MTA-STS enforce vs. testing: know before you switch
RFC 8461 defines two modes: testing and enforce
in testing mode, failures are reported via TLS-RPT but mail still delivers
in enforce mode, the sending server must abort if TLS negotiation fails
I always recommend at least 30 days in testing mode with TLS-RPT active before switching
the reports show you exactly who will break
no guessing required

