TLS-RPT record checker

Check the SMTP TLS Reporting record (RFC 8460) at _smtp._tls.<domain>: the version tag and every rua address that reports are sent to.

What TLS-RPT does

SMTP TLS Reporting (RFC 8460) asks sending mail servers to tell you when they could not deliver to your domain over a properly encrypted connection: an expired certificate on an MX host, a host that stopped offering STARTTLS, an MTA-STS policy that does not match. Senders that support it collect these events and send one JSON report per day to the addresses you publish.

The record is a TXT record at _smtp._tls.<domain>, for example v=TLSRPTv1; rua=mailto:tls-reports@example.com. The rua tag takes one or more addresses separated by commas, each either a mailto: address or an https: endpoint that accepts the report by POST.

What this tool checks

It looks up the TXT record, makes sure there is exactly one TLS-RPT record, that it starts with v=TLSRPTv1, that rua is present, and that every address is a syntactically valid mailto: or https: URI. Plain http: endpoints and addresses without a scheme are flagged, because senders ignore them.

It does not send a test report and cannot know whether anybody reads the mailbox. Reports are machine-readable JSON, often gzip-compressed; most people point rua at a mailbox or a service that parses them.

Why it belongs next to MTA-STS

MTA-STS in enforce mode makes senders refuse delivery when TLS fails. Without TLS-RPT you would only hear about that from people whose mail did not arrive. Publish TLS-RPT first, run MTA-STS in testing mode, and switch to enforce when the reports are clean. TLS-RPT is also useful on its own and for domains that use DANE.

How to use this tool

  1. Enter the domain. Type or paste a domain name such as example.com. A full URL works too: the scheme, path and a leading www are removed.
  2. Look up the record. The tool queries the TXT record at _smtp._tls.<domain>.
  3. Check the report addresses. The version tag and every rua address are validated: mailto: or https:, nothing else.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • TLS-RPT recorddig _smtp._tls.example.com TXT +short
  • Windowsnslookup -type=TXT _smtp._tls.example.com

FAQ

What is a TLS-RPT record?

A TXT record at _smtp._tls.<domain> that tells sending mail servers where to send daily reports about TLS failures when delivering to your domain. It looks like v=TLSRPTv1; rua=mailto:tls-reports@example.com.

Can rua point to another domain?

Yes. Unlike DMARC, RFC 8460 does not define an authorization record for external report addresses, so a mailbox at a reporting service works without extra DNS records.

I published the record but get no reports. Why?

Only some senders produce reports, they send at most one per day, and only when they delivered mail to your domain in that period. Low-volume domains can wait days for the first one.

Do I need TLS-RPT if I do not use MTA-STS?

It still reports STARTTLS and certificate failures seen by senders that support it, so it is useful before and without MTA-STS.