MTA-STS tells sending mail servers they must use an encrypted (TLS) connection when delivering to you, which stops an attacker downgrading the connection to plain text. Setup is a TXT record plus a small policy file that you host at mta-sts.yourdomain.com, which needs its own A or CNAME record.
Set it up in ShieldMarc
Open the domain from Domains, go to Checks, choose + Add a check, then MTA-STS and Set up. The wizard reads your live MX records and gives you both pieces ready to copy.
What you publish
- A TXT record at
_mta-sts.yourdomain.comcontainingv=STSv1; id=YYYYMMDD. The id is a version marker, set to today's date. Change it whenever you edit the policy file, so receivers fetch the new one. - The policy file, served over HTTPS at
https://mta-sts.yourdomain.com/.well-known/mta-sts.txt. You also need a DNS record (A or CNAME) formta-sts.yourdomain.comthat points at wherever you host the file. The wizard does not show that record, because it depends on your host.
ShieldMarc writes the policy, you host it
We do not host the policy file for you. The wizard fills it in with your real MX hosts, so you do not have to guess the mx: lines. For Microsoft 365 or Google Workspace it looks like this, with one mx: line for each MX host:
version: STSv1mode: testingmx: your-mx-hostmax_age: 604800
If your domain has no MX records, the file has a placeholder instead. Replace it with your real MX host before you publish.
Start in testing mode
The wizard starts you in mode: testing on purpose. In testing, receivers report problems but still deliver, so a mistake cannot cost you mail. Keep it for at least two weeks, longer if a gateway or list server sits in front of your MX. Read your TLS-RPT reports, then change the file to mode: enforce and update the id.
Verifying and monitoring
Run verification checks both pieces: the TXT record, and a policy file that loads over HTTPS, lists your MX hosts and keeps max_age at a day or more. If anything is missing, it tells you exactly what, and the check can only be turned on once both are right.
Once the check is on, we test the record and the policy file every 5 minutes. The file must load over HTTPS, list every one of your MX hosts and keep max_age at a day or more. Problems show on the domain's MTA-STS check. We email you if a policy that was on enforce drops back to testing or none. Other problems, such as a missing record or a file that will not load, show on the check but do not send an email.