How to Setup Hosted MTA-STS
Last updated by Stuart Larsen on
Hosted MTA-STS will allow you to deploy an MTA-STS policy file without the headache of managing the infrastructure. We manage the policy distribution, hosting, and TLS certificate. It's recommended to first enable TLS-RPT before enabling MTA-STS.
1. Configure DNS Records
DNS Setup Instructions for Hosted MTA-STS
First go to the Hosted MTA-STS Tab (Domains -> Select a Domain -> MTA-STS).
Both DNS records need to be installed.
- Cloudfront CNAME: This record allows us to host the policy and request a TLS certificate
- MTA CNAME: This record allows us to update the policy version
Once installed, click "Verify".
2. Wait for Deploy
Once verified, you will need to wait ~2 minutes for the infrastructure to launch. Under the hood we're creating a Cloudfront distribution and requesting a certificate.
You can click 'Refresh' to get updates on the process.
3. Create Policy
Create an MTA-STS Policy
Click "Create Policy" to begin creating your MTA-STS policy. For your convenience we added 'Insert Google Workspace' and 'Insert Microsoft 365' MX patterns.
Start in testing
Unless you are certain no issues exist, we recommend deploying in mode=testing and verifying the TLS-RPT reports until your comfortable moving to mode=enforce.
Once done, click "Save Hosted Policy" and you're all done. If may take a few minutes to propagate the changes.
4. Verify
Refresh the panel to verify the setup status. You can also verify using the Domain Check tool.