MTA-STS policy host

ydfnzp70bb2qsdw5.mta-sts.rua.emailengine.app

This name is the CNAME target of one RUA Reports account. It serves the MTA-STS policy files of that account's domains, and nothing else. The certificate you see was issued for it on purpose: your setup works.

To publish a policy for a domain:

  1. Enable hosting on the domain's MTA-STS tab and save a policy.
  2. Add a CNAME from mta-sts.<your domain> to this name.
  3. Publish the _mta-sts TXT record with the policy id shown on the tab.

Sending servers then read https://mta-sts.<your domain>/.well-known/mta-sts.txt.