Short answer: Create the subdomain mta-sts.example.com in cPanel or DirectAdmin, make sure it has a valid TLS certificate, and put a plain-text file at /.well-known/mta-sts.txt in its document root containing version: STSv1, mode: testing, one mx: line per MX host and max_age. Then publish _mta-sts.example.com TXT "v=STSv1; id=..." and a TLS-RPT record at _smtp._tls.example.com. Before switching to mode: enforce, confirm every MX host presents a valid certificate for its own name.
Neither panel has a built-in MTA-STS feature: we found none in cPanel & WHM 11.138 or DirectAdmin 1.712 on our AlmaLinux 9.8 lab servers on 6 October 2026. On the same day we ran the SMTP certificate and MIME checks shown below on those servers. The policy format was checked against RFC 8461 and RFC 8460; we did not publish a live policy for a lab domain.
Table of Contents
What you are setting up
MTA-STS lets a receiving domain tell sending servers: “only deliver to these MX hosts, and only over TLS with a valid certificate”. It has three parts:
| Part | Where | Example |
|---|---|---|
| Policy indicator | TXT at _mta-sts.example.com | v=STSv1; id=202610060001 |
| Policy file | https://mta-sts.example.com/.well-known/mta-sts.txt | mode, allowed MX names, cache time |
| TLS reporting (TLS-RPT) | TXT at _smtp._tls.example.com | v=TLSRPTv1; rua=mailto:tlsrpt@example.com |
The id is 1 to 32 letters and digits. Senders cache your policy and only fetch it again when the id changes, so change it every time you edit the file.
Step 1: check your MX certificates first
In enforce mode, senders refuse to deliver if the MX host does not present a valid, unexpired certificate that matches the MX host name. Check each MX before anything else:
dig +short MX example.com
echo QUIT | openssl s_client -starttls smtp -connect mail.example.com:25 -servername mail.example.com 2>/dev/null | openssl x509 -noout -subject -issuer -enddate -ext subjectAltName
What we saw on our labs is a good warning. On DirectAdmin, Exim chose the domain’s Let’s Encrypt certificate by SNI, and it listed mail., smtp. and pop. names for the domain. On cPanel, for a domain whose own certificate was self-signed, Exim fell back to the server hostname’s certificate, which does not cover mail. that domain. A policy listing mx: mail.example.com would fail there in enforce mode.
Two ways to get a valid match on shared hosting:
- Make sure AutoSSL (cPanel) or Let’s Encrypt (DirectAdmin) issues a certificate that covers
mail.example.com, and confirm with the command above that Exim presents it. - Or point the domain’s MX at the server hostname (for example
server1.example.net), which always has a valid certificate, and list that name in the policy.
Our SMTP Test shows the certificate an MX presents, and our MX Lookup lists the MX names you must put in the policy.
Step 2: host the policy on cPanel
- In cPanel, open Domains and create
mta-sts.example.com. Note the document root cPanel assigns to it. - If the zone is hosted on the server, cPanel adds the DNS record for the new subdomain. If DNS is elsewhere (for example Cloudflare), add an A (and AAAA if used) record for
mta-stspointing to the server. - Run AutoSSL for the account, or wait for the next run, and check that
mta-sts.example.comgets a valid certificate. - In File Manager, inside that document root, create the folder
.well-known(enable “Show Hidden Files” to see it) and the filemta-sts.txt.
Step 2 (alternative): host the policy on DirectAdmin
- In DirectAdmin, open Subdomain Management for
example.comand addmta-sts. DirectAdmin creates a folder for the subdomain inside the domain’s web root; confirm the exact path in File Manager. - If DNS is local, DirectAdmin adds the record. Otherwise add an A record for
mta-stsat your DNS provider. - In SSL Certificates, request or renew the Let’s Encrypt certificate so it includes
mta-sts.example.com. - Create
.well-known/mta-sts.txtinside the subdomain’s folder.
Step 3: write the policy file
Start in testing mode with a short cache time:
version: STSv1
mode: testing
mx: mail.example.com
mx: mail2.example.com
max_age: 86400
mode:testing(report failures but deliver anyway),enforce(refuse delivery that fails), ornone(used when removing MTA-STS).mx: one line per allowed MX name. A wildcard is allowed only as the whole left-most label:*.example.commatchesmail.example.combut notexample.com.max_age: seconds senders may cache the policy, maximum 31557600 (about one year). RFC 8461 expects weeks or more once you are confident; 604800 (one week) is a common next step.
