Definition · DNS & Email Spoofing
What is MTA-STS?
MTA-STS (Mail Transfer Agent Strict Transport Security) is an email security standard, defined in RFC 8461, that lets a domain declare that mail servers sending to it must use TLS with a valid certificate. Without MTA-STS, SMTP falls back to unencrypted delivery when TLS negotiation fails — a weakness that on-path attackers can exploit by stripping the STARTTLS capability from the connection.
How MTA-STS works
MTA-STS uses two components:
- A DNS TXT record at
_mta-sts.example.comannouncing that a policy exists and carrying a policy version identifier - A policy file served over HTTPS at
https://mta-sts.example.com/.well-known/mta-sts.txt
The policy file specifies a mode (testing, enforce, or none), the MX hostnames that are valid for the domain, and a max_age for caching. In enforce mode, sending servers that support MTA-STS must refuse to deliver mail to the domain over an unencrypted or improperly authenticated connection.
Why it matters
Opportunistic TLS for SMTP protects against passive eavesdropping only. An active attacker who can intercept traffic can force a downgrade to plaintext. MTA-STS closes this gap for inbound mail, in the same way HSTS does for web traffic.
Related standards
MTA-STS pairs with TLS-RPT, which delivers reports about TLS delivery failures, and complements the email authentication stack of SPF, DKIM, and DMARC. SurfaceLoop checks for MTA-STS records as part of its DNS and email security scans.