TLS-RPT Checker and Generator
Check a domain's SMTP TLS reporting record and generate a simple TLS-RPT record if secure-delivery reports are not configured.
Start Here
Enter a domain and run TLS-RPT Checker and Generator.
Review the TLS-RPT Checker Result
Review the status, warnings, and recommended actions shown in the result panel.
Ready When You Are
Run TLS-RPT Checker and Generator to see the TLS-RPT Checker result and next actions.
About TLS-RPT Checker and Generator
TLS-RPT is a reporting record for domains that want to receive reports about TLS delivery problems. It is commonly used with MTA-STS so domain owners can see when other mail servers had trouble sending encrypted mail to them. The TLS-RPT checker reviews the _smtp._tls DNS record and can help generate a clean starter record. Read MTA-STS and TLS Reporting before publishing changes.
A TLS-RPT record is useful only when the report destination is monitored by someone who can act on failures. The TLS-RPT checker explains missing records, duplicate records, and report addresses that need review. If you are not responsible for the domain's inbound mail setup, share the TLS-RPT result with the person who manages DNS or mail security. TLS and Secure Sending explains the practical meaning of TLS in email.
What TLS-RPT Checker and Generator Checks
- TLS-RPT TXT lookup at _smtp._tls.domain
- Missing or duplicate TLS-RPT records
- Report destination review
- mailto and HTTPS destination checks
- Suggested starter record when missing
- Plain-English reporting guidance
Questions
Does TLS-RPT enforce secure delivery?
No. TLS-RPT only asks other mail systems to send reports about secure-delivery problems. MTA-STS is the policy that can ask senders to enforce TLS.
Where should TLS reports go?
Use a monitored mailbox or a reporting service that can process JSON reports. Do not send reports to an inbox nobody checks.