TLS-RPT record missing: how to add it
What TLS-RPT reports tell you, why a missing, duplicate or address-less record means you hear nothing, and how to publish one correctly.
By the Domain Health Hub team · Updated
- TLS-RPT (RFC 8460) asks senders to send daily reports of failed encrypted deliveries to you.
- It's one TXT record at _smtp._tls.<domain> with an rua= address.
- No record, more than one, or no rua= means no reports.
What the error means
TLS-RPT (SMTP TLS Reporting) lets a domain ask sending servers to report when they couldn't deliver to it securely: a certificate problem, a failed STARTTLS, or an MTA-STS policy they couldn't fetch. It's a TXT record at _smtp._tls.<domain>:
v=TLSRPTv1; rua=mailto:tls-reports@example.com
We raise this when there's no record, more than one (RFC 8460 says senders then treat the domain as not using TLS-RPT), or a record with no rua= address to send reports to.
Why it matters
Without reports, encrypted delivery failures are invisible: a sender falls back to plain text, or with MTA-STS enforced refuses to deliver, and nobody tells you. Reports are also how you decide when testing mode is ready for enforce.
Each report covers one day from one sender. It counts the sessions that succeeded and failed, names the policy the sender applied, and gives a result type for each failure, such as a certificate that has expired, a name that doesn't match, or a policy file that couldn't be fetched. That's usually enough to find the cause without asking the sender.
How to confirm it
Look up TXT records at _smtp._tls.<domain>. There should be exactly one, starting v=TLSRPTv1, with an rua= of mailto: or https:.
How to fix it
Add the record with a mailbox that someone, or something, reads. The reports are compressed JSON, so a tool that parses them is far easier than reading them by hand. If there are two records, merge their addresses into one, separated by a comma.
Cloudflare DNS
Add a TXT record with the name _smtp._tls and the value above. If the record is a CNAME to our hosted record, leave it DNS only.
Questions
Is TLS-RPT only for MTA-STS?
No. Reports cover failed TLS connections whether or not you use MTA-STS, though they matter most when you're about to enforce.
Who sends the reports?
Large providers such as Google and Microsoft send them once a day, as JSON files. Smaller servers mostly don't.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.