Back to feed
Dev.to
Dev.to
7/4/2026
97.8% of the top 10,000 domains have no MTA-STS. Here's how to be in the other 2%

97.8% of the top 10,000 domains have no MTA-STS. Here's how to be in the other 2%

Short summary

97.8% of the top 10,000 web domains lack MTA-STS email-security policies, despite their effectiveness at preventing SMTP downgrade attacks. The barrier isn't technical complexity but the lack of a forcing function like inbox providers' deliverability requirements. Implementation follows DMARC's pattern: publish a policy file and DNS records in testing mode, monitor TLS-RPT reports, then enforce.

  • MTA-STS adoption is only 2.2% among top 10,000 domains, nearly 3x lower than DMARC adoption
  • Implementation requires a policy file, DNS record, and valid TLS certificates—straightforward but multi-part setup
  • Recommended rollout: testing mode first, validate with TLS-RPT reports, then switch to enforce

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more