What TLS-RPT does
SMTP TLS Reporting (RFC 8460) asks sending mail servers to tell you when they could not deliver to your domain over a properly encrypted connection: an expired certificate on an MX host, a host that stopped offering STARTTLS, an MTA-STS policy that does not match. Senders that support it collect these events and send one JSON report per day to the addresses you publish.
The record is a TXT record at _smtp._tls.<domain>, for example v=TLSRPTv1; rua=mailto:tls-reports@example.com. The rua tag takes one or more addresses separated by commas, each either a mailto: address or an https: endpoint that accepts the report by POST.