Free tool · Three checks in one
Is your mail forced
over TLS?
MTA-STS closes the TLS-downgrade hole in email; TLS-RPT tells you when delivery breaks. Check both records and the policy file in one pass.
Questions, answered honestly
What problem does MTA-STS actually solve?
Email between servers is encrypted opportunistically — if a connection can't negotiate TLS, it falls back to plaintext. An attacker in the network path can force that downgrade and read your mail. MTA-STS lets your domain publish 'always require TLS for my mail', closing the downgrade hole.
What are the three pieces this checker verifies?
The _mta-sts TXT record (the signal that a policy exists and its version id), the policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt (the actual rules: mode, allowed MX hosts, max_age), and the _smtp._tls TXT record (TLS-RPT — where failure reports go).
Why can't the policy file always be fetched here?
Browsers enforce CORS, and mail-policy hosts have no reason to send CORS headers — sending mail servers aren't browsers and don't care. When the fetch is blocked we say so honestly and give you the direct URL to open yourself; a blocked fetch tells you nothing about whether the policy works for real senders.
Which mode should I publish first?
mode: testing, together with TLS-RPT. Testing mode tells senders to evaluate your policy and report failures without bouncing anything. After a couple of clean weeks of TLS reports, switch to mode: enforce.
Does MTA-STS help my cold email deliverability?
Indirectly. It protects mail coming TO your domain, so it doesn't change your sending reputation directly — but Gmail publishes and honors it, security-conscious receivers notice it, and a domain with complete mail security posture (SPF, DKIM, DMARC, MTA-STS) reads as a serious operator, not a burner.
Posture checked. Now keep it that way.
Norbelys monitors your domains' full mail posture continuously — authentication, policies and reputation — and tells you in plain language when something drifts.
Start sendingFrom $29/mo · Cancel anytime