LearnMTA-STS
MTA-STS

MTA-STS — Mail Transfer Agent Strict Transport Security

How MTA-STS enforces encrypted TLS connections for email delivery and prevents downgrade attacks.

What is MTA-STS?

MTA-STS (Mail Transfer Agent Strict Transport Security) is an email security standard defined in RFC 8461. It allows domain owners to declare that their mail servers support TLS encryption and that sending mail servers should refuse to deliver email if a secure TLS connection cannot be established. It is designed to prevent downgrade attacks and SMTP man-in-the-middle attacks.

The Problem MTA-STS Solves

By default, SMTP uses opportunistic TLS — it will attempt TLS but fall back to unencrypted delivery if TLS fails or is not supported. An attacker performing a man-in-the-middle attack can strip TLS from an SMTP connection and intercept email in plaintext.


MTA-STS solves this by telling sending servers: "Our mail servers always support TLS. If you cannot establish a valid TLS connection to us, do not deliver the email at all."

How MTA-STS Works

1. The domain publishes a DNS TXT record at _mta-sts.{domain} with a policy ID.

2. The domain also hosts a policy file at https://mta-sts.{domain}/.well-known/mta-sts.txt over HTTPS.

3. When a sending server looks up MX records for the domain, it also checks for an MTA-STS DNS record.

4. If found, it fetches the policy file and caches it for the duration specified.

5. For subsequent deliveries, even if DNS is tampered with, the cached policy enforces TLS.

6. If TLS cannot be established to the listed MX hosts, the message is not delivered.

MTA-STS DNS Record & Policy File

DNS record at _mta-sts.{domain}:

_mta-sts.example.com IN TXT "v=STSv1; id=20240101000000"

The id= value must change whenever the policy file is updated.


Policy file at https://mta-sts.{domain}/.well-known/mta-sts.txt:

version: STSv1mode: enforcemx: mail.example.commx: *.example.commax_age: 604800

Modes:

• testing — report only, do not block delivery

• enforce — block delivery on TLS failure

• none — disable the policy

MTA-STS vs. DANE

DANE (DNS-based Authentication of Named Entities) is an alternative standard that also enforces TLS for SMTP, but uses DNSSEC to bind TLS certificates to DNS records. DANE is more technically robust but requires DNSSEC deployment, which is complex.


MTA-STS works without DNSSEC, making it easier to deploy. The tradeoff is that MTA-STS relies on HTTPS (Certificate Authority trust) for the policy file, so it's only as secure as the CA ecosystem. Most organizations deploy MTA-STS because it's practical and widely supported by major providers like Gmail and Outlook.

MTA-STS Best Practices

1. Start with mode: testing to monitor without affecting delivery.

2. Pair with TLS-RPT to receive failure reports while in testing mode.

3. Update the id= in the DNS record every time you change the policy file.

4. Ensure your MX hosts have valid, publicly-trusted TLS certificates.

5. Set max_age to 604800 (1 week) while testing, increase to 86400*30 in enforce mode.