What is a mta-sts?
Also called: SMTP MTA Strict Transport Security
MTA-STS lets a domain declare that incoming mail must arrive over an authenticated TLS connection, published as a policy file over HTTPS. It closes a gap in SMTP where encryption is opportunistic and can be stripped by an attacker sitting between the two mail servers.
SMTP encryption is negotiated by STARTTLS, which is advertised in plaintext and therefore removable. An attacker able to modify traffic can strip the advertisement and the sending server will silently fall back to sending in the clear, because the alternative is not delivering at all.
MTA-STS removes the fallback. The policy is published at a well-known HTTPS URL on the domain and names the valid MX hostnames, so a sending server that supports it will refuse to deliver over an unauthenticated connection rather than downgrade.
It is a receiving-side control, unlike SPF, DKIM and DMARC which protect your outbound identity. Adoption is far from universal, so treat it as hardening rather than a deliverability lever — it will not change inbox placement.
Last reviewed 2026-09-11