Guide

MTA-STS and TLS-RPT

MTA-STS tells other mail servers to use TLS when they deliver mail to your domain. TLS-RPT sends you reports when transport encryption fails. MailControl Essential and larger bundles include hosted publication on NovaMX.

What MTA-STS does

Without MTA-STS, a sender may try opportunistic TLS and fall back to plain text if negotiation fails. With MTA-STS in enforce mode and a valid policy file, supporting senders must use TLS to your MX hosts. TLS-RPT complements this with aggregate reports about failures.

Who needs it

Internet.nl mail tests check for MTA-STS and TLS-RPT. Growth-focused teams often add it after SPF, DKIM and DMARC monitoring are stable. MailControl Essential (EUR 17.95/month, excl. VAT) and higher bundles include MTA-STS and TLS-RPT hosting for covered sending domains.

Steps in My NovaMX

  1. Verify the domain and order MailControl Essential or a larger bundle, or confirm your bundle already includes transport reporting.
  2. Open MailControl for the domain and follow the MTA-STS wizard: policy mode, MX hosts and TLS requirements.
  3. Publish the _mta-sts TXT record and TLS-RPT record the portal provides, plus the hosted policy file when NovaMX serves it.
  4. Wait for DNS propagation, then re-test at Internet.nl or with the free mail check.

Common mistakes

Publishing enforce before MX hosts offer valid TLS on all paths. Leaving an old policy file at a former hosting URL after you move mail. Missing TLS-RPT so failures stay invisible. Editing MTA-STS records by hand while MailControl also manages them.

When you are stuck

Check transport status in MailControl and compare with Internet.nl mail results. Browse Help for MTA-STS articles. Open Messages if policy publication fails or external MX paths differ from NovaMX hosting.