MTA-STS Inspector
Validate MTA-STS DNS records and retrieve HTTPS policy files.
DNS lookups and policy retrieval run from the PacketWizard server with SSRF protections and timeout handling.
What is MTA-STS Inspector?
MTA-STS tells sending mail servers to use TLS for SMTP to your domain according to a published HTTPS policy, reducing opportunistic downgrade risk.
How it works
PacketWizard validates the MTA-STS DNS TXT record and retrieves the HTTPS policy file for mode, MX patterns, and max age.
Common issues
DNS and HTTPS policy mismatch
The id in DNS must change when the policy file changes. Stale IDs delay policy adoption at senders.
Frequently asked questions
What is testing vs enforce mode?
testing reports failures without requiring TLS; enforce instructs compliant senders to fail delivery when TLS policy cannot be met.
Related tools
Continue with these related PacketWizard tools for adjacent diagnostics.
TLS-RPT InspectorInspect TLS reporting (TLS-RPT) DNS records for SMTP TLS failure reporting.TLS InspectorInspect TLS handshakes, cipher suites, and certificate chains.SPF InspectorLookup, parse, and analyze SPF records with DNS lookup counting and evaluation tree.DNS LookupQuery DNS records for a hostname or domain.