Free Tool
TLS-RPT Checker
Check your domain's TLS-RPT record configuration. Verify you're receiving reports about TLS failures in email delivery.
Free instant check — no signup required
What is TLS-RPT?
SMTP TLS Reporting (TLS-RPT) is a standard defined in RFC 8460 that provides a reporting mechanism for domains to receive feedback about TLS connection successes and failures when other mail servers deliver email to them. It is the companion reporting standard to MTA-STS and DANE.
Without TLS-RPT, domain owners have no visibility into whether email being delivered to their domain is encrypted in transit. If a sending server fails to establish a TLS connection due to certificate errors, misconfiguration, or an active attack, the domain owner would never know. TLS-RPT provides this critical feedback loop.
TLS-RPT reports are delivered as JSON files to an email address or HTTPS endpoint specified in your DNS TXT record. They include details about which sending servers experienced TLS failures, the type of failure, and the volume of affected sessions, enabling you to quickly diagnose and fix encryption issues.
Frequently Asked Questions
What is SMTP TLS Reporting (TLS-RPT)?
How do I set up TLS-RPT?
What does a TLS-RPT report contain?
What's the difference between TLS-RPT and DMARC reports?
How do I read TLS failure reports?
Need continuous TLS monitoring?
Get automatic alerts when your TLS-RPT configuration changes or breaks. Monitor TLS-RPT, MTA-STS, SPF, DKIM, DMARC, and 60 blacklists.
Start Monitoring Free