KorantixKorantix

Understand what your scan results mean / MTA-STS

MTA-STS: forcing encrypted mail delivery, and why SMTP needed it

Unlike a browser connecting over HTTPS, an SMTP server delivering your email has historically had no reliable way to insist on an encrypted connection β€” MTA-STS is the record that closes that gap.

Standard SMTP mail delivery uses "opportunistic" TLS: the receiving server can advertise STARTTLS support, but if that advertisement is stripped by a network attacker in transit (a well-documented downgrade attack), the sending server has historically had no way to know encryption was supposed to happen, and silently falls back to sending the message in plaintext.

MTA-STS (Mail Transfer Agent Strict Transport Security) is a DNS TXT record plus an HTTPS-hosted policy file that tells sending servers "delivery to this domain must use TLS with a valid, trusted certificate β€” refuse to deliver if it can't." A sender that respects MTA-STS will queue or bounce a message rather than silently send it unencrypted if the destination fails the TLS requirement.

This only works if senders actually check for and respect your policy β€” support has grown substantially among major providers (Google, Microsoft, Yahoo all implement it) but it's not universal, so MTA-STS is a real improvement, not a guarantee, until adoption is complete across the ecosystem.

What to do: if you're already enforcing STARTTLS correctly (verified via Korantix's Mail Server check), MTA-STS is a natural next step β€” it turns "we support encryption" into "encryption is required, full stop" for any sender that honors the policy.

Check this on your domain β†’