MTA-STS made practical

Generate an MTA-STS policy your mail server can use.

Create the policy text, DNS TXT record, and a deployment-ready file in under a minute. Nothing you enter leaves your browser.

Get the Email Authentication Starter Kit - $9

Policy details

Use the domain people send mail from, without https:// or @.

Enforcement mode

Testing requests reporting-compatible behavior while you verify delivery.

Enter every MX hostname that can receive mail, for example aspmx.l.google.com. Wildcards are allowed only as the leftmost label.

Your deployment kit will appear here

It includes the exact MTA-STS policy and DNS record based on your entries.

MTA-STS policy generator FAQ

What does MTA-STS do?

MTA-STS lets a domain publish a policy telling compatible sending mail systems to require authenticated TLS when delivering to its MX hosts.

Which MX hosts should I enter?

Copy all hosts currently returned by your domain’s MX records. A policy that omits a legitimate destination can disrupt delivery after enforcement is enabled.

Does this tool host the policy?

No. PolicyForge generates files locally. You retain control and can host the policy on any HTTPS-capable service.