Enter your domain and abr.cloud checks your MTA-STS record and policy — the mechanism that forces other mail servers to deliver to you over TLS — and tells you whether encrypted inbound mail is actually enforced.
One quick verification, no account. We store nothing unless you start monitoring.
MTA-STS (SMTP MTA Strict Transport Security) lets you require that other mail servers use TLS when delivering to your domain, and refuse to fall back to plaintext. Without it, inbound mail can be downgraded to cleartext by a network attacker. It pairs with TLS-RPT, which reports delivery failures back to you.
_mta-sts record plus a policy file served over HTTPS.enforce (not just testing) once you're confident._mta-sts TXT record and host the policy at https://mta-sts.yourdomain/.well-known/mta-sts.txt.testing mode, watch TLS-RPT, then move to enforce.Yes — free with a quick CAPTCHA, no account. It reads only public DNS and the public policy file.
Your server may support TLS, but without MTA-STS a sender can be tricked into downgrading to plaintext. MTA-STS makes TLS mandatory.
Both enforce TLS for mail; MTA-STS uses HTTPS + DNS and is easier to deploy without DNSSEC, while DANE relies on DNSSEC.
abr.cloud puts 80+ network & security tools behind one fast interface — with AI analysis and always-on monitoring.
open abr.cloud →