Build a valid SPF, DMARC, DKIM or MTA-STS record from a form, then paste it into your DNS. Everything is assembled in your browser, nothing you type here is sent anywhere, including to us.
.
Host names are shown the way most DNS panels expect them. A few providers
want the full name including your domain, if yours shows an existing record as
_dmarc.yourdomain.com rather than _dmarc, use the full form.
At https://mta-sts.yourdomain.com/.well-known/mta-sts.txt, served with a valid certificate for that exact subdomain. The DNS record only announces it; the file is the policy.
TLS-RPT is the companion record where receivers report delivery attempts that failed your policy. Publishing MTA-STS without TLS-RPT means enforcing a rule with no way to see what it breaks.
Testing. It reports what WOULD fail without blocking anything, exactly like DMARC p=none. Move to enforce after the reports run clean.