📊 TLS-RPT Checker

Verify TLS-RPT (SMTP TLS Reporting) configuration for any domain. TLS-RPT provides reports about TLS connection failures during email delivery.

What is TLS-RPT?

TLS-RPT (SMTP TLS Reporting) is a standard that allows mail servers to report TLS connection failures when attempting to deliver email to your domain. These reports help you identify and fix TLS configuration issues.

How TLS-RPT Works

  • You publish a DNS TXT record at _smtp._tls.yourdomain.com
  • The record specifies where to send TLS failure reports (email or HTTPS endpoint)
  • Sending mail servers that fail to establish TLS connections send daily reports
  • Reports are in JSON format and include details about failed connections

TLS-RPT and MTA-STS

TLS-RPT is commonly used alongside MTA-STS (Mail Transfer Agent Strict Transport Security). While MTA-STS enforces TLS for incoming mail, TLS-RPT provides visibility into any TLS failures that occur.

Report Contents

  • Organization sending the report
  • Time period covered
  • Policy applied (MTA-STS or DANE)
  • Failure counts and types
  • Specific error details