This error indicates (per RFC 8461 Section 3.3) that the subdomain setup for the MTA-STS policy (mta-sts.domain.com) DOES NOT have a valid certificate or the certificate has expired. Without a valid, non-expired certificate (issued by a trusted Certificate Authority), the MTA-STS policy is invalid.
How can I resolve this issue?
-
Purchase or renew an X.509 certificate for the HTTPS server hosting the subdomain
-
Certificate MUST be from a trusted Certificate Authority