MTA-STS
_mta-sts.<domain> · TXT
Not checked yetWhether an MTA-STS policy is announced, its version id, and whether the policy host exists.
MTA-STS · RFC 8461 — TLS-RPT · RFC 8460
Type a domain to read the record that announces its MTA-STS policy and the record that says where senders report TLS failures. Both are explained; the policy file itself is not fetched.
_mta-sts.<domain> · TXT
Not checked yetWhether an MTA-STS policy is announced, its version id, and whether the policy host exists.
_smtp._tls.<domain> · TXT
Not checked yetWhere the domain asks senders to report deliveries that failed over TLS.
Mail between servers is encrypted only when both sides agree to it at the moment of delivery, and an attacker in the path can remove the offer. MTA-STS lets a domain declare that its mail hosts support TLS with a certificate senders can verify, and tell senders what to do when that fails (RFC 8461). It has two parts: a TXT record at _mta-sts.<domain> that announces the policy, and the policy itself, a small text file served over HTTPS.
_mta-sts.example.com. IN TXT "v=STSv1; id=20160831085700Z;"
The example record of RFC 8461 §3.1.
version: STSv1
mode: enforce
mx: mail.example.com
mx: *.example.net
mx: backupmx.example.com
max_age: 604800
The example policy of RFC 8461 §3.2, served at https://mta-sts.example.com/.well-known/mta-sts.txt.
v=STSv1 is the version and must come first.id= is 1 to 32 letters and digits that identify this version of the policy. Senders compare it with the id they have cached and fetch the policy again only when it changed, so the id has to change every time the policy file does (RFC 8461 §3.1).v=STSv1 is not exactly one, senders act as if the domain had no policy.mode is one of three. With enforce, senders must not deliver to a host that fails the check. With testing, they deliver anyway and report the failure. With none, they treat the domain as having no policy (RFC 8461 §5). mx lists the mail hosts that may receive the domain's mail, and max_age is the lifetime of the policy in seconds, at most 31557600.
The checker reads the TXT record and looks up whether the policy host mta-sts.<domain> has an address. It does not fetch the file, because that would send the domain you typed somewhere other than the two DNS operators. The card gives the address of the file so that you can open it yourself.
TLS-RPT is the companion record. A TXT record at _smtp._tls.<domain> that begins with v=TLSRPTv1 gives senders an address, mailto: or https:, to which they report deliveries that failed over TLS (RFC 8460 §3). Without it a domain in enforce mode does not learn that a sender could not deliver.
_smtp._tls.example.com. IN TXT "v=TLSRPTv1;rua=mailto:reports@example.com"
The example record of RFC 8460 §3.1.1.
mta-sts.<domain> does not exist. Senders that have no cached policy then deliver as if MTA-STS were not there (RFC 8461 §3.3)._mta-sts and _smtp._tls too. Records that do not begin with the right version are discarded, and the checker says when it has discarded some.