The gap it closes
Encryption between mail servers is opportunistic. If someone on the path interferes with the connection, most servers send the message anyway, unencrypted, and neither side is told.
How MTA-STS works
Two things are published. A DNS record at _mta-sts.yourcompany.co.uk says a policy exists. The policy itself is a small text file served over HTTPS at mta-sts.yourcompany.co.uk. It names your mail servers and a mode. A sending server that supports MTA-STS fetches the policy and refuses to deliver to anything else.
version: STSv1 mode: enforce mx: yourcompany-co-uk.mail.protection.outlook.com max_age: 604800
Testing and enforce
Failures are reported. Mail is delivered anyway. It protects nothing.
Mail is delivered over a verified, encrypted connection, or held.
Start in testing, read the reports, then move to enforce. The common mistake is never coming back: in our scan of 200 English housing associations, 13% published MTA-STS at all.
Source: OuterMark, UK Housing Email Security Report 2026.
TLS reporting
One DNS record at _smtp._tls.yourcompany.co.uk names an address. Sending servers post a daily report there: how many connections succeeded, how many failed, and why.
What goes wrong
Left in testing
It looks present and protects nothing.
The policy file stops answering
The certificate on mta-sts. lapsed, or the host was retired.
The mail servers changed and the policy did not
Enforce then holds your own incoming mail.
How OuterMark handles it
The free check reads the record, fetches the policy and reports its mode (checks 5, 6 and 12). On Managed DMARC, Managed MTA-STS hosts the policy and its certificate for you: two records, once. It starts in testing mode, and one of our engineers moves it to enforce. TLS reporting is included for every domain, and the portal turns each report into a cause and what to do about it. A domain that already publishes a policy is left alone until an engineer has moved it across.
Questions
Does MTA-STS encrypt the email we send?
It protects email delivered to you. Protection for what you send depends on the receiving domain's policy.
Do we need DNSSEC for this?
No. MTA-STS was designed for domains without it.
What if our mail provider changes its servers?
A hosted policy is updated for you. One you serve yourself has to be edited first.