All fixes

Fix a broken MTA-STS policy file

mta-sts-invalid

Your _mta-sts DNS record points at a policy file that is missing or malformed, so senders ignore it and fall back to plaintext delivery.

Why this matters

The MTA-STS DNS record exists but the policy file is missing or broken. It's like putting up a sign for a door that doesn't open.

Cloudflare

  1. 1 Verify your policy file is accessible at https://mta-sts.yourdomain.com/.well-known/mta-sts.txt
  2. 2 Ensure it contains version: STSv1, mode:, mx:, and max_age: lines
  3. 3 Check that the URL does not redirect (MTA-STS spec forbids redirects)
# Valid policy file format:
version: STSv1
mode: enforce
mx: mail.yourdomain.com
max_age: 604800

# mode must be: enforce, testing, or none
# URL must NOT redirect (3xx = invalid per RFC 8461)
Cloudflare docs

Does your app still have this?

Scan your domain