Available at https://www.suped.com/tools/mta-sts-checker.
Enter a domain and the checker looks up the _mta-sts TXT record, fetches the policy file from the standard HTTPS location, compares live MX records to the policy, and tests whether each MX server can upgrade to an encrypted SMTP connection with STARTTLS. It also checks the TLS-RPT TXT record at _smtp._tls for TLS reporting configuration.
How it works
Enter a domain and click Check. You can also click View sample to run the sample check for suped.com.

Results are split into four sections: the MTA-STS DNS record, the MTA-STS policy file, MX server encryption support, and the TLS-RPT DNS record. All four sections contribute to the overall score.
Checks
MTA-STS DNS record
- Record found at
_mta-sts - Only one MTA-STS TXT record found
- Record has valid
v=andid=tags
MTA-STS policy file
- Policy file found at the standard HTTPS URL
- Policy file is valid
- Policy file is served via HTTPS
MX server supports encryption
- MX records found
- MX servers accept SMTP and advertise STARTTLS
- MX records match the hosts listed in the policy file
TLS-RPT DNS record
- Record found at
_smtp._tls - Only one TLS-RPT TXT record found
- Record has valid syntax, starts with
v=TLSRPTv1, and includesrua=reporting destinations using validmailto:addresses or HTTPS URLs
The checker displays the reporting destinations and validates their syntax. It does not send reports or verify that the destinations accept them.
In-app version
The same MTA-STS checker is available inside the app under Tools → MTA-STS checker. Use it the same way you would the public tool. Results and the share link are identical to the public version.