Sign in Check my email
Email authentication

MTA-STS Checker

Check whether a domain requires encrypted delivery of inbound mail, and whether the policy file it points at is actually being served.

Free, and no account needed. We read public DNS only.
About this tool. MTA-STS tells sending servers they must use verified TLS when delivering to you, blocking downgrade and man-in-the-middle attacks. It needs both a DNS record and a policy file — this check validates the pair together.

Ten signals decide whether your mail arrives. You just checked one.

MTA-STS protects the mail arriving at you. It says nothing about whether the mail leaving you is trusted, which is decided by SPF, DKIM and DMARC.

Run the full checkup free
No card, and nothing to cancel.

How to read your MTA-STS setup

Common problems and how to fix them

MTA-STS record present but not enforced
Confirm the HTTPS policy file exists at the mta-sts subdomain and lists the correct MX hosts, with mode set to enforce.
TLS-RPT CheckSPF CheckDKIM CheckDMARC CheckFull email checkup
Common questions.
What is MTA-STS?

A standard that lets a domain require encrypted (TLS) delivery of inbound mail, closing a gap where attackers could force plaintext.

Is MTA-STS required?

No, but it hardens inbound mail against downgrade attacks. Pair it with TLS-RPT to get reports when encryption fails.