Email Security
This subdomain hosts the MTA-STS email security policy for st-johns-knaphill.surrey.sch.uk, requiring sending mail servers to deliver email using encrypted TLS connections and validated mail servers.
MTA-STS (Mail Transfer Agent Strict Transport Security) is an email security standard defined in RFC 8461. It allows organisations to publish a policy stating that email must be delivered using TLS encryption and only to authorised mail servers. If these conditions cannot be met, compliant sending servers will defer or refuse delivery.
Emails sent between mail servers typically use opportunistic TLS encryption, meaning encryption is attempted but not strictly required. However, attackers can exploit weaknesses such as STARTTLS downgrade attacks or MX record manipulation to force messages to be sent in plain text or redirected to malicious servers.
MTA-STS mitigates these risks by publishing a policy that requires sending mail servers to:
This helps prevent downgrade attacks and reduces the risk of man-in-the-middle interception of email traffic.
MTA-STS complements other email security technologies such as SPF, DKIM and DMARC, which protect sender authenticity and domain spoofing, by securing the transport layer used to deliver email.
Policy File
https://mta-sts.st-johns-knaphill.surrey.sch.uk/.well-known/mta-sts.txt
Organisation Website
st-johns-knaphill.surrey.sch.uk
st-johns-knaphill.surrey.sch.uk