MTA-STS Generator

Create your MTA-STS policy and DNS record in seconds. Secure your email transport with TLS.

Enter Your Domain

The domain you want to create an MTA-STS policy for

Policy Mode

How strictly to enforce TLS connections

MX Hosts

List all MX hosts that support TLS

Max Age

How long the policy should be cached

Understanding MTA-STS

What is MTA-STS?

MTA-STS (SMTP MTA Strict Transport Security) enables mail service providers to declare their ability to receive TLS-secured SMTP connections and to specify whether sending servers should refuse to deliver emails to MX hosts that don't offer TLS with a trusted certificate.

Policy Modes

testing (Monitor Mode)

Emails are delivered but TLS failures are reported. Perfect for initial setup. Start here!

enforce (Strict Mode)

Emails must be delivered over TLS or they will be rejected. Maximum security after testing period.

none (Disabled)

MTA-STS is disabled. Use this to temporarily disable the policy.

💡 Recommended Implementation Path

  1. Week 1-2: Start with mode=testing to monitor TLS support
  2. Review logs: Ensure all email delivery is working correctly
  3. Week 3+: Move to mode=enforce for maximum security
  4. Update ID: Change the ID in DNS record whenever you update the policy

Automate MTA-STS Management

Monitor your MTA-STS policy 24/7, get alerts for configuration issues, and ensure encrypted email delivery with automatic validation.

No credit card required • Free monitoring for 14 days • Setup in 5 minutes