# MTA-STS on cPanel and DirectAdmin: Policy File and TLS-RPT

Source: https://srvscripts.com/guides/mta-sts-cpanel-directadmin/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Create the subdomain `mta-sts.example.com` in cPanel or DirectAdmin, make sure it has a valid TLS certificate, and put a plain-text file at `/.well-known/mta-sts.txt` in its document root containing `version: STSv1`, `mode: testing`, one `mx:` line per MX host and `max_age`. Then publish `_mta-sts.example.com TXT "v=STSv1; id=..."` and a TLS-RPT record at `_smtp._tls.example.com`. Before switching to `mode: enforce`, confirm every MX host presents a valid certificate for its own name.

Neither panel has a built-in MTA-STS feature: we found none in cPanel & WHM 11.138 or DirectAdmin 1.712 on our AlmaLinux 9.8 lab servers on 6 October 2026. On the same day we ran the SMTP certificate and MIME checks shown below on those servers. The policy format was checked against RFC 8461 and RFC 8460; we did not publish a live policy for a lab domain.

## What you are setting up

MTA-STS lets a receiving domain tell sending servers: “only deliver to these MX hosts, and only over TLS with a valid certificate”. It has three parts:

| Part | Where | Example |
| --- | --- | --- |
| Policy indicator | TXT at _mta-sts.example.com | v=STSv1; id=202610060001 |
| Policy file | https://mta-sts.example.com/.well-known/mta-sts.txt | mode, allowed MX names, cache time |
| TLS reporting (TLS-RPT) | TXT at _smtp._tls.example.com | v=TLSRPTv1; rua=mailto:tlsrpt@example.com |

The `id` is 1 to 32 letters and digits. Senders cache your policy and only fetch it again when the `id` changes, so change it every time you edit the file.

## Step 1: check your MX certificates first

In `enforce` mode, senders refuse to deliver if the MX host does not present a valid, unexpired certificate that matches the MX host name. Check each MX before anything else:

```
dig +short MX example.com
echo QUIT | openssl s_client -starttls smtp -connect mail.example.com:25 -servername mail.example.com 2>/dev/null | openssl x509 -noout -subject -issuer -enddate -ext subjectAltName
```

What we saw on our labs is a good warning. On DirectAdmin, Exim chose the domain’s Let’s Encrypt certificate by SNI, and it listed `mail.`, `smtp.` and `pop.` names for the domain. On cPanel, for a domain whose own certificate was self-signed, Exim fell back to the server hostname’s certificate, which does not cover `mail.` that domain. A policy listing `mx: mail.example.com` would fail there in enforce mode.

Two ways to get a valid match on shared hosting:

- Make sure AutoSSL (cPanel) or Let’s Encrypt (DirectAdmin) issues a certificate that covers `mail.example.com`, and confirm with the command above that Exim presents it.

- Or point the domain’s MX at the server hostname (for example `server1.example.net`), which always has a valid certificate, and list that name in the policy.

Our [SMTP Test](/tools/smtp-test/) shows the certificate an MX presents, and our [MX Lookup](/tools/mx-lookup/) lists the MX names you must put in the policy.

## Step 2: host the policy on cPanel

- In cPanel, open **Domains** and create `mta-sts.example.com`. Note the document root cPanel assigns to it.

- If the zone is hosted on the server, cPanel adds the DNS record for the new subdomain. If DNS is elsewhere (for example Cloudflare), add an A (and AAAA if used) record for `mta-sts` pointing to the server.

- Run AutoSSL for the account, or wait for the next run, and check that `mta-sts.example.com` gets a valid certificate.

- In **File Manager**, inside that document root, create the folder `.well-known` (enable “Show Hidden Files” to see it) and the file `mta-sts.txt`.

## Step 2 (alternative): host the policy on DirectAdmin

- In DirectAdmin, open **Subdomain Management** for `example.com` and add `mta-sts`. DirectAdmin creates a folder for the subdomain inside the domain’s web root; confirm the exact path in File Manager.

- If DNS is local, DirectAdmin adds the record. Otherwise add an A record for `mta-sts` at your DNS provider.

- In **SSL Certificates**, request or renew the Let’s Encrypt certificate so it includes `mta-sts.example.com`.

- Create `.well-known/mta-sts.txt` inside the subdomain’s folder.

## Step 3: write the policy file

Start in testing mode with a short cache time:

```
version: STSv1
mode: testing
mx: mail.example.com
mx: mail2.example.com
max_age: 86400
```

- `mode`: `testing` (report failures but deliver anyway), `enforce` (refuse delivery that fails), or `none` (used when removing MTA-STS).

- `mx`: one line per allowed MX name. A wildcard is allowed only as the whole left-most label: `*.example.com` matches `mail.example.com` but not `example.com`.

- `max_age`: seconds senders may cache the policy, maximum 31557600 (about one year). RFC 8461 expects weeks or more once you are confident; 604800 (one week) is a common next step.

Lines may end in LF or CRLF. Apache’s `mime.types` on both our labs maps `.txt` to `text/plain`, which is the media type RFC 8461 says senders should check.

