Skip to main content

Free tools

MTA-STS checker

Enter the domain that receives mail (the domain in your MX records).

Back to Email authentication tools

What this checks

MTA-STS TXT at _mta-sts.domain, policy mode, max_age, mx host patterns, and HTTPS policy file fetch status.

Why it matters

MTA-STS tells sending MTAs to use TLS when delivering to your domain. Misconfiguration can cause delivery failures or weak transport.

Run check

Live diagnostic — results run from MailFleet tool APIs or locally in your browser.

Security verification

Required to prevent automated abuse of public tools.

Verification challenge

Results

Common issues

  • Policy file not reachable over HTTPS or wrong Content-Type.
  • MX patterns in policy do not match published MX hostnames.
  • Jumping to mode=enforce before testing TLS compatibility.

How to fix

  • Start with mode=testing and monitor TLS-RPT reports.
  • Align mx: patterns with actual MX records.
  • Move to enforce after confirming compatible sending paths.

How MailFleet helps

MailFleet focuses on outbound campaign control; MTA-STS helps teams harden inbound transport for domains they operate.

Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.

For regulatory context on commercial email in the United States, see the FTC CAN-SPAM compliance guide.

Frequently asked questions

Publish policy at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt with mode testing, enforce, or none per your rollout stage.

Get started

Prepare and control campaigns with MailFleet

Run integrated diagnostics, manage providers, and monitor campaigns from a professional desktop app.

Available on

  • Windows 10+
  • macOS 12+
  • Linux (DEB & RPM)

Same desktop experience across every platform — one workflow for your entire team.