Skip to content

Free tool · Three checks in one

Is your mail forced
over TLS?

MTA-STS closes the TLS-downgrade hole in email; TLS-RPT tells you when delivery breaks. Check both records and the policy file in one pass.

DNS over encrypted DNS-over-HTTPS, straight from your browser.

Questions, answered honestly

What problem does MTA-STS actually solve?

Email between servers is encrypted opportunistically — if a connection can't negotiate TLS, it falls back to plaintext. An attacker in the network path can force that downgrade and read your mail. MTA-STS lets your domain publish 'always require TLS for my mail', closing the downgrade hole.

What are the three pieces this checker verifies?

The _mta-sts TXT record (the signal that a policy exists and its version id), the policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt (the actual rules: mode, allowed MX hosts, max_age), and the _smtp._tls TXT record (TLS-RPT — where failure reports go).

Why can't the policy file always be fetched here?

Browsers enforce CORS, and mail-policy hosts have no reason to send CORS headers — sending mail servers aren't browsers and don't care. When the fetch is blocked we say so honestly and give you the direct URL to open yourself; a blocked fetch tells you nothing about whether the policy works for real senders.

Which mode should I publish first?

mode: testing, together with TLS-RPT. Testing mode tells senders to evaluate your policy and report failures without bouncing anything. After a couple of clean weeks of TLS reports, switch to mode: enforce.

Does MTA-STS help my cold email deliverability?

Indirectly. It protects mail coming TO your domain, so it doesn't change your sending reputation directly — but Gmail publishes and honors it, security-conscious receivers notice it, and a domain with complete mail security posture (SPF, DKIM, DMARC, MTA-STS) reads as a serious operator, not a burner.

Posture checked. Now keep it that way.

Norbelys monitors your domains' full mail posture continuously — authentication, policies and reputation — and tells you in plain language when something drifts.

Start sending

From $29/mo · Cancel anytime