7 min read
Microsoft Licensing Update: How Agent 365 Manages & Secures AI Agents
Microsoft Ignite 2025 marked a turning point for organizations seeking practical solutions to manage the rapid growth of AI-powered automation. This...
3 min read
Nicole Walker
:
Jul 10, 2025 9:00:00 AM
Microsoft’s new email security standards (MTA-STS, TLS-RPT, DANE, and DNSSEC) are redefining how organizations protect email in transit. These protocols enforce encrypted delivery, validate sender authenticity, and provide actionable reporting, making it possible to prevent interception, downgrade attacks, and spoofing.
The shift to Microsoft’s new MX records unlocks inbound protections, ensuring that only properly authenticated and encrypted messages reach their destination.
In this episode of Demystifying Microsoft podcast, Nathan Taylor (SVP, Global Microsoft Practice Leader at Sourcepass MCOE) explores the practical impact of Microsoft’s latest email security technologies. The discussion covers how MTA-STS enforces encrypted delivery, how TLS-RPT provides visibility into delivery failures, and how DANE with DNSSEC binds TLS certificates to your domain for stronger authentication. The migration to Microsoft’s new MX records enables organizations to enforce advanced inbound email protections, supporting stricter authentication and encryption standards that improve deliverability and trust.
MTA-STS (Mail Transfer Agent Strict Transport Security) is a protocol that requires email leaving your organization to use TLS encryption. If encryption cannot be established, the message is not delivered. This prevents downgrade and man-in-the-middle attacks, ensuring that only secure connections are used for email delivery.
TLS-RPT (Transport Layer Security Reporting) provides domain owners with reports on email delivery failures related to TLS negotiation, DNS issues, and MTA-STS problems. These reports, delivered in JSON format, offer clear visibility into where and why emails fail, enabling rapid troubleshooting and continuous improvement.
DNSSEC (Domain Name System Security Extensions) digitally signs DNS records, preventing tampering and spoofing. DANE (DNS-based Authentication of Named Entities) binds TLS certificates to your domain, ensuring only valid, signed certificates are accepted for encrypted email delivery. Together, these standards provide end-to-end trust and prevent unauthorized interception.
Microsoft’s migration from protection.outlook.com to mx.microsoft unlocks inbound support for MTA-STS and DANE. This change enables organizations to enforce strict security policies for incoming email, improving deliverability and reputation with receiving servers.
MTA-STS is a protocol that enforces TLS encryption for email delivery, preventing messages from being sent over insecure connections and protecting against man-in-the-middle and downgrade attacks.
TLS-RPT provides reports on email delivery failures related to TLS negotiation, DNS issues, and MTA-STS problems, helping organizations troubleshoot and maintain secure mail flow.
DNSSEC digitally signs DNS records to prevent tampering, while DANE binds TLS certificates to domains, ensuring only valid certificates are accepted for encrypted email delivery.
The update enables inbound support for advanced security protocols like MTA-STS and DANE, improving authentication, encryption, and overall trust in email delivery.
Use tools like MXToolbox, EasyDMARC, or the Microsoft 365 Admin Center to check DNS, SPF, DKIM, DMARC, DNSSEC, and DANE records for correct configuration.
Email security is a continuous process that relies on robust protocols, careful configuration, and regular review. Implementing standards like MTA-STS, TLS-RPT, DNSSEC, and DANE helps organizations enforce encrypted delivery, strengthen authentication, and gain visibility into mail flow issues before they impact business operations. Migrating to Microsoft’s new MX records enables advanced inbound protections, supporting compliance and improving trust across the ecosystem. Staying proactive with security awareness training and periodic assessments ensures your organization is prepared for emerging threats and evolving requirements.
If you have questions about deploying these protocols, want to audit your DNS setup, or need a security assessment tailored to your environment, Sourcepass MCOE can help. Our team offers support for configuring authentication records, optimizing security features, and aligning your setup with current best practices.
Subscribe to the Demystifying Microsoft podcast for ongoing insights, and reach out to connect with one of our Sourcepass MCOE experts or to schedule a Microsoft 365 email security assessment.
Explore the rest of the series:
Part 2: Fix Email Delivery and Spoofing with Better DNS Security
Part 3: Email Security Best Practices with Microsoft Defender and EasyDMARC
7 min read
Microsoft Ignite 2025 marked a turning point for organizations seeking practical solutions to manage the rapid growth of AI-powered automation. This...
8 min read
Microsoft Ignite 2025 set a new direction for organizations navigating the evolving landscape of AI and cloud technology.
6 min read
Microsoft’s Windows 365 Cloud Apps, now available in public preview, introduces a new way for organizations to deliver only the applications users...
Microsoft 365 has introduced a new generation of email security capabilities designed to address modern threats like phishing, spoofing, and business...
Ensuring email deliverability and security requires a layered approach built on DNS, SPF, DKIM, and DMARC. These technologies work together to...
Most IT leaders already know email is the primary attack vector. You see it every day through phishing attempts, spoofed domains, and impersonated...