MTA-STS & TLS-RPT Checker
Check whether a domain publishes an MTA-STS policy record and TLS-RPT reporting — the pair that forces inbound mail to your servers over TLS and reports failures.
Checks the _mta-sts and _smtp._tlsTXT records over DNS-over-HTTPS. The policy file itself is served from your domain and can't be read cross-origin — open the link below to verify it.
About MTA-STS
It takes three parts
A _mta-sts TXT record, a policy file at mta-sts.yourdomain over HTTPS, and (ideally) a _smtp._tlsTLS-RPT record. Miss one and it won't enforce.
Start in testing mode
Set the policy to mode: testing first and watch TLS-RPT. Move to enforce once you confirm no legitimate senders are affected.
We host MTA-STS for you
Serving the policy file over HTTPS with a valid cert is the part teams get stuck on. DDMARC hosts your MTA-STS policy (and TLS-RPT) on managed infrastructure — no web server to maintain.
More free tools
DMARC Report Analyzer
Paste or upload a DMARC aggregate (RUA) report and see total volume, pass/fail rates, and which senders are failing. Runs in your browser.
Use ToolDMARC Record Generator
Create a valid DMARC record for your domain. Configure policy, reporting emails, and advanced options.
Use ToolSPF Record Generator
Build an SPF record to authorize your email senders. Includes common services and DNS lookup counter.
Use ToolDomain Checker
Check your domain's email authentication setup. See your SPF, DKIM, DMARC, and MTA-STS configuration.
Use ToolDMARC Record Lookup
Look up any domain's DMARC record and get every tag explained — policy, alignment, reporting, and coverage.
Use ToolDKIM Record Checker
Check a domain's DKIM record by selector. See the key type, size, and each tag, with quick-picks for common providers.
Use ToolBIMI Record Checker
Look up a domain's BIMI record, preview the logo, and confirm the VMC and DMARC enforcement it requires.
Use Tool