MTA-STS policy file missing
https://mta-sts.<domain>/.well-known/mta-sts.txt was not a published policy.
Why it matters
A DNS record without the policy file does not enforce TLS for inbound mail.
What to do
Publish a version STSv1 policy at that URL over HTTPS.
Reference
MTA-STS lets receiving domains require TLS for inbound email.