DIAGNOSTIC PLAYBOOK
Changed an MTA-STS file? Update its discovery identifier
The MTA-STS DNS identifier signals that the policy has changed. Editing only the HTTPS file can leave supporting senders relying on a previously cached policy until they refresh it.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Validate the new policy file and ensure it is publicly reachable over valid HTTPS.
- Publish a new policy identifier in the discovery TXT record as part of the change.
- Verify both DNS and HTTPS responses and monitor subsequent TLS reports.
What this looks like
ILLUSTRATIVE EXAMPLE
A policy adds a new MX hostname but keeps its old discovery identifier. Some senders continue using their existing cached version.
A mistake to avoid
A new identifier is a change signal, not a guarantee that all senders have already fetched the file.
Keep the result in context
Transport encryption protects a connection between mail systems. It is different from message authentication and does not imply end-to-end encryption. Investigate the receiving MX hostname, the TLS session and the applicable policy separately before deciding which system needs a change.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.