Skip to content
Runs in your browser · nothing is sent to us

An MTA-STS record and the policy file it points to, built together.

MTA-STS is two pieces that have to agree: a DNS record that carries an id, and a policy file on an HTTPS host that lists your MX servers. Start in testing mode, read the TLS-RPT reports, and enforce once they are clean.

Policy mode

Copy them from your MX records. A wildcard such as *.example.com covers every host one level under that name, but not example.com itself.

How long senders cache the policy (max_age)

Keep it short while testing so a mistake ages out quickly. Once enforced, a week or more is usual; the maximum is about a year.

Enter your domain and at least one MX host. The DNS record and the policy file to serve appear here.
01 — Serving the policy file

The DNS record is the easy half.

Senders only apply a policy they can fetch. Each of these has to hold for as long as the policy is published, not only on the day you set it up.

01

Its own hostname

The file is fetched from mta-sts.yourdomain, which needs an A or CNAME record of its own. The parent domain's website does not count.

02

A certificate that stays valid

Senders validate the certificate for mta-sts.yourdomain like any HTTPS client. An expired one means the policy cannot be fetched, and enforcement quietly lapses.

03

Served as text/plain, with no redirect

Senders do not follow redirects, so the file must answer 200 at exactly /.well-known/mta-sts.txt with a text/plain content type.

We can host the policy file for you.

On Growth, DDMARC hosts your MTA-STS policy file and handles its HTTPS certificate, so the policy stays reachable without a web server of your own. Growth is $69 a month for up to 15 domains, with a 14-day trial.

See what Growth includes
02 — FAQ

Frequently asked questions.

Senders cache your policy file and only fetch it again when the id in the _mta-sts TXT record changes. Change the id every time you change the policy, or senders keep applying the old one until its max_age runs out. This generator creates a new timestamp id on every edit.

For the full walkthrough, see the MTA-STS setup guide.

A policy only protects you while senders can fetch it.

Once both pieces are live, the MTA-STS checker fetches the policy file over HTTPS the way a sender does and reports the mode and MX list it finds. On Growth, DDMARC serves the file and renews its certificate, so the policy stays reachable without a web server of your own.

Free plan: 2 domains, no card, no expiry · Trial: card required, billed on day 15 unless you cancel · 14-day money-back on new paid plans