Z
ZoneSanity Console v1.3.0
RFC 8461 & RFC 8460 Standards • SMTP Transport Security

MTA-STS & TLS-RPT: Enforcement of Transport Layer Security (RFC 8461)

Published by ZoneSanity Technical Engineering • IETF RFC 8461 / 8460 Specifications

1. Vulnerabilities in Opportunistic STARTTLS (RFC 3207)

By default, SMTP mail routing between Transfer Agents (MTA-to-MTA) relies on Opportunistic TLS (RFC 3207). When a sending MTA issues a STARTTLS command on port 25, a Man-in-the-Middle (MitM) attacker on the network path can strip the STARTTLS capability response or inject negotiation errors. In response, conventional MTAs silently fall back to unencrypted cleartext transmission, exposing sensitive message payloads to wiretapping.

MTA-STS (Mail Transfer Agent Strict Transport Security, RFC 8461) resolves this vulnerability by allowing domain owners to declare that inbound SMTP traffic must utilize TLS v1.2+ with valid, trusted X.509 certificates matching published MX hosts.

2. Structure of the HTTPS .well-known/mta-sts.txt Policy File

The MTA-STS policy file must be served strictly over HTTPS on the dedicated subdomain mta-sts.yourdomain.com at the standardized URI path /.well-known/mta-sts.txt.

version: STSv1
mode: enforce
mx: mail.yourdomain.com
mx: *.aspmx.l.google.com
max_age: 604800
  • mode: enforce — Mandates encrypted TLS connections and valid X.509 cert validation. If handshake fails, delivery is rejected.
  • mode: testing — Logs TLS failures without blocking mail delivery. Recommended during initial rollout.
  • max_age — Policy cache duration in seconds for sending MTAs (e.g., 604800s = 7 days).

3. Publishing DNS TXT Records & TLS-RPT Telemetry (RFC 8460)

To signal MTA-STS policy support and enable diagnostic reporting for TLS connection failures, publish the following DNS records:

1. MTA-STS Signaling DNS TXT Record
_mta-sts.yourdomain.com. IN TXT "v=STSv1; id=20261002T010101;"
2. TLS-RPT Telemetry Reporting DNS TXT Record
_smtp._tls.yourdomain.com. IN TXT "v=TLSRPTv1; rua=mailto:[email protected]"
Audit MTA-STS Policy & TLS-RPT Telemetry
Verify HTTPS reachability of mta-sts.txt policy endpoints and TLS-RPT configuration for any domain.