DIAGNOSTIC PLAYBOOK

Changed an MTA-STS file? Update its discovery identifier

The MTA-STS DNS identifier signals that the policy has changed. Editing only the HTTPS file can leave supporting senders relying on a previously cached policy until they refresh it.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Validate the new policy file and ensure it is publicly reachable over valid HTTPS.
  2. Publish a new policy identifier in the discovery TXT record as part of the change.
  3. Verify both DNS and HTTPS responses and monitor subsequent TLS reports.

What this looks like

ILLUSTRATIVE EXAMPLE

A policy adds a new MX hostname but keeps its old discovery identifier. Some senders continue using their existing cached version.

A mistake to avoid

A new identifier is a change signal, not a guarantee that all senders have already fetched the file.

Keep the result in context

Transport encryption protects a connection between mail systems. It is different from message authentication and does not imply end-to-end encryption. Investigate the receiving MX hostname, the TLS session and the applicable policy separately before deciding which system needs a change.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.