Omnikite Logo
Omnikite
Toggle theme
Security & Network100% In-Memory SandboxPopular Utility

MTA-STS Policy & DNS TXT Record Generator (RFC 8461)

Enforce TLS email encryption and prevent SMTP man-in-the-middle downgrade attacks (STARTTLS).

More in Security & Network
Advertisement
Zero-Knowledge Privacy

Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. No data is ever transmitted across the network.

Sub-Millisecond Native

Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.

RFC Standards Compliant

Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.

How to Use MTA-STS Policy & DNS TXT Record Generator (RFC 8461)

1
Enter Domain & MX Hosts

Provide your domain name and authorized mail server patterns.

2
Select Enforcement Mode

Choose enforce, testing, or none.

3
Export Policy & DNS Records

Download mta-sts.txt and copy the _mta-sts TXT record.

Frequently Asked Questions

Where should mta-sts.txt be hosted?

It must be hosted at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt over HTTPS with a valid certificate.

What is the difference between enforce and testing mode?

Enforce mode instructs sending mail servers to refuse delivery if TLS is absent, while testing mode delivers mail and reports failures via TLS-RPT.

Advertisement