Policies are fetched over HTTPS and only a 200 response counts: RFC 8461 says senders must not follow 3xx redirects. A redirect to www, to a “coming soon” page or to the main site breaks the policy.

If the subdomain’s folder sits inside the main site’s `public_html` (the usual DirectAdmin layout), Apache also reads the parent folder’s `.htaccess`, so WordPress or “force www” rewrite rules can apply to the policy URL. If your test below shows a redirect, add a `.htaccess` file in the subdomain’s folder containing `RewriteEngine Off` and test again.

## Step 4: publish the DNS records

```
_mta-sts.example.com.   TXT  "v=STSv1; id=202610060001"
_smtp._tls.example.com. TXT  "v=TLSRPTv1; rua=mailto:tlsrpt@example.com"
```

Use cPanel’s **Zone Editor**, DirectAdmin’s **DNS Management**, or your external DNS provider. The TLS-RPT address receives daily JSON reports from large senders about TLS successes and failures to your MX hosts. Use a mailbox that can take attachments, or a reporting service.

## Check that it worked

```
curl -sS -i https://mta-sts.example.com/.well-known/mta-sts.txt
dig +short TXT _mta-sts.example.com
dig +short TXT _smtp._tls.example.com
```

- The `curl` output must start with `HTTP/1.1 200` or `HTTP/2 200`, show `content-type: text/plain`, have no `location:` header, and print your policy.

- Our [MTA-STS Checker](/tools/mta-sts-checker/) fetches the TXT record and policy and checks the MX names against your real MX records.

- Our [TLS-RPT Checker](/tools/tls-rpt-checker/) validates the `_smtp._tls` record.

- Wait a few days in testing mode and read the TLS-RPT reports. Zero failures for every MX means you can move on.

## Switch to enforce, and change the policy safely

- Edit `mta-sts.txt`: set `mode: enforce` and a longer `max_age`, such as 604800.

- Update the `id` in the `_mta-sts` TXT record so senders refetch.

- Before you change MX hosts later, add the new MX to the policy first, update the `id`, and wait at least the old `max_age` before removing the old MX. Senders with a cached policy will refuse an MX that is not in it.

- To remove MTA-STS, publish `mode: none` with a new `id` and keep it online for the full previous `max_age` before deleting anything.

## Common problems

- **Certificate error on the policy host.** AutoSSL or Let’s Encrypt has not covered `mta-sts.example.com` yet, usually because DNS for the subdomain was missing or pointed elsewhere when validation ran.

- **301 to https or www.** Remove the redirect for the subdomain; senders fetch the https URL directly and will not follow it.

- **Policy MX names do not match the real MX records.** After a mail migration, the old policy still lists old hosts. Update the file and the `id` together.

- **HTML instead of the policy.** The request fell through to a CMS 404 page. Check the file is in the subdomain’s document root, not the main site’s.

- **Cloudflare in front.** Proxied subdomains work if Cloudflare serves a valid certificate and adds no redirect or challenge for the path. Bot challenges block policy fetches.

**Official documentation:** [RFC 8461: SMTP MTA Strict Transport Security](https://datatracker.ietf.org/doc/html/rfc8461) · [RFC 8460: SMTP TLS Reporting](https://datatracker.ietf.org/doc/html/rfc8460) · [cPanel docs: Domains](https://docs.cpanel.net/cpanel/domains/domains/)

**Related:** [MTA-STS Checker](/tools/mta-sts-checker/) · [TLS-RPT Checker](/tools/tls-rpt-checker/) · [SMTP Test: Free STARTTLS, Certificate and Banner Check](/tools/smtp-test/) · [cPanel Hostname SSL: Let’s Encrypt AutoSSL Fix in WHM](/guides/cpanel-hostname-ssl-lets-encrypt/) · [DirectAdmin Old Certificate After Renewal: 3 Service Fixes](/guides/directadmin-old-certificate-exim-dovecot/)

**See also:** [MTA-STS Generator: TXT Record and Policy File](/tools/mta-sts-generator/) · [TLS-RPT Record Generator: _smtp._tls TXT Record](/tools/tls-rpt-generator/)

## Frequently asked questions

### Where does the MTA-STS policy file go?

At https://mta-sts.yourdomain/.well-known/mta-sts.txt, served with a valid certificate for mta-sts.yourdomain, as text/plain, with a 200 response and no redirects.

### Do cPanel or DirectAdmin create MTA-STS automatically?

Not on the versions we checked (cPanel 11.138 and DirectAdmin 1.712). You create the subdomain, file and DNS records yourself.

### Should I start with mode enforce?

No. Start with mode: testing and a TLS-RPT record, read the reports for a few days, then switch to enforce and change the id.

### What is the maximum max_age?

RFC 8461 allows up to 31557600 seconds, about one year. Use a short value while testing and weeks or more once stable.

### Do I need TLS-RPT for MTA-STS?

It is optional but strongly advised. Without it you have no view of senders that fail to connect to your MX over TLS.

### Why must I change the id after editing the policy?

Senders cache the policy and only refetch it when the id in the _mta-sts TXT record changes.
