MTA-STS and TLS reporting

Email that arrives encrypted, or not at all.

Mail servers encrypt email to each other when they can, and quietly fall back to plain text when they cannot. MTA-STS tells them not to fall back. TLS reporting tells you when it happens.

Last reviewed 27 September 2026

The gap it closes

Encryption between mail servers is opportunistic. If someone on the path interferes with the connection, most servers send the message anyway, unencrypted, and neither side is told.

How MTA-STS works

Two things are published. A DNS record at _mta-sts.yourcompany.co.uk says a policy exists. The policy itself is a small text file served over HTTPS at mta-sts.yourcompany.co.uk. It names your mail servers and a mode. A sending server that supports MTA-STS fetches the policy and refuses to deliver to anything else.

HTTPS · text file · mta-sts.yourcompany.co.uk/.well-known/mta-sts.txtExample
version: STSv1
mode: enforce
mx: yourcompany-co-uk.mail.protection.outlook.com
max_age: 604800

Testing and enforce

mode: testing

Failures are reported. Mail is delivered anyway. It protects nothing.

mode: enforce

Mail is delivered over a verified, encrypted connection, or held.

Start in testing, read the reports, then move to enforce. The common mistake is never coming back: in our scan of 200 English housing associations, 13% published MTA-STS at all.

Source: OuterMark, UK Housing Email Security Report 2026.

TLS reporting

One DNS record at _smtp._tls.yourcompany.co.uk names an address. Sending servers post a daily report there: how many connections succeeded, how many failed, and why.

What goes wrong

Left in testing

It looks present and protects nothing.

The policy file stops answering

The certificate on mta-sts. lapsed, or the host was retired.

The mail servers changed and the policy did not

Enforce then holds your own incoming mail.

How OuterMark handles it

The free check reads the record, fetches the policy and reports its mode (checks 5, 6 and 12). On Managed DMARC, Managed MTA-STS hosts the policy and its certificate for you: two records, once. It starts in testing mode, and one of our engineers moves it to enforce. TLS reporting is included for every domain, and the portal turns each report into a cause and what to do about it. A domain that already publishes a policy is left alone until an engineer has moved it across.

Questions

Does MTA-STS encrypt the email we send?

It protects email delivered to you. Protection for what you send depends on the receiving domain's policy.

Do we need DNSSEC for this?

No. MTA-STS was designed for domains without it.

What if our mail provider changes its servers?

A hosted policy is updated for you. One you serve yourself has to be edited first.

See where your domain stands.

The free check reads these records in about 30 seconds.