CrawlCheck

Glossary · Security and privacy

MTA-STS

A policy, published at a well-known URL and announced in DNS, telling sending servers that mail to this domain must use TLS to the named mail exchangers.

What MTA-STS means

A policy, published at a well-known URL and announced in DNS, telling sending servers that mail to this domain must use TLS to the named mail exchangers. It closes the downgrade attack that plain SMTP allows; testing mode reports, enforce mode refuses, and TLS-RPT is where the reports go.

Where MTA-STS comes up on this site

Terms this definition uses

TLS-RPT

Definitions that name MTA-STS

TLS-RPT

Related terms in Security and privacy

Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

Indirect prompt injection · Direct prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Excessive agency · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model · DMARC · DMARC alignment · SPF · DKIM · TLS-RPT · CAA record · DNSSEC · hard bounce

Questions about MTA-STS

What is MTA-STS?

A policy, published at a well-known URL and announced in DNS, telling sending servers that mail to this domain must use TLS to the named mail exchangers.

Which area of the glossary does MTA-STS belong to?

Security and privacy: Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

← DKIM  ·  TLS-RPT →

See it in the full glossary · 668 terms across 19 areas.