Guide
MTA-STS and TLS-RPT
MTA-STS tells other mail servers to use TLS when they deliver mail to your domain. TLS-RPT sends you reports when transport encryption fails. MailControl Essential and larger bundles include hosted publication on NovaMX.
What MTA-STS does
Without MTA-STS, a sender may try opportunistic TLS and fall back to plain text if negotiation fails. With MTA-STS in enforce mode and a valid policy file, supporting senders must use TLS to your MX hosts. TLS-RPT complements this with aggregate reports about failures.
Who needs it
Internet.nl mail tests check for MTA-STS and TLS-RPT. Growth-focused teams often add it after SPF, DKIM and DMARC monitoring are stable. MailControl Essential (EUR 17.95/month, excl. VAT) and higher bundles include MTA-STS and TLS-RPT hosting for covered sending domains.
Steps in My NovaMX
- Verify the domain and order MailControl Essential or a larger bundle, or confirm your bundle already includes transport reporting.
- Open MailControl for the domain and follow the MTA-STS wizard: policy mode, MX hosts and TLS requirements.
- Publish the _mta-sts TXT record and TLS-RPT record the portal provides, plus the hosted policy file when NovaMX serves it.
- Wait for DNS propagation, then re-test at Internet.nl or with the free mail check.
Common mistakes
Publishing enforce before MX hosts offer valid TLS on all paths. Leaving an old policy file at a former hosting URL after you move mail. Missing TLS-RPT so failures stay invisible. Editing MTA-STS records by hand while MailControl also manages them.
When you are stuck
Check transport status in MailControl and compare with Internet.nl mail results. Browse Help for MTA-STS articles. Open Messages if policy publication fails or external MX paths differ from NovaMX hosting.