Skip to content
Free Tool

MTA-STS & TLS-RPT Checker

Check whether a domain publishes an MTA-STS policy record and TLS-RPT reporting — the pair that forces inbound mail to your servers over TLS and reports failures.

Checks the _mta-sts and _smtp._tlsTXT records over DNS-over-HTTPS. The policy file itself is served from your domain and can't be read cross-origin — open the link below to verify it.

About MTA-STS

It takes three parts

A _mta-sts TXT record, a policy file at mta-sts.yourdomain over HTTPS, and (ideally) a _smtp._tlsTLS-RPT record. Miss one and it won't enforce.

Start in testing mode

Set the policy to mode: testing first and watch TLS-RPT. Move to enforce once you confirm no legitimate senders are affected.

We host MTA-STS for you

Serving the policy file over HTTPS with a valid cert is the part teams get stuck on. DDMARC hosts your MTA-STS policy (and TLS-RPT) on managed infrastructure — no web server to maintain.