What is MTA-STS?

MTA-STS (Mail Transfer Agent Strict Transport Security) is a standard that lets a domain tell other mail servers to deliver its mail only over TLS with a valid certificate. The domain publishes a policy over HTTPS. Sending servers that support it hold the mail back if the connection can’t be secured, instead of falling back to plain text.

Also called: SMTP MTA Strict Transport Security, MTA Strict Transport Security

Updated October 2026. Sources are numbered and listed at the end.

On this page

The problem MTA-STS solves

Mail servers encrypt the connections between them with STARTTLS, but only if both sides offer it. Someone in the path can remove the offer, or redirect the mail to a server of their own, and the mail goes through unprotected without anyone noticing. MTA-STS lets the receiving domain say in advance: always use TLS with me, and check that it is really me.1

How MTA-STS works

  1. A DNS record announces the policy. A TXT record at _mta-sts.example.com holds a version and an id, for example v=STSv1; id=20260315. The id changes whenever the policy changes.
  2. The policy is served over HTTPS at https://mta-sts.example.com/.well-known/mta-sts.txt. Because it comes over HTTPS, it is protected by the web’s certificate system.
  3. The sending server saves the policy for as long as its max_age says, so an attacker can’t make it vanish later.
  4. Each delivery is checked. The receiving server must be one of the names in the policy, must offer TLS, and must present a valid certificate for that name. In enforce mode, if any of that fails, the mail isn’t delivered to that server.
The three modes a policy can set.
ModeWhat sending servers do when the secure connection fails
noneNothing special. The domain has no active policy
testingDeliver anyway, and report the failure if reporting is set up
enforceDon’t deliver to that server. Try another listed server or try again later

A companion standard, SMTP TLS Reporting (TLS-RPT), lets a domain publish an address where senders report TLS failures, so the owner can see problems before and after switching to enforce.2

Why MTA-STS matters

Encryption that an attacker can switch off only protects you from people who aren’t trying. MTA-STS turns TLS between mail servers from “if possible” into “or not at all” for the domains that publish it. It needs nothing from the people writing or reading the mail.

How to check a domain’s MTA-STS policy

  1. Look up the DNS record: dig +short TXT _mta-sts.example.com. A reply starting with v=STSv1 means the domain has a policy.
  2. Read the policy file: open https://mta-sts.example.com/.well-known/mta-sts.txt in a browser.
  3. Check the mode line. Only enforce makes sending servers refuse an unprotected delivery.

Where you’ll see it

MTA-STS works out of sight, between servers. You’ll meet it when setting up mail for a domain or reading a TLS report. The other way to get the same guarantee is DANE, which pins the mail server’s certificate in DNS and depends on DNSSEC.3 MTA-STS was designed for domains that don’t have DNSSEC.

MTA-STS in Secria

Secria’s domains publish an MTA-STS policy in enforce mode, with TLS reporting. Mail servers that support MTA-STS deliver to Secria only over TLS with a valid certificate. Once a message arrives, it is stored with zero-access encryption, locked with a key made from your password on your device.

Sources

  1. IETF, RFC 8461: SMTP MTA Strict Transport Security (MTA-STS) (September 2018).
  2. IETF, RFC 8460: SMTP TLS Reporting (September 2018).
  3. IETF, RFC 7672: SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) (October 2015).

Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.

Questions about MTA-STS

What is the difference between MTA-STS and STARTTLS?

STARTTLS is the command that turns encryption on between two mail servers, when both agree. MTA-STS is a policy that tells sending servers they must use it, and must check the certificate, when delivering to a domain.

What is the difference between testing and enforce mode?

In testing mode, sending servers still deliver when the secure connection fails, and report the failure. In enforce mode they don’t deliver to that server. Domains usually start in testing, read the reports, then move to enforce.

Is MTA-STS the same as DANE?

No. Both make TLS between mail servers mandatory, but they prove the server’s identity differently. MTA-STS relies on HTTPS and public certificate authorities. DANE publishes the certificate details in DNS and needs DNSSEC.

Does MTA-STS encrypt my email end to end?

No. It protects a message while it travels between two mail servers. The servers at each end still handle the message itself. Protecting the stored message is a separate layer, such as zero-access or end-to-end encryption.

What is TLS-RPT?

TLS-RPT, or SMTP TLS Reporting, is a DNS record that names an address where other mail servers send daily reports about TLS problems they hit when delivering to a domain. It is usually set up together with MTA-STS.

Email that’s ready for what comes next.

Post-quantum encryption on every plan, free included.

Start free

Explore Secria Mail