MTA-STS Policy Generator
An MTA-STS policy generator produces the two artefacts RFC 8461 requires: a policy file served at a well-known HTTPS URL listing your MX hosts and mode, and a DNS TXT record whose id changes whenever the policy does. Together they stop attackers downgrading inbound mail to plaintext.
Last reviewed by the Radiatus Cloud team
Policy File
DNS TXT Record
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
The problem MTA-STS solves
SMTP encrypts opportunistically. A sending server offers STARTTLS, and if the offer is stripped by a man in the middle or the certificate does not match, most senders fall back to plaintext rather than fail. MTA-STS lets the receiving domain publish a policy saying: my mail servers always support TLS with valid certificates, and if you cannot get that, do not deliver. Gmail and Outlook.com both honour published policies.
The two pieces
- Policy file at
https://mta-sts.example.com/.well-known/mta-sts.txt, served over HTTPS with a valid certificate for the mta-sts subdomain. It contains version, mode, max_age and one mx line per mail host. - DNS record: a TXT at
_mta-sts.example.comcontainingv=STSv1; id=followed by an identifier. Senders cache the policy for max_age and re-fetch only when the id changes, so update the id every time you edit the file. The generator sets a fresh date-based id on every run.
Choosing mode and max_age
| Setting | Recommendation |
|---|---|
| mode: testing | Start here. Senders report failures via TLS-RPT but still deliver. |
| mode: enforce | Switch after two clean weeks of reports. Non-compliant senders now refuse delivery. |
| mode: none | Withdraw the policy while keeping the record present. |
| max_age | 604800 (one week) in testing; 2592000 (30 days) or more once enforcing. Maximum is 31557600. |
MX lines and wildcards
List every hostname that appears in your MX records, exactly as they appear. A wildcard such as *.mailhost.com matches one label only, so it covers mx1.mailhost.com but not mx1.eu.mailhost.com. For Google Workspace the standard set is aspmx.l.google.com and the alt entries; providers publish their MTA-STS MX list in their documentation.
Pair it with TLS-RPT
Publish a _smtp._tls TXT record with v=TLSRPTv1; rua=mailto:tlsrpt@example.com. Senders will email daily JSON reports of TLS failures against your domain, which is the only way to know a testing-mode policy is safe to enforce.
Related tools
- DMARC Record Generator — Generate a correct DMARC TXT record with policy, reporting address, percentage and alignment options, with rollout guidance.
- SPF Record Checker — Check an SPF record for syntax, lookup limits and the mistakes that cause mail to fail.
- DKIM Record Checker — Look up a DKIM record by selector and check the key, syntax and common publication errors.
- TLS Cipher Strength Checker — Check TLS cipher suite strength and security configurations.
Frequently Asked Questions
Does the policy file need its own subdomain?
Yes. The file must be fetched from https://mta-sts.yourdomain and the certificate must be valid for that exact hostname. A static host, an object-storage bucket behind a CDN, or a single-file web server all work.
What happens if I change the file but not the DNS id?
Senders keep using the cached policy until max_age expires, which could be weeks. Always change the id together with the file; the generator produces a new one on every run.
Will MTA-STS block legitimate mail?
In enforce mode, mail from senders that cannot establish TLS with a valid certificate to your listed MX hosts is not delivered. Run in testing mode with TLS-RPT first to see whether any real senders would be affected.
Is MTA-STS the same as DANE?
No. DANE achieves a similar goal using DNSSEC-signed TLSA records and is stronger but requires DNSSEC. MTA-STS was designed for domains without DNSSEC and relies on HTTPS instead. You can publish both.
Do I need MTA-STS if I already have SPF, DKIM and DMARC?
They solve a different problem. SPF, DKIM and DMARC authenticate who sent a message; MTA-STS protects the transport of mail sent to you from being read or altered in transit.
Privacy & Security
Generated locally in your browser. No data is sent to any server.
How to Use
Enter your MX hosts and mode, then generate policy + DNS record.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
DMARC Record Generator
SecurityGenerate a correct DMARC TXT record with policy, reporting address, percentage and alignment options, with rollout guidance.
SPF Record Checker
SecurityCheck an SPF record for syntax, lookup limits and the mistakes that cause mail to fail.
DKIM Record Checker
SecurityLook up a DKIM record by selector and check the key, syntax and common publication errors.