Free diagnostic

MTA-STS checker for SMTP transport policy.

Check the MTA-STS DNS signal and HTTPS policy using bounded, redirect-free public-network requests with private-address protection.

Validate both publication surfaces

MTA-STS requires a DNS TXT signal and a policy served over HTTPS from the fixed mta-sts hostname. This tool checks both without following redirects or contacting private network addresses.

  • Start in testing mode and use TLS-RPT to observe failures.
  • Bump the DNS policy id when the HTTPS policy changes.
  • Match policy MX patterns to the domain's real receiving infrastructure.

Publication is not transport telemetry

A fetchable policy does not prove that every SMTP connection negotiated TLS successfully. Pair MTA-STS with TLS-RPT guidance and ongoing domain monitoring.

Live diagnostic

Check current evidence

This anonymous tool is rate limited and does not retain submitted input. It reports observable evidence without promising delivery, authentication alignment, or inbox placement.

No SMTP mailbox probing, account lookup, or tenant data is used.

Enter an input to see current evidence, limitations, official references, and the relevant next step.

FAQ