CAA and MTA-STS: DNS records against forged certificates and mail interception
CAA says who may issue certificates for your domain. MTA-STS forces encrypted mail delivery. How to add both records without breaking email.
Checked against sources: 11 October 2026

- RFC 8659the CAA record standard
- RFC 8461the MTA-STS standard
- 2 weeksin testing mode before enforce
CAA: who may issue a certificate
Certificate authorities check the CAA record before issuing. If only your authority is named, no other will issue a forged certificate for your domain.
example.com. CAA 0 issue "letsencrypt.org" example.com. CAA 0 issuewild "letsencrypt.org"
MTA-STS: mail over an encrypted channel only
Without MTA-STS a sender’s mail server may fall back to plain text when encryption fails, and the message can be intercepted. MTA-STS is a TXT record plus a policy file on the mta-sts subdomain.
_mta-sts.example.com. TXT "v=STSv1; id=20261001" # https://mta-sts.example.com/.well-known/mta-sts.txt version: STSv1 mode: testing mx: mx.example.com max_age: 86400
How not to break mail
Start with mode: testing and switch to enforce after two error-free weeks. Before enabling CAA make sure every authority that issues for your subdomains is named, otherwise renewal stops. The SPF, DMARC, CAA and MTA-STS generator builds both records.
Frequently asked
Do I need MTA-STS with Google Workspace or Microsoft 365?
Yes, if you want customer mail delivered over an encrypted channel. The services support MTA-STS, you only publish the record and the policy.
What happens if CAA is wrong?
The authority refuses to issue or renew the certificate and the site becomes unreachable over HTTPS. Test renewal after any change.
How does it differ from DANE?
DANE solves a similar problem through DNSSEC. MTA-STS is simpler: it works without DNSSEC and big mail providers support it.
