Created: 2023-10-20 Fri 07:05
_mta-sts at the
mail-domain for which a policy should be definedexample.org that would be a TXT record at the
domain name _mta-sts.example.org
; <<>> DiG 9.16.44-Debian <<>> _mta-sts.microsoft.com txt [...] ;; ANSWER SECTION: _mta-sts.microsoft.com. 3564 IN TXT "v=STSv1; id=20210331000000Z;"
;
STSv1 is defined_mta-sts
signals a MTA-STS policy on the webserver with the name mta-sts
(no underscore in the name of the web-server!)mta-sts inside the mail domain
example.org, the web-server would be named
mta-sts.example.org.mta-sts.txt and is located under the
.well-known pathtext/plainexpample.org would be
https://mta-sts.example.org/.well-known/mta-sts.txtExample of a real world MTA-STS policy file
% curl https://mta-sts.microsoft.com/.well-known/mta-sts.txt version: STSv1 mode: enforce mx: *.mail.protection.outlook.com max_age: 604800
STSv1none: no policy should be enforced. This value can be used to
migrate away from an active MTA-STS policytesting: the policy is not enforced, but violations against the
policy should be reported via TLS-Reporting (TLS-RPT, RFC 8460)enforce: The MTA-STS policy must be enforced by sending MTAs,
mail can only be delivered with transport security enabled and
verified*
as the leftmost label
mx lines can existQuestions? / Answers!