Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Ensure your Mail Transfer Agent Strict Transport Security (MTA-STS) policy complies with RFC 8461. Validate DNS records, policy hosting over HTTPS, and TLS certificate requirements to prevent man-in-the-middle (MitM) downgrade attacks.
SMTP historically relies on opportunistic TLS, leaving emails vulnerable to active STRIPTLS downgrade attacks. MTA-STS enforces mandatory TLS encryption for inbound emails by explicitly declaring that...
SMTP historically relies on opportunistic TLS, leaving emails vulnerable to active STRIPTLS downgrade attacks. MTA-STS enforces mandatory TLS encryption for inbound emails by explicitly declaring that all SMTP connections to your domain's MX servers must be secured with valid, unexpired X.509 certificates issued by a trusted root CA. Without MTA-STS, attackers can silently intercept, modify, or block email routing before the STARTTLS negotiation completes.
Failing to host the MTA-STS policy text file (mta-sts.txt) strictly at the '.well-known/' directory on the 'mta-sts' subdomain over HTTPS., Mismatched policy 'id' in the TXT record (_mta-sts) compared to the currently served policy., Using a self-signed or expired SSL/TLS certificate for the mta-sts subdomain, violating RFC 8461..
DNS Discovery: The sender's Mail Transfer Agent queries the _mta-sts TXT record to discover if the recipient domain supports MTA-STS and checks the policy ID.
Policy Retrieval: If a valid TXT record exists, the sender fetches the policy file via HTTPS from the predefined mta-sts subdomain using the well-known URI.
Validation: The sender validates the policy syntax, MX host patterns, and ensures the HTTPS server presents a valid certificate.
Enforcement: The sender connects to the authorized MX hosts using STARTTLS. If the connection fails or the certificate is invalid, the message is deferred or dropped depending on the policy mode.
Deep static analysis of your mta-sts.txt file to ensure strict compliance with parsing rules, key-value pairs, and maximum allowed age (max_age).
Instantly queries and validates your domain's _mta-sts TXT record, ensuring the v=STSv1 protocol and valid 'id' parameters are properly formatted.
Verifies that your policy is served over HTTPS using TLS 1.2+ with a trusted, unexpired X.509 certificate, checking for misconfigurations or chain-of-trust issues.
Cross-references the MX hosts listed in your policy against your active DNS MX records to prevent unauthorized routing or broken configurations.
Checks if the policy ID in the DNS TXT record matches the state of the active policy file, avoiding cache inconsistencies for sending MTAs.
Validates the presence of corresponding RFC 8460 _smtp._tls DNS TXT records to ensure you receive failure reports when connections fall back.
Don't let misconfigured certificates or syntax errors block your inbound emails. Run a comprehensive analysis of your DNS records and HTTPS policy endpoints now.