Free Tool - No Signup Required
MTA-STS Policy Generator
Generate MTA-STS DNS records and policy files to enforce TLS encryption for inbound email. Prevent downgrade attacks.
Policy Mode
MX Hosts
List the MX hostnames that receive email for your domain. Use wildcards like *.example.com to match subdomains.
mx:
Cache Duration (max_age)
1. DNS TXT Record
Add this TXT record at _mta-sts.yourdomain.com
v=STSv1; id=STSv1_mlvqa6ud
2. Policy File
Host this file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt
version: STSv1 mode: testing max_age: 604800
Setup Checklist:
- Create a subdomain
mta-sts.yourdomain.compointing to a web server - Install a valid HTTPS certificate for
mta-sts.yourdomain.com - Host the policy file at
/.well-known/mta-sts.txt - Add the DNS TXT record at
_mta-sts.yourdomain.com - Optionally add a TLS-RPT record for failure reporting