check_smtp_tls
Live check of the first 4 MX hosts in priority order (hosts beyond 4 are not tested): opens TCP 25, runs EHLO + STARTTLS, validates TLS certificate trust chain, hostname match, expiry window, advertised EHLO capabilities, plus PTR and forward-confirmed reverse DNS. Read-only — connects and quits without sending mail. Returns per-MX TLS protocol version, certificate subject/issuer/SANs/validity/SHA-256 fingerprint, expiry days, and FCrDNS details. Use to verify inbound mail TLS posture; pair with check_mta_sts for the policy layer. May be slower (10-30s) due to live SMTP handshakes. Measured from the IntoDNS.ai server: a host that does not answer there has startTlsSupported null (not measured), not false; do not report that as missing STARTTLS. No auth.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain name only, e.g. example.com (no URL, path, or port) |