Skip to content
Free, no sign-up

TLS-RPT record checker

Check whether a domain asks other mail servers to report failed encrypted deliveries, and where those reports go.

What this checks

  • The _smtp._tls TXT record, and that there's exactly one
  • The rua addresses reports are sent to (mailto: or https:)
  • The domain's MTA-STS set-up alongside, since the two work together

An example, explained

TXT record at _smtp._tls.example.co.uk
v=TLSRPTv1; rua=mailto:tls-reports@example.co.uk
v=TLSRPTv1
Marks the record as TLS-RPT. It must come first.
rua=
Where reports go: one or more mailto: or https: addresses, comma-separated.

What TLS reports tell you

TLS-RPT (RFC 8460) asks mail servers that deliver to a domain to send a daily report of their attempts: how many connections were encrypted successfully, and the reasons any weren't, such as an expired certificate or a host not in the MTA-STS policy. Google and Microsoft both send them.

On its own it changes nothing about delivery. Its value is that you hear about problems before they matter, which is why it belongs beside MTA-STS: run MTA-STS in testing mode, read the TLS reports, fix what they show, then enforce.

Common problems

  • No record: encryption failures happen silently.
  • No rua: the record exists but there's nowhere to send reports.
  • Nobody reads them: reports are JSON files, often gzipped, one per sender per day. Without something to read them they pile up unopened.

Domain Health Hub receives TLS reports at the same address as DMARC reports, reads the totals, deletes the file, and shows the results beside DMARC. More in the MTA-STS and TLS-RPT guide.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

Do I need MTA-STS to use TLS-RPT?

No, TLS-RPT works on its own, but the two are designed together. Reports are most useful while MTA-STS is in testing mode.

Who sends TLS reports?

Large mail providers including Google and Microsoft send them daily for domains that publish a TLS-RPT record.

Can reports go to another domain's mailbox?

Yes. Unlike DMARC, TLS-RPT doesn't need the receiving domain to authorise it.

Is my data kept when you receive reports?

For workspaces, we keep the totals and delete each report file after reading it. The free checker keeps nothing.

Read TLS reports beside DMARC.

Start a free 28-day trial: up to 3 domains, no card needed.