

version: STSv1 mode: enforce mx: mail.example.com mx: *.example.net mx: backupmx.example.com max_age: 604800

The example policy of RFC 8461 §3.2, served at https://mta-sts.example.com/.well-known/mta-sts.txt.

How to read the record

  • v=STSv1 is the version and must come first.
  • id= is 1 to 32 letters and digits that identify this version of the policy. Senders compare it with the id they have cached and fetch the policy again only when it changed, so the id has to change every time the policy file does (RFC 8461 §3.1).
  • If the number of records that begin with v=STSv1 is not exactly one, senders act as if the domain had no policy.

How to read the policy file

mode is one of three. With enforce, senders must not deliver to a host that fails the check. With testing, they deliver anyway and report the failure. With none, they treat the domain as having no policy (RFC 8461 §5). mx lists the mail hosts that may receive the domain's mail, and max_age is the lifetime of the policy in seconds, at most 31557600.

The checker reads the TXT record and looks up whether the policy host mta-sts.<domain> has an address. It does not fetch the file, because that would send the domain you typed somewhere other than the two DNS operators. The card gives the address of the file so that you can open it yourself.

TLS-RPT: the reports

TLS-RPT is the companion record. A TXT record at _smtp._tls.<domain> that begins with v=TLSRPTv1 gives senders an address, mailto: or https:, to which they report deliveries that failed over TLS (RFC 8460 §3). Without it a domain in enforce mode does not learn that a sender could not deliver.

_smtp._tls.example.com. IN TXT "v=TLSRPTv1;rua=mailto:reports@example.com"

The example record of RFC 8460 §3.1.1.

The common mistakes

  • The policy changed, the id did not. Senders that hold the old policy in their cache keep using it.
  • An id with punctuation. Only letters and digits are allowed; a date written with hyphens is not valid.
  • No policy host. The record is published and mta-sts.<domain> does not exist. Senders that have no cached policy then deliver as if MTA-STS were not there (RFC 8461 §3.3).
  • A redirect on the policy URL. Senders must not follow HTTP redirects when they fetch a policy (RFC 8461 §3.3).
  • Expecting subdomains to inherit. A policy covers its own domain only: for mail to user@mail.example.com senders look at mail.example.com, never at example.com (RFC 8461 §3.4).
  • A wildcard TXT record in the zone. It answers for _mta-sts and _smtp._tls too. Records that do not begin with the right version are discarded, and the checker says when it has discarded some.