Free MTA-STS Record & Policy Generator
MTA-STS needs two pieces published together: a DNS TXT record and a policy file hosted over HTTPS. This generates both.
How to Use the MTA-STS Generator
List your MX hosts
The same mail server hostnames you already publish in your MX records – one per line.
Choose a mode
Testing reports problems without blocking mail. Enforce rejects mail that can't negotiate TLS to a listed host.
Publish both artifacts
The DNS record and the policy file go in different places – see below – then verify with the checker.
What Each Artifact Does
DNS TXT record
A short record at _mta-sts.yourdomain.com. Its only job is to announce that a policy exists and carry the id senders use to know whether the policy file has changed.
Policy file
The actual rules – your mode and mx hosts – hosted as plain text over HTTPS at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt. This is what senders enforce against, not the DNS record.
What is an MTA-STS Record?
MTA-STS (RFC 8461) lets a domain tell other mail servers that inbound SMTP connections must use TLS – and to reject the message rather than deliver it over a downgraded or unencrypted connection. Standard opportunistic TLS (STARTTLS) can be silently stripped by an attacker on the network path; MTA-STS closes that gap by making TLS mandatory and giving senders a verified list of the domain's real mail servers before they deliver.
That's why it needs two pieces published together instead of one DNS record: the TXT record this generator builds only announces that a policy exists and carries an id senders use to detect changes; the actual rules – mode and mx hosts – live in the policy file, hosted over HTTPS. MTA-STS is often deployed alongside TLS-RPT, which reports on TLS failures instead of enforcing anything – together they cover both prevention and visibility.
MTA-STS Fields Explained
| Tag | Where | What it does | Example | Required? |
|---|---|---|---|---|
| v | DNS record | Protocol version. Must be the first tag. | v=STSv1 | Required |
| id | DNS record | Identifies the current policy. Change it whenever the policy file's content changes, or caching senders will never notice the update. | id=20261024140500Z | Required |
| version | Policy file | The policy file's own version tag, also STSv1. | version: STSv1 | Required |
| mode | Policy file | Enforcement level: none, testing, or enforce. | mode: enforce | Required |
| mx | Policy file | One line per mail server hostname senders are allowed to deliver to over TLS. | mx: mail.example.com | Required (at least one) |
| max_age | Policy file | How long, in seconds, a sender may cache this policy before re-checking. | max_age: 604800 | Required |
How to Publish & Verify
Host the policy file first, at a real HTTPS-served mta-sts subdomain with a valid certificate and no redirect. Add the DNS TXT record afterward, then confirm both sides:
DNS record, using nslookup
nslookup -type=TXT _mta-sts.yourdomain.com
DNS record, using dig
dig TXT _mta-sts.yourdomain.com
Policy file, using curl
curl https://mta-sts.yourdomain.com/.well-known/mta-sts.txt
Next Steps
Verify what you published
Confirm the DNS record resolves correctly with the free checker.
MTA-STS Checker →Add failure reporting
Pair this with a TLS-RPT record so you hear about any TLS negotiation failures MTA-STS causes or catches.
TLS-RPT Generator →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this MTA-STS generator free?
Yes – generate a DNS record and policy file for free, no signup required.
Which should I publish first, the DNS record or the policy file?
The policy file. If a sender sees the DNS record before the policy file is reachable, the fetch fails and that sender may cache the failure. Publish the file, confirm it loads over HTTPS, then add the DNS record.
What happens if I change my MX hosts later?
Update the policy file's mx lines and generate a new id – senders cache your old policy by id and won't notice a content change unless the id itself changes.
Can I skip testing mode and go straight to enforce?
You can, but it's risky – any MX host missing from your list will start bouncing mail immediately. Testing mode for a full max_age period first is the safer rollout.
Does this generator check my DNS or my server for me?
No – it only builds the text for both artifacts. Publish them yourself, then use the MTA-STS checker to confirm the DNS side.