Message Transfer Agent – Strict Transport Security (MTA-STS)

What is MTA-STS?

Message Transfer Agent – Strict Transport Security (MTA-STS) adds an additional layer of security by requiring authentication checks and encryption for email sent to your domain. Specifically, mail services that use this mechanism will be able to create secure SMTP (using TLS) connections with other email servers. MTA-STS can also be used to refuse delivery of messages to mail servers that do not offer TLS with a trusted server certificate.

Since this mechanism is invoking the usage of TLS, TLS Reporting (TLS-RPT) is used to determine whether or not a secure connection was established. These reports will come from external servers that make connections to your domain.


What it Protects

MTA-STS protects against the follow threats:

  • Man-in-the-Middle attacks – this occurs when an attacker intercepts messages between two email servers. The goal is to steal or alter the data, and then send it to the recipient.
  • Downgrade attacks – this occurs when the attacker forces the communication to change to an insecure mode (no longer using TLS).
  • DNS spoofing attacks – this type of attack changes the DNS record of the intended destination, thus tricking the user into thinking that they are visiting a legitimate site or domain.

Our DMARC Boot Camp offered five weeks of free online technical training focused on DMARC, including the basics of SPF and DKIM, and MTA-STS.


OTHER GCA TOOLS AND PROJECTS

ACT offers an easy-to-use, wiki-style layout that can help you quickly find cybersecurity solutions that fit your unique needs. Using ACT, you can identify cybersecurity solutions to minimize the risk of disruptions to essential services that you and your community rely on.
LEARN MORE
AIDE is a threat intelligence platform that collects data from a globally distributed network of honeypots to offer actionable insights into infected Internet infrastructure.
LEARN MORE
CyberFlex is a safe space for young adults to explore, learn, and share experiences around cybersecurity and online scams. Stay protected. Stay alert. Stay CyberFlexed.
LEARN MORE
DMARC is a mechanism that allows senders and receivers to monitor and improve protection of their domain from fraudulent email. Implementing DMARC ensures mail recipients can detect when spammers have spoofed the “From” address on mail messages. 
LEARN MORE
Domain Trust logo
Domain Trust uses the power of data sharing, community building, and mutual agreement to reduce the number and impact of malicious domains. Its data-sharing platform includes 32M+ domains (and growing!), and is working toward identifying industry-validated mechanisms for change.
LEARN MORE
The GCA Cybersecurity Toolkits include free and effective tools that organizations can use to reduce cyber risk right away. GCA has created toolkits that are tailored to the unique needs of specialized industries, including small businesses, individuals, elections offices, mission-based organizations, and journalists.
LEARN MORE
MANRS outlines simple, concrete actions organizations can take, tailored to their role on the Internet, offering four programs for Network Operators, Internet Exchange Points, CDN and Cloud Providers, and Equipment Vendors. Joining MANRS means joining a community of security-minded organizations committed to making the global routing infrastructure more robust and secure.
LEARN MORE
GCA, in collaboration with IBM and PCH, developed Quad9, a free, privacy-focused DNS service that replaces your default DNS settings and blocks access to known malicious sites.
LEARN MORE

Subscribe to our newsletter to keep up with the latest.

SUBSCRIBE

IMPROVE YOUR CYBERSECURITY. USE A TOOL.