5 min read
Microsoft Licensing Update: Combined Defender & Purview Suite Add-On
Microsoft has introduced a combined security and compliance add-on for Business Premium subscribers, delivering enterprise-grade protection and...
3 min read
Nicole Walker
:
Jul 10, 2025 9:00:00 AM
Microsoft’s new email security standards (MTA-STS, TLS-RPT, DANE, and DNSSEC) are redefining how organizations protect email in transit. These protocols enforce encrypted delivery, validate sender authenticity, and provide actionable reporting, making it possible to prevent interception, downgrade attacks, and spoofing.
The shift to Microsoft’s new MX records unlocks inbound protections, ensuring that only properly authenticated and encrypted messages reach their destination.
In this episode of Demystifying Microsoft podcast, Nathan Taylor (SVP, Global Microsoft Practice Leader at Sourcepass MCOE) explores the practical impact of Microsoft’s latest email security technologies. The discussion covers how MTA-STS enforces encrypted delivery, how TLS-RPT provides visibility into delivery failures, and how DANE with DNSSEC binds TLS certificates to your domain for stronger authentication. The migration to Microsoft’s new MX records enables organizations to enforce advanced inbound email protections, supporting stricter authentication and encryption standards that improve deliverability and trust.
MTA-STS (Mail Transfer Agent Strict Transport Security) is a protocol that requires email leaving your organization to use TLS encryption. If encryption cannot be established, the message is not delivered. This prevents downgrade and man-in-the-middle attacks, ensuring that only secure connections are used for email delivery.
TLS-RPT (Transport Layer Security Reporting) provides domain owners with reports on email delivery failures related to TLS negotiation, DNS issues, and MTA-STS problems. These reports, delivered in JSON format, offer clear visibility into where and why emails fail, enabling rapid troubleshooting and continuous improvement.
DNSSEC (Domain Name System Security Extensions) digitally signs DNS records, preventing tampering and spoofing. DANE (DNS-based Authentication of Named Entities) binds TLS certificates to your domain, ensuring only valid, signed certificates are accepted for encrypted email delivery. Together, these standards provide end-to-end trust and prevent unauthorized interception.
Microsoft’s migration from protection.outlook.com to mx.microsoft unlocks inbound support for MTA-STS and DANE. This change enables organizations to enforce strict security policies for incoming email, improving deliverability and reputation with receiving servers.
MTA-STS is a protocol that enforces TLS encryption for email delivery, preventing messages from being sent over insecure connections and protecting against man-in-the-middle and downgrade attacks.
TLS-RPT provides reports on email delivery failures related to TLS negotiation, DNS issues, and MTA-STS problems, helping organizations troubleshoot and maintain secure mail flow.
DNSSEC digitally signs DNS records to prevent tampering, while DANE binds TLS certificates to domains, ensuring only valid certificates are accepted for encrypted email delivery.
The update enables inbound support for advanced security protocols like MTA-STS and DANE, improving authentication, encryption, and overall trust in email delivery.
Use tools like MXToolbox, EasyDMARC, or the Microsoft 365 Admin Center to check DNS, SPF, DKIM, DMARC, DNSSEC, and DANE records for correct configuration.
Email security is a continuous process that relies on robust protocols, careful configuration, and regular review. Implementing standards like MTA-STS, TLS-RPT, DNSSEC, and DANE helps organizations enforce encrypted delivery, strengthen authentication, and gain visibility into mail flow issues before they impact business operations. Migrating to Microsoft’s new MX records enables advanced inbound protections, supporting compliance and improving trust across the ecosystem. Staying proactive with security awareness training and periodic assessments ensures your organization is prepared for emerging threats and evolving requirements.
If you have questions about deploying these protocols, want to audit your DNS setup, or need a security assessment tailored to your environment, Sourcepass MCOE can help. Our team offers support for configuring authentication records, optimizing security features, and aligning your setup with current best practices.
Subscribe to the Demystifying Microsoft podcast for ongoing insights, and reach out to connect with one of our Sourcepass MCOE experts or to schedule a Microsoft 365 email security assessment.
Explore the rest of the series:
Part 2: Fix Email Delivery and Spoofing with Better DNS Security
Part 3: Email Security Best Practices with Microsoft Defender and EasyDMARC
5 min read
Microsoft has introduced a combined security and compliance add-on for Business Premium subscribers, delivering enterprise-grade protection and...
6 min read
Microsoft Purview Suite for Business Premium is a compliance add-on for Microsoft 365 Business Premium that delivers enterprise-grade data...
4 min read
In September 2025, Microsoft announced a major change: Teams will no longer be automatically bundled with Microsoft 365 and Office 365 suites for new...
Microsoft 365 has introduced a new generation of email security capabilities designed to address modern threats like phishing, spoofing, and business...
Ensuring email deliverability and security requires a layered approach built on DNS, SPF, DKIM, and DMARC. These technologies work together to...
Most IT leaders already know email is the primary attack vector. You see it every day through phishing attempts, spoofed domains, and impersonated...