What TLS-RPT does
SMTP TLS Reporting (RFC 8460) asks sending mail servers to tell you when they could not deliver to your domain over a properly encrypted connection: an expired certificate on an MX host, a host that stopped offering STARTTLS, an MTA-STS policy that does not match. Senders that support it collect these events and send one JSON report per day to the addresses you publish.
The record is a TXT record at _smtp._tls.<domain>, for example v=TLSRPTv1; rua=mailto:tls-reports@example.com. The rua tag takes one or more addresses separated by commas, each either a mailto: address or an https: endpoint that accepts the report by POST.
What this tool checks
It looks up the TXT record, makes sure there is exactly one TLS-RPT record, that it starts with v=TLSRPTv1, that rua is present, and that every address is a syntactically valid mailto: or https: URI. Plain http: endpoints and addresses without a scheme are flagged, because senders ignore them.
It does not send a test report and cannot know whether anybody reads the mailbox. Reports are machine-readable JSON, often gzip-compressed; most people point rua at a mailbox or a service that parses them.
Why it belongs next to MTA-STS
MTA-STS in enforce mode makes senders refuse delivery when TLS fails. Without TLS-RPT you would only hear about that from people whose mail did not arrive. Publish TLS-RPT first, run MTA-STS in testing mode, and switch to enforce when the reports are clean. TLS-RPT is also useful on its own and for domains that use DANE.