Created: 2023-10-31 Tue 12:17
_smtp._tls at the mail domain. For the mail-domain
example.org the domain name for the TXT record would be
_smtp._tls.example.org.TLSRPTv1
; <<>> DiG 9.16.44-Debian <<>> _smtp._tls.google.com txt [...] ;; ANSWER SECTION: _smtp._tls.google.com. 360 IN TXT "v=TLSRPTv1;rua=mailto:sts-reports@google.com"
application/tlsrpt+json mime type)no-policy-found if neither DANE nor MTA-STS have been
found
| Reported failure | Description |
|---|---|
| starttls-not-supported | Receiver does not offer STARTTLS |
| certificate-host-mismatch | Domain name(s) in the receiving MTA certificate do not match the DNS name of the MTA |
| certificate-expired | The certificate is expired |
| certificate-not-trusted | The certificate does not contain a valid trust chain towards a trusted root CA |
| validation-failure | The certificate could not be validated |
| Reported failure | Description |
|---|---|
| tlsa-invalid | The TLSA record found in DNS is invalid |
| dnssec-invalid | The DNSSEC validation on the TLSA record failed |
| dane-required | The sending MTA is configured to require mandatory DANE security for this mail destination. Mandatory DANE for SMTP is described in Section 6 of RFC7672 |
| Reported failure | Description |
|---|---|
| sts-policy-fetch-error | The MTA-STS policy cannot be loaded from the web server (document does not exist or other http error) |
| sts-policy-invalid | The MTS-STS policy document cannot be parsed, it is invalid |
| sts-webpki-invalid | The TLS connection to the web-server containing the MTA-STS document cannot be established |
Questions? / Answers!