MTA-STS monitoring
How SealedMail verifies your MTA-STS policy is present, reachable and correctly configured, so encryption is actually enforced.
MTA-STS is HTTPS for email between servers. Here is what SealedMail verifies, and the configuration mistakes that quietly break delivery.
Watch: MTA-STS in plain English
What MTA-STS is
MTA-STS (Mail Transfer Agent Strict Transport Security) forces email arriving at your domain to use encryption, or not be delivered. Think of it as HTTPS for the conversations between mail servers. For the full detail, see our guide: What is MTA-STS?
Why it matters to your business
Without it, an attacker positioned on the network can strip away encryption (a downgrade attack) and read or tamper with email in transit. The NCSC recommends MTA-STS alongside TLS-RPT.
How SealedMail monitors it
Every health check verifies your MTA-STS policy exists, is reachable, and is correctly configured, including the policy file, which must stay accessible over HTTPS or delivery can break.
What commonly goes wrong
Enforcing too quickly. MTA-STS should start in testing mode; jumping straight to enforcement can block legitimate inbound mail. The other classic fault is a policy file that becomes unreachable after a website change.
Want the full technical detail? Read our plain-English guide: What is MTA-STS?
Scope: reporting only
SealedMail monitors, interprets and reports. It does not change your DNS, configure your systems, or remediate problems. Your reports tell you clearly what is wrong and what kind of fix is needed, and the changes remain in your hands (or your IT provider’s). That boundary keeps the service simple, affordable and honest.