Ask whether the solo ad path requires TLS
Answer A domain can publish an MTA-STS policy that tells senders to use TLS when delivering mail to its servers. RFC 8461 defines that policy. It does not prove a solo ad was wanted or filed in the inbox. It does tell you whether the seller is guessing about the path.
The note that started this: RFC 8461, SMTP MTA Strict Transport Security (MTA-STS), RFC 8461.
Buyers rarely ask about transport security. They should ask one question that does not require a lab. Does the seller know whether the hop to the big mailboxes is authenticated and encrypted, or are they hoping the platform sorts it out? A seller who cannot answer has not looked at a control the receiver is allowed to publish.
RFC 8461 is SMTP MTA Strict Transport Security. A domain puts a policy where senders can fetch it, over HTTPS, and a DNS record that says the policy exists. The policy can require TLS, and it can name the mail servers that are allowed to receive the mail. The point is to stop a silent downgrade, where an attacker or a sloppy hop talks a sender into sending the message in the clear. This is the receiver writing a rule. A solo ad seller who transmits through a platform is depending on that platform to honor other people's rules. Ask whether they have ever checked.
What is MTA-STS in plain language?
It is a policy a domain can publish so senders know to use TLS when delivering mail to that domain's mail servers. RFC 8461 defines it. The receiver is stating a requirement. The sender still has to honor it.
You do not need to fetch the policy file yourself before you buy. You need the seller to know the difference between we sent it and the path was willing to authenticate. A platform that retries in the clear when TLS fails is a platform that will fail a receiver who published enforce. The mail you paid for then sits, or bounces, while the sales page still says the drop went out.
This sits beside the envelope note from August 2. The envelope is where failure returns. The TLS policy is one reason a failure returns. If you buy solo ads from a seller who has never heard the term, you are not required to teach a course. You are required to notice that the path is a black box they do not open.
- The seller can name the platform that makes the hop.
- They can say whether that platform honors a receiver's TLS requirement.
- A failure to negotiate is visible in the bounce file, not hidden.
- Nobody promises that encryption equals inbox placement.
Does a TLS policy prove a solo ad reached the inbox?
No. Requiring encryption on the hop is about the path, not about whether a person wanted the mail or where it was filed. A protected hop can still land in junk.
Keep the layers separate, the way the month has been separating them. The header is the author. The envelope is the return path. The signature is the domain that signed. The TLS policy is how the hop is supposed to be protected. The folder is the receiver's later decision. A seller who waves a padlock and calls it deliverability has collapsed the stack into a sticker. The sticker can be true and the folder can still be junk, because the list did not ask for the offer.
If you sell the send, do not invent a compliance badge out of a protocol you have not checked. Say the platform. Say you rely on it to negotiate TLS. If a receiver refuses the message, show the bounce. That is a more trustworthy sentence than a claim that the path is military grade, which is not a thing this specification says.
What should you ask a seller about the path?
Ask whether they know if the sending path authenticates and encrypts the hop, and ask what they do when a receiver's policy refuses a clear-text delivery. A shrug is a guess.
A usable answer sounds like this. The mail leaves from this platform. The platform reports a TLS failure as a bounce. Here is where that bounce shows up in the export I will send you. An unusable answer sounds like the mail always gets there. The second answer is how a buyer learns the path was a guess.
Put the platform name next to the price. Solo ad pricing without a named path is a price for a wish. The policy in RFC 8461 is optional for a domain to publish, and mandatory for a sender to respect once it is published in enforce mode. You are not buying a certificate. You are buying a sender who knows when the other side has written a rule.