How a sending server uses MTA-STS.
- It looks up the TXT record at
_mta-sts.yourdomain:v=STSv1; id=…. No record means no policy. - It fetches the policy over HTTPS from
https://mta-sts.yourdomain/.well-known/mta-sts.txt. The certificate must be valid for that exact name, the answer must be 200 with no redirect, and the file should betext/plain. - It keeps the policy for
max_ageseconds (at most 31557600, one year) and fetches it again only when the id in the TXT record changes. - Before each delivery it checks that the MX host matches an
mx:line (*.example.comcovers one label, such as mail.example.com) and that the host offers TLS with a valid certificate.
Testing, enforce, none.
- testing: senders deliver even when TLS fails and send you a report. Safe to start with.
- enforce: senders refuse to deliver unless TLS succeeds. This is the mode that protects mail.
- none: switches the policy off. To remove MTA-STS, publish mode none with a small max_age and a new id, wait until the old max_age has passed, then delete the record and the file.
Changing mail providers safely.
Add the new provider's mail servers to the mx: lines, then change the id (file first, record second), wait for the old max_age to pass, then switch the MX records. In enforce mode, switching MX first makes senders that cached the old policy refuse your mail.
What this checker cannot test.
The last step, the STARTTLS handshake with each mail server on port 25, needs a connection that Cloudflare Workers, where Hivex runs, cannot open. Your TLS reports (_smtp._tls) show any failure there from the senders' side.
Questions people ask.
What is MTA-STS?
A policy that tells other mail servers to deliver mail to your domain only over encrypted TLS, only to the mail servers you list, and only when their certificate is valid. Without it, an attacker on the path can strip the encryption and the mail goes through in plain text.
How do I set up MTA-STS?
Publish a TXT record at _mta-sts.yourdomain with v=STSv1 and an id, serve a policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt that lists your mail servers, and add a TLS reporting record at _smtp._tls.yourdomain. The checker drafts all three from your MX records.
What is the difference between testing and enforce mode?
In testing mode, senders still deliver when TLS fails and only report it. In enforce mode they refuse to deliver unless TLS succeeds with a valid certificate. Start in testing, read the reports, then switch to enforce.
Why does my MTA-STS policy fail?
The usual causes are a policy host without a valid HTTPS certificate for mta-sts.yourdomain, a policy URL that redirects, a mail server missing from the mx lines, or a TXT record without a valid id.
Do I need TLS reporting (TLS-RPT)?
It is optional, but it belongs with MTA-STS: senders send a daily report of TLS failures to the address in your _smtp._tls record, so you see problems before you enforce the policy.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
More Email tools
- Email deliverability checkerMX, SPF, DKIM, DMARC, MTA-STS, TLS reporting and BIMI in one report.
- SPF checkerEvery include followed, the 10-lookup limit counted, mistakes named.
- DKIM checkerFinds keys at common selectors and checks their type and size.
- DMARC checkerPolicy, alignment and report addresses, checked and explained.
- SPF generatorPick your mail services, get one record that stays under 10 lookups.
- DMARC generatorPolicy, reports and alignment, with a safe rollout path.
- BIMI checkerRecord, DMARC, SVG logo and VMC or CMC, with a preview.
- Email blacklist checkerAn IP or a domain against live email blocklists.
- Email header analyzerWho sent it, SPF, DKIM, DMARC and every hop, in your browser.
- SMTP testGreeting, STARTTLS and sign-in methods on 587 and 465.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- RFC 8461: SMTP MTA Strict Transport Security (MTA-STS)
- RFC 8460: SMTP TLS reporting
- RFC 6125: Checking a server's name against its certificate
By Hivex. Updated 10 October 2026. DNS is read live through Cloudflare's public resolver; policy files, logos and certificates are fetched live over HTTPS and never stored.