DIAGNOSTIC PLAYBOOK
MTA-STS testing mode reports failures: what to check
MTA-STS testing mode is intended to surface policy problems without requiring enforcement of those failures. Use the reports to find certificate or MX mismatches before asking senders to enforce the policy.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Confirm the policy mode and collect a complete TLS reporting interval.
- Group failures by MX host and result type to identify the specific endpoint or validation issue.
- Fix those issues and observe representative traffic before considering enforcement.
What this looks like
ILLUSTRATIVE EXAMPLE
A secondary MX has an invalid certificate chain. Testing reports expose the problem even though mail may continue arriving.
A mistake to avoid
A quiet report period does not prove every fallback server was exercised. Test all advertised destinations, including infrequently used backups.
Keep the result in context
Transport encryption protects a connection between mail systems. It is different from message authentication and does not imply end-to-end encryption. Investigate the receiving MX hostname, the TLS session and the applicable policy separately before deciding which system needs a change.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.