EMAIL-004: MTA-STS Policy

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Mail Transfer Agent Strict Transport Security (MTA-STS) prevents TLS downgrade attacks and man-in-the-middle interception of email in transit by requiring authenticated TLS connections

Recommended value

MTA-STS TXT record published and policy hosted at https://mta-sts.<domain>/.well-known/mta-sts.txt

Remediation

Publish _mta-sts.<domain> TXT record with v=STSv1; id=<unique_id> and host MTA-STS policy file at https://mta-sts.<domain>/.well-known/mta-sts.txt

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-004
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
SC-8, SC-8(1)
CIS Benchmark
2.4
MITRE ATT&CK
T1557, T1040