TLS-RPT asks mail servers that deliver to your domain to send you a daily report of any TLS problems they met. Enter a domain to check the _smtp._tls TXT record, its report addresses and whether MTA-STS is published too.
Table of Contents
What TLS-RPT does
When a sending server such as Gmail or Microsoft 365 cannot set up TLS with your MX, for example because of an expired certificate or a name mismatch, it records the failure. With TLS-RPT published, it sends you a daily JSON summary of successes and failures, which is often the first sign of a broken mail certificate.
Record syntax
Publish one TXT record at _smtp._tls.example.com with the value v=TLSRPTv1; rua=mailto:tlsrpt@example.com. Several destinations can be listed separated by commas, and an https:// URL can receive reports by POST. More than one TLS-RPT record makes the policy invalid.
TLS-RPT with MTA-STS and DANE
TLS-RPT does not change delivery on its own. It is most useful with MTA-STS or DANE, which make TLS mandatory: the reports show failures before mail starts bouncing in enforce mode.
TLS-RPT Checker at a glance



Official documentation: RFC 8460 (SMTP TLS Reporting), RFC 8461 (MTA-STS).
Related guides: SPF DKIM DMARC cPanel DNS: Easy Setup · DirectAdmin Old Certificate After Renewal: 3 Easy Service Fixes · Warm Up New Mail Server IP Without Spam Problems.
Frequently asked questions
Where do the reports come from?
Large mail providers such as Google and Microsoft send them once a day as gzipped JSON attachments. Smaller senders often do not send reports at all.
Can I use the same mailbox as for DMARC reports?
Yes, but a separate mailbox or a report service makes the JSON files easier to process. The address can be on another domain without extra DNS records.
Do I need MTA-STS to use TLS-RPT?
No, TLS-RPT works alone and reports failures for opportunistic TLS too. It is most valuable together with MTA-STS or DANE.