Guide · Trust and delivery

MTA-STS explained: making senders encrypt mail to your domain

Mail between servers is encrypted when both sides agree to it, and an attacker can sometimes prevent the agreement. MTA-STS lets a domain say that encryption is expected. This guide explains the policy and its modes.

The problem it addresses

Servers that exchange mail negotiate encryption: the receiver announces it, the sender upgrades. An attacker positioned between them can delete the announcement, so mail travels unencrypted, or can impersonate the destination by spoofing its MX record. RFC 8461 names both attack classes.

What MTA-STS is

RFC 8461 describes MTA-STS as a mechanism that lets mail providers declare their ability to receive TLS-secured SMTP connections, and say whether sending servers should refuse to deliver to MX hosts that do not offer TLS with a trusted certificate.

Where the policy lives

The policy is a small text file served over HTTPS at a fixed path, /.well-known/mta-sts.txt, on a host whose name is mta-sts followed by the domain. Alcitron Mail serves that file for the domains it hosts, so a customer does not have to run a web server for it. The file lists the version, the mode, the permitted MX hosts, and how long senders may cache it.

The three modes

  • enforce. Senders must not deliver to a host that fails the policy. This is the goal.
  • testing. Senders report failures but still deliver, which is how a policy is introduced safely.
  • none. The policy is withdrawn.

The max_age field says how long a sender may keep the policy, up to a limit the RFC sets. A long value protects a domain between visits; a short one lets a mistake be corrected quickly.

What it does not do

MTA-STS concerns the hop between mail servers. It does not encrypt the message end to end, and it does not replace SPF, DKIM and DMARC, which are about who sent a message. It is one layer, and the service operator sets the mode.

What a business owner needs to do

Nothing for the policy file itself: it is the service’s. The practical step is to keep the domain’s MX pointing at the service’s mail host, because the policy lists that host as the only permitted one.

Questions

What does the enforce mode do?

It asks sending servers to refuse delivery to a host that does not offer TLS with a trusted certificate or that is not listed in the policy.

Where is the MTA-STS policy published?

In a text file at /.well-known/mta-sts.txt on a host named mta-sts followed by the domain, served over HTTPS.

Does MTA-STS encrypt the whole message?

No. It protects the connection between mail servers; it is not end-to-end encryption of the message.

Sources

The documents this guide’s statements rest on. Each link opens in a new page.

  1. RFC 8461: SMTP MTA Strict Transport Security (MTA-STS)