Short answer: Enter your domain and the MX host names that receive its mail, choose a mode and max_age, and the generator writes the _mta-sts TXT record (v=STSv1; id=…), the policy file and the exact URL where it must be hosted: https://mta-sts.yourdomain/.well-known/mta-sts.txt. Add a report address to get a matching TLS-RPT record too.
Built and tested in Chromium on 6 Oct 2026; runs entirely in your browser.
Table of Contents
How to use the MTA-STS generator
- Enter the domain that receives mail, for example
example.com. - List every MX host that receives mail for it, separated by commas. Run an MX lookup if you are not sure. A wildcard such as
*.mx.example.netis allowed. - Start with mode testing. Switch to enforce only after the reports show every sender reaches your MX over TLS.
- Choose max_age: one week is a sensible start; raise it once the policy is stable. RFC 8461 allows at most 31557600 seconds (about a year).
- Leave the policy id blank to use the current UTC time, or enter your own (letters and digits only, up to 32).
- Optionally enter a TLS-RPT address so you receive daily reports of TLS failures.
What the output means
| Output | Where it goes |
|---|---|
| TXT record name and value | DNS, at _mta-sts.example.com. The id tells senders whether the policy has changed. |
| Policy file URL | Where senders download the policy. It must be served over HTTPS with a valid certificate for mta-sts.example.com. |
| Policy file contents | The text file itself: version, mode, one mx: line per allowed MX, and max_age. |
| TLS-RPT record | Optional TXT record at _smtp._tls.example.com naming where reports go. |
| Publish it table | The order to do things in: web host first, TXT record last. |
RFC 8461 requires a 200 response with media type text/plain; senders must not follow redirects, so the file cannot be a redirect to another site.
Examples
For example.com with two MX patterns in testing mode the generator produces:
_mta-sts.example.com. TXT "v=STSv1; id=20261006120000"
# https://mta-sts.example.com/.well-known/mta-sts.txt
version: STSv1
mode: testing
mx: mail.example.com
mx: *.mx.example.net
max_age: 604800
On nginx, serve the file from the document root of the mta-sts host and set the type explicitly:
location = /.well-known/mta-sts.txt {
default_type text/plain;
}
On cPanel or DirectAdmin, create a subdomain called mta-sts, let AutoSSL or Let’s Encrypt issue its certificate, and upload the file to .well-known/mta-sts.txt in that subdomain’s document root. Then run the MTA-STS checker.
Common mistakes
- Missing an MX. In enforce mode, senders that support MTA-STS will not deliver to an MX that is not listed. Include backup MX hosts too.
- Expecting one wildcard to cover everything.
*.example.netmatches one label, such asmx1.example.net, but notexample.netora.b.example.net. - MX certificates that do not match the host name. Each MX must present a certificate valid for its own name. Test with our SMTP test.
- Changing the file without changing the id. Senders only re-fetch the policy when the id in DNS changes.
- Dropping MTA-STS by deleting the records. Senders keep the cached policy until max_age runs out. Publish mode none with a short max_age first, as RFC 8461 section 8.3 describes.
Official documentation: RFC 8461: MTA-STS · RFC 8460: SMTP TLS Reporting
Related: MTA-STS Checker · TLS-RPT Checker · SMTP Test: Free STARTTLS, Certificate and Banner Check · MX Lookup · Email Domain Health Check
See also: MTA-STS on cPanel and DirectAdmin: Policy File and TLS-RPT · TLS-RPT Record Generator: _smtp._tls TXT Record
Frequently asked questions
Where does the MTA-STS policy file go?
At https://mta-sts.yourdomain/.well-known/mta-sts.txt, served with HTTP 200, Content-Type text/plain and a valid certificate for the mta-sts host name.
Should I start in testing or enforce mode?
Testing. Senders still deliver when TLS fails but report it through TLS-RPT. Move to enforce after a week or two of clean reports.
What is the id in the MTA-STS TXT record?
A string of up to 32 letters and digits that identifies the current policy. Change it every time you edit the policy file so senders fetch the new version.
What max_age should I use?
Start with about a week (604800 seconds) and raise it once the policy is stable. The maximum allowed is 31557600 seconds.
Does MTA-STS affect mail I send?
No. It tells other servers how to deliver mail to your domain. Your outgoing mail is affected only by the recipient domain’s policy.