TLS Reports

TLS-RPT Checker and Generator

Check a domain's SMTP TLS reporting record and generate a simple TLS-RPT record if secure-delivery reports are not configured.

Step 1

Start Here

Enter a domain and run TLS-RPT Checker and Generator.

Uses public DNS. Recent DNS changes can take time to appear.

Step 2

Review the TLS-RPT Checker Result

Review the status, warnings, and recommended actions shown in the result panel.

Ready When You Are

Run TLS-RPT Checker and Generator to see the TLS-RPT Checker result and next actions.

About TLS-RPT Checker and Generator

TLS-RPT is a reporting record for domains that want to receive reports about TLS delivery problems. It is commonly used with MTA-STS so domain owners can see when other mail servers had trouble sending encrypted mail to them. The TLS-RPT checker reviews the _smtp._tls DNS record and can help generate a clean starter record. Read MTA-STS and TLS Reporting before publishing changes.

A TLS-RPT record is useful only when the report destination is monitored by someone who can act on failures. The TLS-RPT checker explains missing records, duplicate records, and report addresses that need review. If you are not responsible for the domain's inbound mail setup, share the TLS-RPT result with the person who manages DNS or mail security. TLS and Secure Sending explains the practical meaning of TLS in email.

What TLS-RPT Checker and Generator Checks

  • TLS-RPT TXT lookup at _smtp._tls.domain
  • Missing or duplicate TLS-RPT records
  • Report destination review
  • mailto and HTTPS destination checks
  • Suggested starter record when missing
  • Plain-English reporting guidance

Questions

Does TLS-RPT enforce secure delivery?

No. TLS-RPT only asks other mail systems to send reports about secure-delivery problems. MTA-STS is the policy that can ask senders to enforce TLS.

Where should TLS reports go?

Use a monitored mailbox or a reporting service that can process JSON reports. Do not send reports to an inbox nobody checks.