Back to all tools
Record builder SPF · DKIM · DMARC · MTA-STS · 100% client-side

MTA-STS Generator

Build a valid SPF, DMARC, DKIM or MTA-STS record from a form, then paste it into your DNS. Everything is assembled in your browser, nothing you type here is sent anywhere, including to us.

Your record
.
Type
TXT
Host
.
Value
.
TTL
3600

Host names are shown the way most DNS panels expect them. A few providers want the full name including your domain, if yours shows an existing record as _dmarc.yourdomain.com rather than _dmarc, use the full form.

Questions people ask

Where does the policy file go?

At https://mta-sts.yourdomain.com/.well-known/mta-sts.txt, served with a valid certificate for that exact subdomain. The DNS record only announces it; the file is the policy.

What is TLS-RPT and why generate it here?

TLS-RPT is the companion record where receivers report delivery attempts that failed your policy. Publishing MTA-STS without TLS-RPT means enforcing a rule with no way to see what it breaks.

Start in testing or enforce mode?

Testing. It reports what WOULD fail without blocking anything, exactly like DMARC p=none. Move to enforce after the reports run clean.