1 min read

What is MTA-STS

What is MTA-STS

Increase email security by turning on MTA Strict Transport Security (MTA-STS) for your domain. MTA-STS improves email security by requiring authentication checks and encryption for email sent to your domain. Use Transport Layer Security (TLS) reporting to get information about external server connections to your domain.

Like all mail providers, email uses Simple Mail Transfer Protocol (SMTP) to send and receive messages. SMTP alone does not provide security, and many SMTP servers don’t have added security to prevent malicious attacks.

For example, SMTP is vulnerable to man-in-the-middle attacks. Man-in-the-middle is an attack where communication between two servers is intercepted and possibly changed without detection. Using MTA-STS to secure mail server connections helps prevent these types of attacks.

Learn more about MTA-STS (RFC 8461) and TLS Reporting (RFC 8460)

MTA-STS email security

SMTP connections for email are more secure when the sending server supports MTA-STS and the receiving server has an MTA-STS policy in enforced mode.

Receiving mail: When you turn on MTA-STS for your domain, you request external mail servers to send messages to your domain only when the SMTP connection is both:

  • Authenticated with a valid public certificate
  • Encrypted with TLS 1.2 or higher

Mail servers that support MTA-STS will send messages to your domain only over connections that have both authentication and encryption.

Sending mail: Email messages from your domain comply with MTA-STS when sent to external servers with an MTA-STS policy in enforced mode.

TLS reporting

When you turn on TLS reporting, you request daily reports from external mail servers that connect to your domain. The reports have information about any connection problems the external servers find when sending mail to your domain. Use report data to identify and fix security issues with your mail server.

Uncovering the Latest CUPS Vulnerability

Uncovering the Latest CUPS Vulnerability

Intro In the realm of IT and network management, vulnerabilities are a constant concern for professionals tasked with maintaining secure systems. One...

Read More
Your PCI DSS Compliance Checklist Guide

Your PCI DSS Compliance Checklist Guide

Intro Navigating the complexities of PCI DSS compliance can be daunting for businesses that handle cardholder data. This comprehensive PCI DSS...

Read More
Unlocking the Potential of A.I. in Cyber Security

Unlocking the Potential of A.I. in Cyber Security

Intro In today's digital age, the importance of cyber security cannot be overstated. With the increasing number of cyber threats and attacks,...

Read More
What is SPF

What is SPF

SPF is a standard email authentication method. SPF helps protect your domain against spoofing, and helps prevent your outgoing messages from being...

Read More
What is DMARC

What is DMARC

DMARC is a standard email authentication method. DMARC helps mail administrators prevent hackers and other attackers from spoofing their organization...

Read More
What is BIMI

What is BIMI

Brand Indicators for Message Identification (BIMI) is an email standard that lets you add a brand logo to authenticated messages sent from your...

Read More