Hosted MTA-STS

MTA-STS hosted for you: the record, the policy file and the certificate.

MTA-STS tells senders to deliver your mail only to your named MX hosts, over verified TLS. It needs a DNS record, a policy file on an HTTPS host with a valid certificate, and an id that changes with every edit. Point two names at us and we run all three.

Create your account Hosted DMARC works the same way

MX list read from your DNS · Testing before enforce · Fails open

The hosted MTA-STS card in enforce mode: the live badge, the mode control, and the two MX hosts read from DNS. The hosted MTA-STS card in enforce mode: the live badge, the mode control, and the two MX hosts read from DNS.
The hosted MTA-STS card for a domain in enforce. The mode is one control, and the MX hosts under it come from the domain's own DNS.
Setup

Setup is two CNAMEs

MTA-STS has two halves, and both have to be delegated or the policy still needs a hand edit every time it changes.

STEP 1

Switch to hosted MTA-STS

On the domain's MTA-STS page, press Switch to hosted MTA-STS. We read your MX hosts from DNS at that moment and write the first policy in testing mode.

STEP 2

Publish two CNAMEs

_mta-sts for the record and mta-sts for the policy host. We give you both values, and the card watches until both resolve.

STEP 3

Confirm the MX list, then enforce

Check the hosts on the card against what receives your mail. Press Refresh from DNS if they've changed. Then move the mode to enforce.

What you get

The record, the file and the certificate

We serve every piece a sender checks, at your own hostnames.

Served at your own hostnames

The TXT at _mta-sts, the policy file at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt, and a certificate valid for that hostname. You publish two CNAMEs and we run the rest.

The id changes on every edit

Senders re-fetch the policy only when the record's id changes. Every edit you save bumps it, so a policy change reaches senders without a hand edit that someone can forget.

Your MX hosts, from your DNS

The policy's mx lines come from your live MX records and sit on the card for you to confirm. Add a mail host, press Refresh from DNS, and the policy follows.

Testing first

In testing, every message still delivers even when a check fails. Moving to enforce before the policy is live asks you to confirm, because senders hold to the MX list the moment they can fetch it.

How long senders cache the policy

The policy caches for one day in testing and two weeks in enforce. The card says so under How serving works, because an enforce mistake can take two weeks to leave every sender's cache.

Back to testing in one save

Drop the mode back to testing the moment enforce breaks a relay. The id bumps, and senders that re-check pick the change up at once.

When something fails

What happens if we're unreachable

If our DNS or the policy host is unreachable

Senders keep the policy they cached, and once it expires they fall back to ordinary TLS. Your mail still delivers. A missing policy costs the protection and nothing else, and hosting it with us keeps that.

If your plan lapses

The record and the policy keep serving exactly as they stand. Only the mode control locks. Stop hosting and the card hands you the record and the policy text to publish yourself.

Leaving

Stop hosting whenever you want

To drop MTA-STS, delete the two CNAMEs. Senders fall back to ordinary TLS when their cached policy expires. To keep it self-managed, publish your own TXT with a new id, serve your own policy file at mta-sts.yourdomain.com, and delete both CNAMEs last. We keep answering both names until you remove them, and for twenty days after that we retire the records and the certificate.

Plans

Part of Pro and Team

Hosted MTA-STS comes with the paid plans, beside the monitoring they're built on: the Monday digest, same-day alerts, and the sender evidence behind every verdict. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, no card.

Read the full plan table

FAQ

Questions people ask first

What is MTA-STS?

A policy your domain publishes to tell every sending mail server two things: use TLS to reach me, and here are the only hosts allowed to receive my mail. Without it, a sender that can't negotiate TLS falls back to plaintext, and anyone on the path can make that happen on purpose.

Do I need it if I use Google Workspace or Microsoft 365?

The policy is published by your domain, whichever provider receives the mail. Both providers' MX hosts speak TLS, so the policy names those hosts and senders hold to them. Neither provider publishes the policy for you.

What's the difference between testing and enforce?

In testing, every message still delivers, even when a check fails. In enforce, a sender refuses to deliver to a host that isn't on your MX list or can't present a valid certificate. Start in testing, confirm the MX list, then enforce.

Why is hosting the policy the hard part?

The file has to sit on an HTTPS host named mta-sts.yourdomain.com, with a certificate for that exact name renewed before it expires, and the DNS record's id has to change every time the file does. That's a web server and a certificate kept alive for one text file. We run it for you.

What about TLS-RPT?

TLS-RPT is the reporting half: a TXT at _smtp._tls that tells senders where to mail their TLS failure reports. We don't read those reports today, so we don't publish that record for you. Point it at any collector you already use.

What happens if DomainCanary is down?

Senders keep the policy they cached, and when it expires they fall back to ordinary TLS. Your mail still delivers. MTA-STS fails open by design, and hosting it with us keeps that.

How long does an enforce mistake last?

The policy caches for one day in testing and two weeks in enforce. Drop back to testing and the id bumps, so senders that re-check pick the change up at once. A sender that doesn't re-check keeps enforcing until its cached copy expires.

What does it cost?

It's part of Pro and Team. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, and the trial needs no card.

Publish two CNAMEs and stop running a web server for one text file

We read your MX hosts, write the policy in testing, and carry the certificate for your own hostname. You confirm the list and pick the mode.

First domain free · 14 days of every paid feature · No card

  • The record, the policy file and the certificate, at your names
  • The id bumps on every edit, so senders see the change
  • Testing first, enforce on confirmation, back in one save
  • Fails open: senders fall back to ordinary TLS