MTA-STS policy builder
Pick your MX hosts and a mode. We'll give you the policy file (host at mta-sts.<domain>/.well-known/mta-sts.txt) and the matching DNS TXT record.
Policy inputs
Exact hosts (mail.example.com) and wildcards (*.example.com) are both valid. Use the hosts your receiving mail provider tells you to put in MX.
Output
Valid- · Mode=testing — receivers will report failures via TLS-RPT but won't actually reject. Move to enforce once you're confident.
version: STSv1 mode: testing mx: aspmx.l.google.com mx: alt1.aspmx.l.google.com max_age: 604800
v=STSv1; id=202608121859
How MTA-STS works. MTA-STS is the “HSTS for email.” You publish a policy at mta-sts.<domain>/.well-known/mta-sts.txt over HTTPS, plus a DNS TXT record at _mta-sts.<domain>. Sending MTAs fetch the policy and refuse to deliver mail unless TLS is used and the receiver's cert matches one of the listed MX names. Pair with TLS-RPT so you find out when something breaks.
See also the SPF builder, DMARC validator, and the full email security scan.
Keep hardening your email
Each record is one layer. Check the rest of yours — every tool is free, no account.
Email security scan
Run all 8 checks at once
SPF builder
Assemble a clean SPF record
SPF analyzer
Count your real DNS lookups
DMARC generator
Build a v=DMARC1 record
DMARC validator
Grade a record you have
DMARC report analyzer
Read a rua= XML report
DKIM validator
Check a DKIM key
Header analyzer
Trace a suspicious email
Blocklist checker
Are you on a DNSBL?
BIMI check
Get your logo in inboxes
TLS-RPT
Get TLS failure reports
DMARC visibility
Ingest your rua= reports
Continuous monitoring
Catch record drift on a schedule