# MTA-STS Policy Checker (`junipr/mta-sts-policy-checker`) Actor

Audit mta-sts policy checker inputs and return structured findings, evidence rows, and a buyer-ready report for SEO, developer, and operations teams.

- **URL**: https://apify.com/junipr/mta-sts-policy-checker.md
- **Developed by:** [junipr](https://apify.com/junipr) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $4.90 / 1,000 page auditeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## MTA-STS Policy Checker

Check supplied MTA-STS DNS, policy-file, HTTP-status, and MX-host evidence for enforcement readiness and coverage gaps.

### Inputs

- `domains`: Domain evidence with `txt`, `policy`, `policyStatus`, and `mxHosts`.
- `maxDomains`: Maximum paid domain rows to emit.
- `includeReport`: Create Markdown and JSON report artifacts.
- `maxChargeUsd`: Stop before the next PPE event would exceed the run budget.

```json
{
  "domains": [
    {
      "domain": "gmail.com",
      "txt": "v=STSv1; id=20190429T010101;",
      "policy": "version: STSv1\nmode: enforce\nmx: smtp.google.com\nmx: gmail-smtp-in.l.google.com\nmx: *.gmail-smtp-in.l.google.com\nmax_age: 86400",
      "policyStatus": 200,
      "mxHosts": ["gmail-smtp-in.l.google.com", "alt1.gmail-smtp-in.l.google.com"]
    }
  ],
  "maxDomains": 1,
  "includeReport": true,
  "maxChargeUsd": 1
}
```

### Dataset

Rows report DNS validity, policy reachability, policy mode, `max_age`, policy MX patterns, supplied-MX coverage, issues, warnings, and status. Missing MX evidence is reported explicitly rather than replaced with an assumed host.

### Billing

The pay-per-event billing events are `actor-start`, `page-audited`, `record-extracted`, `finding-emitted`, and `audit-report-generated`. Dataset and report output is charge-gated. A zero-dollar cap emits no paid output.

### Use Cases

- Verify an MTA-STS TXT record and policy version agree.
- Detect policy files that were observed as unreachable.
- Compare policy MX patterns with known inbound MX hosts.
- Identify testing-mode policies before enforcement rollout.
- Export domain-level rollout findings and evidence.

### Limitations

The actor evaluates supplied DNS, HTTP, policy, and MX observations. It does not perform DNS or HTTP requests. Wildcard coverage follows MTA-STS-style suffix matching against the supplied host list.

# Actor input Schema

## `domains` (type: `array`):

Domains with observed MTA-STS DNS, policy, and MX evidence.

## `maxDomains` (type: `integer`):

Hard cap for MTA-STS policy rows.

## `includeReport` (type: `boolean`):

Create charged Markdown and JSON report artifacts.

## `maxChargeUsd` (type: `number`):

Stop before an event would exceed this run budget.

## Actor input object example

```json
{
  "domains": [
    {
      "domain": "gmail.com",
      "txt": "v=STSv1; id=20190429T010101;",
      "policy": "version: STSv1\nmode: enforce\nmx: smtp.google.com\nmx: gmail-smtp-in.l.google.com\nmx: *.gmail-smtp-in.l.google.com\nmax_age: 86400",
      "policyStatus": 200,
      "mxHosts": [
        "gmail-smtp-in.l.google.com",
        "alt1.gmail-smtp-in.l.google.com"
      ]
    }
  ],
  "maxDomains": 1,
  "includeReport": true,
  "maxChargeUsd": 1
}
```

# Actor output Schema

## `dataset` (type: `string`):

Structured rows emitted by the actor.

## `report` (type: `string`):

Run summary report stored in the default key-value store.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("junipr/mta-sts-policy-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("junipr/mta-sts-policy-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call junipr/mta-sts-policy-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=junipr/mta-sts-policy-checker",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/TpLswfEq6ICjIzKJz/builds/qcHwbsjMChOt3SoyF/openapi.json
