Short answer: Enter your domain and one or more report destinations (email addresses or https URLs) and the generator writes the TLS-RPT record: a TXT record at _smtp._tls.yourdomain with the value v=TLSRPTv1; rua=mailto:…. Sending servers then mail you a daily summary of TLS connections to your MX hosts, including failures.
Built and tested in Chromium on 6 Oct 2026; runs entirely in your browser.
Table of Contents
How to use the TLS-RPT generator
- Enter the domain that receives mail, for example
example.com. - Enter where reports should go. An email address becomes
mailto:address; anhttps://URL is used as it is. Separate several destinations with commas. - Press Generate TLS-RPT and publish the TXT record at the name shown.
- Check it with the TLS-RPT checker once DNS has updated.
The tool rejects plain http:// URLs (RFC 8460 supports only mailto and https) and percent-encodes commas, semicolons and exclamation marks inside URLs, which the RFC requires.
What the output means
| Output | Meaning |
|---|---|
| Record name | _smtp._tls.example.com: the fixed name RFC 8460 defines. |
| Record value | v=TLSRPTv1; must come first, then rua= with one or more destinations separated by commas. |
| Destinations | How many places reports can go. A sender may deliver to just one of them. |
Reports are JSON documents, usually gzipped, listing successful and failed TLS sessions per policy (MTA-STS or DANE) and the reason for each failure, such as a certificate that does not match the MX name or an expired certificate.
Examples
One mailbox:
_smtp._tls.example.com. TXT "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
A mailbox plus a reporting service that accepts HTTPS POST:
_smtp._tls.example.com. TXT "v=TLSRPTv1; rua=mailto:tls-reports@example.com,https://reports.example.net/tlsrpt"
TLS-RPT pairs with MTA-STS. Our MTA-STS generator can write both records at once if you fill in its report address field.
Reading a TLS-RPT report
Each report is a JSON document (RFC 8460 recommends gzip compression, media type application/tlsrpt+gzip). The fields worth looking at first:
| Field | What it tells you |
|---|---|
organization-name, date-range | Who sent the report and the period it covers. |
policy-type | sts (MTA-STS), tlsa (DANE) or no-policy-found. |
total-successful-session-count, total-failure-session-count | How many TLS connections to your MX hosts worked and how many failed. |
failure-details › result-type | Why sessions failed, for example starttls-not-supported, certificate-host-mismatch, certificate-expired, certificate-not-trusted, sts-policy-fetch-error or sts-webpki-invalid. |
receiving-mx-hostname, receiving-ip | Which of your MX hosts the failures were on. |
A sudden run of certificate-expired usually means a certificate renewal on the mail server did not reach the SMTP service; sts-policy-fetch-error means senders could not download your MTA-STS policy file.
Common mistakes
- Publishing two TLS-RPT records. If more than one TXT record at
_smtp._tlsstarts withv=TLSRPTv1, senders treat the domain as having no TLS-RPT policy. - Putting the record on the wrong name. It belongs at
_smtp._tls.example.com, not on the root domain or under_mta-sts. - Forgetting the mailto: prefix. A bare address is not a valid URI. The generator adds it for you.
- Sending reports to a mailbox nobody reads. Reports arrive daily from every large provider; use a dedicated mailbox or a reporting service.
- Expecting reports without MTA-STS or DANE. The reports are about TLS policies, so they are most useful once one of these is published.
Official documentation: RFC 8460: SMTP TLS Reporting · RFC 8461: MTA-STS
Related: TLS-RPT Checker · MTA-STS Checker · SMTP Test: Free STARTTLS, Certificate and Banner Check · Email Domain Health Check
See also: MTA-STS on cPanel and DirectAdmin: Policy File and TLS-RPT · MTA-STS Generator: TXT Record and Policy File
Frequently asked questions
What is a TLS-RPT record?
A TXT record at _smtp._tls.yourdomain that tells sending mail servers where to send daily reports about TLS connections to your MX hosts.
Can I send TLS-RPT reports to an address on another domain?
Yes. RFC 8460 does not require the extra authorisation record that DMARC uses for external report addresses.
Do I need MTA-STS to use TLS-RPT?
No, but the reports are about MTA-STS and DANE policies, so they are most useful when one of them is in place.
Can I list more than one destination?
Yes. Separate them with commas inside the rua= value. A sender may deliver to any one of them.
Why are commas in my URL encoded?
Commas separate destinations, so RFC 8460 requires commas, semicolons and exclamation marks inside a URL to be percent-encoded.