MTA-STS check (inbound TLS enforcement)
MTA-STS tells sending servers to use secure TLS when delivering email to your domain and helps reduce downgrade attacks.
Free scan = summary. Paid report = complete hardening roadmap.
Get the PDF action plan
Includes MTA-STS and TLS-RPT implementation checklist plus core deliverability fixes.
What you need for MTA-STS
TXT policy id
Publish _mta-sts TXT with v=STSv1; id=....
HTTPS policy file
Host /.well-known/mta-sts.txt at mta-sts.yourdomain.
Valid certificate
The policy endpoint must serve HTTPS with a trusted certificate.
Complementary controls
Use SPF, DKIM and DMARC alongside MTA-STS for full protection.
Preview
Run a free scan to see the summary here...