Lines may end in LF or CRLF. Apache’s mime.types on both our labs maps .txt to text/plain, which is the media type RFC 8461 says senders should check.
Policies are fetched over HTTPS and only a 200 response counts: RFC 8461 says senders must not follow 3xx redirects. A redirect to www, to a “coming soon” page or to the main site breaks the policy.
If the subdomain’s folder sits inside the main site’s public_html (the usual DirectAdmin layout), Apache also reads the parent folder’s .htaccess, so WordPress or “force www” rewrite rules can apply to the policy URL. If your test below shows a redirect, add a .htaccess file in the subdomain’s folder containing RewriteEngine Off and test again.
Step 4: publish the DNS records
_mta-sts.example.com. TXT "v=STSv1; id=202610060001"
_smtp._tls.example.com. TXT "v=TLSRPTv1; rua=mailto:tlsrpt@example.com"
Use cPanel’s Zone Editor, DirectAdmin’s DNS Management, or your external DNS provider. The TLS-RPT address receives daily JSON reports from large senders about TLS successes and failures to your MX hosts. Use a mailbox that can take attachments, or a reporting service.
Check that it worked
curl -sS -i https://mta-sts.example.com/.well-known/mta-sts.txt
dig +short TXT _mta-sts.example.com
dig +short TXT _smtp._tls.example.com
- The
curloutput must start withHTTP/1.1 200orHTTP/2 200, showcontent-type: text/plain, have nolocation:header, and print your policy. - Our MTA-STS Checker fetches the TXT record and policy and checks the MX names against your real MX records.
- Our TLS-RPT Checker validates the
_smtp._tlsrecord. - Wait a few days in testing mode and read the TLS-RPT reports. Zero failures for every MX means you can move on.
Switch to enforce, and change the policy safely
- Edit
mta-sts.txt: setmode: enforceand a longermax_age, such as 604800. - Update the
idin the_mta-stsTXT record so senders refetch. - Before you change MX hosts later, add the new MX to the policy first, update the
id, and wait at least the oldmax_agebefore removing the old MX. Senders with a cached policy will refuse an MX that is not in it. - To remove MTA-STS, publish
mode: nonewith a newidand keep it online for the full previousmax_agebefore deleting anything.
Common problems
- Certificate error on the policy host. AutoSSL or Let’s Encrypt has not covered
mta-sts.example.comyet, usually because DNS for the subdomain was missing or pointed elsewhere when validation ran. - 301 to https or www. Remove the redirect for the subdomain; senders fetch the https URL directly and will not follow it.
- Policy MX names do not match the real MX records. After a mail migration, the old policy still lists old hosts. Update the file and the
idtogether. - HTML instead of the policy. The request fell through to a CMS 404 page. Check the file is in the subdomain’s document root, not the main site’s.
- Cloudflare in front. Proxied subdomains work if Cloudflare serves a valid certificate and adds no redirect or challenge for the path. Bot challenges block policy fetches.
Official documentation: RFC 8461: SMTP MTA Strict Transport Security · RFC 8460: SMTP TLS Reporting · cPanel docs: Domains
Related: MTA-STS Checker · TLS-RPT Checker · SMTP Test: Free STARTTLS, Certificate and Banner Check · cPanel Hostname SSL: Let’s Encrypt AutoSSL Fix in WHM · DirectAdmin Old Certificate After Renewal: 3 Service Fixes
See also: MTA-STS Generator: TXT Record and Policy File · TLS-RPT Record Generator: _smtp._tls TXT Record
Frequently asked questions
Where does the MTA-STS policy file go?
At https://mta-sts.yourdomain/.well-known/mta-sts.txt, served with a valid certificate for mta-sts.yourdomain, as text/plain, with a 200 response and no redirects.
Do cPanel or DirectAdmin create MTA-STS automatically?
Not on the versions we checked (cPanel 11.138 and DirectAdmin 1.712). You create the subdomain, file and DNS records yourself.
Should I start with mode enforce?
No. Start with mode: testing and a TLS-RPT record, read the reports for a few days, then switch to enforce and change the id.
What is the maximum max_age?
RFC 8461 allows up to 31557600 seconds, about one year. Use a short value while testing and weeks or more once stable.
Do I need TLS-RPT for MTA-STS?
It is optional but strongly advised. Without it you have no view of senders that fail to connect to your MX over TLS.
Why must I change the id after editing the policy?
Senders cache the policy and only refetch it when the id in the _mta-sts TXT record changes.