MTA-STS tells other mail servers to require an encrypted, certificate-validated connection when delivering mail to you. TLS-RPT gets you a report when a sender's TLS connection attempt fails. Fill this in to generate all three pieces you need to publish.
Before switching to enforce: MTA-STS also requires you to host the policy file over HTTPS at https://mta-sts.<your domain>/.well-known/mta-sts.txt with a valid certificate. Publishing the DNS records alone isn't enough; a sender that can't fetch the policy file falls back to normal, unenforced delivery.
1. TXT record at
2. Policy file: host this exact content at
3. TXT record at
Check what's live now
Uses the same live check as the domain scanner, without needing a full scan.