Email & Communications

MTA-STS: Why Your Emails Might Not Be As Secure As You Think

5 min read
MTA-STS: Why Your Emails Might Not Be As Secure As You Think

You’ve probably heard that email encryption is important. Your IT team (or provider) has likely assured you it’s all sorted. And for the most part, that’s true – modern email systems do encrypt messages when they travel between servers.

But here’s the thing: that encryption is opportunistic. It tries to encrypt, but if something goes wrong, your email gets sent anyway – in plain text. It’s a bit like having a lock on your door that automatically opens if the key doesn’t work properly. Not ideal when you’re sending contracts, financial information, or anything else you wouldn’t want broadcast to the world.

Curious how your own domain scores? Run a free scan below and see your email authentication grade in seconds.

Advanced options

Scanning your domain…

Want to receive a full detailed report?

That’s where MTA-STS comes in. It’s not the catchiest acronym (it stands for Mail Transfer Agent Strict Transport Security, if you’re curious), but it solves a problem most businesses don’t even know they have.

The Problem With “Opportunistic” Email Security

When your email system sends a message to another company, it attempts to establish an encrypted connection. If that works, great – your email travels securely. If it doesn’t work for any reason, the email gets sent unencrypted anyway.

This approach made sense years ago when encrypted email was the exception rather than the rule. But today, when virtually all legitimate email servers support encryption, sending unencrypted emails is a vulnerability you shouldn’t accept.

The worst part? You’d never know it happened. Your email gets delivered, you get no error message, and the sensitive information in that email has traveled across the internet in plain text – readable by anyone who might be watching.

What MTA-STS Actually Does

MTA-STS is essentially a policy you publish that says “if you’re sending email to our domain, encryption isn’t optional – it’s mandatory.”

When another email server tries to send you a message, it checks your MTA-STS policy first. That policy tells it two things: encryption is required, and here’s the valid certificate we’re using. If the sending server can’t establish a properly encrypted connection, the email doesn’t get sent. It fails, and the sender is notified.

Think of it like the difference between a shop that prefers card payments but accepts cash, versus one that’s card-only. The first is flexible but creates security gaps. The second is stricter, but everyone knows exactly what’s expected.

Why This Matters For Your Business

If you’re handling any sensitive information via email – and let’s be honest, most businesses are – MTA-STS addresses some real risks:

GDPR and compliance: When you’re sending personal data, you need to ensure it’s protected in transit. Opportunistic encryption isn’t enough if it can silently fail. Having MTA-STS in place demonstrates you’re taking reasonable steps to protect data.

Business intelligence: Your emails contain competitive information, contract details, strategic plans, and financial data. Even if you’re not legally required to protect it, you certainly don’t want competitors or bad actors reading it.

Man-in-the-middle attacks: These are increasingly common. An attacker intercepts the connection between email servers, downgrades it to unencrypted, and reads everything that passes through. MTA-STS prevents this by requiring valid encryption certificates – if someone’s tampering with the connection, the email won’t be delivered.

The Gap Between Sending and Receiving

Here’s something important: MTA-STS primarily protects emails coming to your domain, not emails you send from it.

When you send an email to another company, whether it’s encrypted depends on their email security setup, not yours. You’re at the mercy of their policies. MTA-STS ensures that anyone sending to your domain must use proper encryption, but it doesn’t force other domains to have the same policy. This is exactly why MTA-STS is paired with TLS-RPT as standard – one enforces encryption on the way in, the other tells you what happened when it did.

This is why the broader adoption of MTA-STS across the business world matters. The more companies that implement it, the more secure email becomes for everyone.

What It Takes To Set Up

MTA-STS requires a few technical pieces to work together:

You need to publish a policy file on your website (at a specific location that other email servers know to check). You need to add a DNS record that points to this policy. And you need to make sure your email server’s TLS certificates are valid and properly configured.

It’s not horrendously complicated, but it’s easy to get wrong. A misconfigured MTA-STS policy can block legitimate emails from reaching you, which is obviously a problem. This is why testing is essential before you switch the policy to “enforce” mode.

Most businesses fall into one of three camps: those with in-house IT teams who can handle this (and who probably should, if they haven’t already), those whose email providers manage it for them, or those who need their IT partner to sort it out.

How We Approach Email Security

When we set up or review email security for our partners, MTA-STS is part of the package alongside SPF, DKIM, DMARC, and TLS-RPT. They all work together to ensure your emails are authenticated, encrypted, and monitored.

We handle the technical setup, but more importantly, we monitor what’s happening. If legitimate emails are being blocked because of a configuration issue, we spot it and fix it quickly. If emails are failing because someone’s certificate has expired, we let you know.

The goal isn’t just to tick a compliance box – it’s to make sure your email is genuinely secure without creating headaches for your team or your contacts.

Is MTA-STS Worth Implementing?

For most businesses? Yes.

If you’re sending or receiving any sensitive information via email (contracts, financial data, personal information, business strategy), MTA-STS closes a security gap you probably didn’t know existed. It’s particularly important if you’re in a regulated sector or if you handle customer data.

The main reason not to implement it would be if you’re using a legacy email system that can’t support modern TLS standards – but if that’s the case, you’ve got bigger security concerns than MTA-STS.

Like most security measures, MTA-STS works best as part of a broader approach. It’s not a silver bullet, but it’s a significant upgrade from hoping encryption just works.

How AOIT Networks Approaches It

MTA-STS is one part of the email authentication setup we manage for clients, alongside SPF, DKIM and DMARC, so encrypted delivery is enforced rather than left to chance.

If you want to know whether your email is actually as secure as you think it is, get in touch and we will run through your current setup.

Share

Got Questions About Your IT?

Questions about your setup? Wondering if there's a better way to do things? We're always happy to have a no-pressure conversation about your IT needs.

No sales pitch. No obligation. Just straightforward advice from people who genuinely care about getting it right.

More in Email & Communications