dns.rehab

MTA-STS: make TLS mandatory for mail to you

SMTP upgrades to TLS opportunistically by default — an attacker in the middle can force plaintext. MTA-STS publishes a policy (a DNS TXT record pointing at an HTTPS-served text file) declaring that your MX servers MUST use TLS.

The policy file is the real check: mode enforce, your exact MX list, and a max_age that keeps the promise cached. We fetch and grade both halves — most deployments publish the TXT and forget the file.

Run it on your domain — the audit includes this check.

Other tools: SPF · DMARC · llms.txt · Header analyzer