Validate both publication surfaces
MTA-STS requires a DNS TXT signal and a policy served over HTTPS from the fixed mta-sts hostname. This tool checks both without following redirects or contacting private network addresses.
- Start in testing mode and use TLS-RPT to observe failures.
- Bump the DNS policy id when the HTTPS policy changes.
- Match policy MX patterns to the domain's real receiving infrastructure.