Skip to content

MTA-STS, TLS-RPT & BIMI checker

Read the transport and brand policies a domain publishes, plus the SPF and DMARC details that decide whether they can work — straight from live DNS, free.

try:

The four records this page reads

_mta-sts.<domain> announces an MTA-STS policy (the policy file itself is served over HTTPS; this page reads the DNS announcement). _smtp._tls.<domain> names where TLS failure reports go. default._bimi.<domain> points at the brand logo. And the domain's SPF and DMARC records are read again here for the details the SPF & DMARC checker does not show: the all qualifier, the DNS lookup count, the DMARC pct tag and whether aggregate reports are collected.

What each answer means

A record is reported as published, not published, or not read when the lookup itself failed; a lookup that failed is never turned into a "no". None of these records affects whether an address at the domain exists. On Spaw's domain endpoint they are hygiene signals about a domain that is looked after, which is context for a signup, never a verdict about a person.

Frequently asked questions

What does MTA-STS protect against?

Downgrade attacks on delivery. SMTP encrypts opportunistically: a sender offers STARTTLS, and if the receiver appears not to support it the message goes in the clear. An attacker on the path can strip that offer. MTA-STS is a policy the receiving domain publishes saying "always use TLS with a valid certificate to reach my mail hosts", so a sender that honours it refuses to fall back.

What is TLS-RPT for?

Reporting. Senders that honour MTA-STS (or DANE) send a daily summary of the connections that failed to negotiate TLS to the address in the TLS-RPT record. Without it a strict policy can quietly cost mail, because nobody on the receiving side hears about the failures.

What is BIMI?

Brand Indicators for Message Identification: a DNS record pointing at a brand logo that participating mailbox providers show beside authenticated mail. It is cosmetic, and it only works once the domain enforces DMARC at quarantine or reject; some providers also require a verified mark certificate.

Why does the SPF lookup count matter?

RFC 7208 lets a receiver spend at most ten DNS lookups evaluating an SPF policy, counting every include, a, mx, ptr, exists and redirect term through the records they pull in. Past ten the receiver returns a permanent error, which is the same as publishing no SPF at all. Long lists of third-party includes reach the limit without anyone noticing.

Data synced on 2026-09-14: the newest sync of the open lists and curated maps behind every answer on this page. The domain's own records are read live at each check.

Wrong result, or is it about you? If this tool said something you think is wrong, tell us and a person reads it. If Spaw is holding data about you and you never signed up here — a customer may have had your address verified, or reported that a message to it bounced — erase it yourself, confirmed by mail to that address and with no account needed.

More free tools

All free tools

Need this at scale?

The Spaw API runs the same checks plus mailbox-level SMTP verification, batch and bulk endpoints, and list monitoring — 10 free lookups a month, no card required.

Get your API key