The problem MTA-STS solves
Mail servers encrypt the connections between them with STARTTLS, but only if both sides offer it. Someone in the path can remove the offer, or redirect the mail to a server of their own, and the mail goes through unprotected without anyone noticing. MTA-STS lets the receiving domain say in advance: always use TLS with me, and check that it is really me.1
How MTA-STS works
- A DNS record announces the policy. A TXT record at
_mta-sts.example.comholds a version and an id, for examplev=STSv1; id=20260315. The id changes whenever the policy changes. - The policy is served over HTTPS at
https://mta-sts.example.com/.well-known/mta-sts.txt. Because it comes over HTTPS, it is protected by the web’s certificate system. - The sending server saves the policy for as long as its max_age says, so an attacker can’t make it vanish later.
- Each delivery is checked. The receiving server must be one of the names in the policy, must offer TLS, and must present a valid certificate for that name. In enforce mode, if any of that fails, the mail isn’t delivered to that server.
| Mode | What sending servers do when the secure connection fails |
|---|---|
| none | Nothing special. The domain has no active policy |
| testing | Deliver anyway, and report the failure if reporting is set up |
| enforce | Don’t deliver to that server. Try another listed server or try again later |
A companion standard, SMTP TLS Reporting (TLS-RPT), lets a domain publish an address where senders report TLS failures, so the owner can see problems before and after switching to enforce.2
Why MTA-STS matters
Encryption that an attacker can switch off only protects you from people who aren’t trying. MTA-STS turns TLS between mail servers from “if possible” into “or not at all” for the domains that publish it. It needs nothing from the people writing or reading the mail.
How to check a domain’s MTA-STS policy
- Look up the DNS record:
dig +short TXT _mta-sts.example.com. A reply starting with v=STSv1 means the domain has a policy. - Read the policy file: open
https://mta-sts.example.com/.well-known/mta-sts.txtin a browser. - Check the mode line. Only enforce makes sending servers refuse an unprotected delivery.
Where you’ll see it
MTA-STS works out of sight, between servers. You’ll meet it when setting up mail for a domain or reading a TLS report. The other way to get the same guarantee is DANE, which pins the mail server’s certificate in DNS and depends on DNSSEC.3 MTA-STS was designed for domains that don’t have DNSSEC.
MTA-STS in Secria
Secria’s domains publish an MTA-STS policy in enforce mode, with TLS reporting. Mail servers that support MTA-STS deliver to Secria only over TLS with a valid certificate. Once a message arrives, it is stored with zero-access encryption, locked with a key made from your password on your device.
Related terms
Sources
- IETF, RFC 8461: SMTP MTA Strict Transport Security (MTA-STS) (September 2018).
- IETF, RFC 8460: SMTP TLS Reporting (September 2018).
- IETF, RFC 7672: SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) (October 2015).
Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.
Questions about MTA-STS
What is the difference between MTA-STS and STARTTLS?
STARTTLS is the command that turns encryption on between two mail servers, when both agree. MTA-STS is a policy that tells sending servers they must use it, and must check the certificate, when delivering to a domain.
What is the difference between testing and enforce mode?
In testing mode, sending servers still deliver when the secure connection fails, and report the failure. In enforce mode they don’t deliver to that server. Domains usually start in testing, read the reports, then move to enforce.
Is MTA-STS the same as DANE?
No. Both make TLS between mail servers mandatory, but they prove the server’s identity differently. MTA-STS relies on HTTPS and public certificate authorities. DANE publishes the certificate details in DNS and needs DNSSEC.
Does MTA-STS encrypt my email end to end?
No. It protects a message while it travels between two mail servers. The servers at each end still handle the message itself. Protecting the stored message is a separate layer, such as zero-access or end-to-end encryption.
What is TLS-RPT?
TLS-RPT, or SMTP TLS Reporting, is a DNS record that names an address where other mail servers send daily reports about TLS problems they hit when delivering to a domain. It is usually set up together with MTA-STS.