Free Tool - No Signup Required

MTA-STS Policy Generator

Generate MTA-STS DNS records and policy files to enforce TLS encryption for inbound email. Prevent downgrade attacks.

Policy Mode

MX Hosts

List the MX hostnames that receive email for your domain. Use wildcards like *.example.com to match subdomains.

mx:

Cache Duration (max_age)

1. DNS TXT Record

Add this TXT record at _mta-sts.yourdomain.com

v=STSv1; id=STSv1_mlvqa6ud

2. Policy File

Host this file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt

version: STSv1
mode: testing
max_age: 604800

Setup Checklist:

  1. Create a subdomain mta-sts.yourdomain.com pointing to a web server
  2. Install a valid HTTPS certificate for mta-sts.yourdomain.com
  3. Host the policy file at /.well-known/mta-sts.txt
  4. Add the DNS TXT record at _mta-sts.yourdomain.com
  5. Optionally add a TLS-RPT record for failure reporting

Frequently Asked Questions