Skip to main content
MTA-STS Setup Help — Generate and validate your MTA-STS policy for secure delivery. Try Generator →

What is RFC 8461 (MTA-STS)?

RFC 8461 defines MTA-STS (SMTP MTA Strict Transport Security), enabling domains to declare that email should only be transmitted over encrypted connections. This prevents downgrade attacks where attackers force unencrypted transmission.

MTA-STS works through policy files hosted at well known URLs, allowing sending servers to discover and cache recipient domain security requirements. Domains can specify whether TLS is required and list valid certificate hosts.

Combined with DANE (DNS-based Authentication of Named Entities), MTA-STS strengthens email encryption by ensuring connections cannot be silently downgraded. This protects against surveillance and man in the middle attacks during message transmission.

Need personalized help?

Secure your domain against downgrade attacks. Open an AI assistant with your question pre-loaded — just add your details and send.