An MTA-STS record and the policy file it points to, built together.
MTA-STS is two pieces that have to agree: a DNS record that carries an id, and a policy file on an HTTPS host that lists your MX servers. Start in testing mode, read the TLS-RPT reports, and enforce once they are clean.
Copy them from your MX records. A wildcard such as *.example.com covers every host one level under that name, but not example.com itself.
The DNS record is the easy half.
Senders only apply a policy they can fetch. Each of these has to hold for as long as the policy is published, not only on the day you set it up.
Its own hostname
The file is fetched from mta-sts.yourdomain, which needs an A or CNAME record of its own. The parent domain's website does not count.
A certificate that stays valid
Senders validate the certificate for mta-sts.yourdomain like any HTTPS client. An expired one means the policy cannot be fetched, and enforcement quietly lapses.
Served as text/plain, with no redirect
Senders do not follow redirects, so the file must answer 200 at exactly /.well-known/mta-sts.txt with a text/plain content type.
We can host the policy file for you.
On Growth, DDMARC hosts your MTA-STS policy file and handles its HTTPS certificate, so the policy stays reachable without a web server of your own. Growth is $69 a month for up to 15 domains, with a 14-day trial.
See what Growth includesFrequently asked questions.
Senders cache your policy file and only fetch it again when the id in the _mta-sts TXT record changes. Change the id every time you change the policy, or senders keep applying the old one until its max_age runs out. This generator creates a new timestamp id on every edit.
For the full walkthrough, see the MTA-STS setup guide.
DMARC Report Analyzer
Paste or upload a DMARC aggregate (RUA) report and see total volume, pass/fail rates, and which senders are failing. Runs in your browser.
DMARC Record Generator
Create a valid DMARC record for your domain. Configure policy, reporting emails, and advanced options.
SPF Record Generator
Build an SPF record to authorize your email senders. Includes common services and DNS lookup counter.
DKIM Key and Record Generator
Generate a DKIM key pair in your browser and get the TXT record to publish. The private key never leaves your device.
TLS-RPT Record Generator
Build the _smtp._tls record that asks senders to report failed TLS connections, with email and https destinations checked.
SPF Checker
Look up a domain's SPF record, walk every include, and count DNS lookups against the limit of 10.
Domain Checker
Check your domain's email authentication setup. See your SPF, DKIM, DMARC, and MTA-STS configuration.
DMARC Checker
Look up any domain's DMARC record and get every tag explained — policy, alignment, reporting, and coverage.
DKIM Checker
Check a domain's DKIM record by selector. See the key type, size, and each tag, with quick-picks for common providers.
MTA-STS & TLS-RPT Checker
Check a domain's MTA-STS policy record and TLS-RPT reporting — the pair that forces inbound mail over TLS.
BIMI Checker
Look up a domain's BIMI record, preview the logo, and confirm the VMC and DMARC enforcement it requires.
A policy only protects you while senders can fetch it.
Once both pieces are live, the MTA-STS checker fetches the policy file over HTTPS the way a sender does and reports the mode and MX list it finds. On Growth, DDMARC serves the file and renews its certificate, so the policy stays reachable without a web server of your own.