TLS-RPT check

If a sender can't reach you over TLS, you'd normally never know. TLS-RPT asks senders to send you a report when that happens - so you can spot a broken certificate or downgrade before it costs you mail.

What this check looks at

TLS-RPT (SMTP TLS Reporting) is a DNS record that asks sending servers to email you aggregate reports about their TLS connections to your domain - including failures. This check looks for the record at _smtp._tls.yourdomain.com and reports whether it's published.

Why it matters

TLS delivery problems are silent by default. If your MX certificate expires, or an MTA-STS policy starts causing senders to refuse delivery, the mail just doesn't arrive and nobody tells you. TLS-RPT turns that silence into actionable reports, so you find out about a downgrade or certificate issue from the senders themselves.

How the diagnostic grades it

ResultSeverityWhat it means
TLS-RPT publishedPassThe domain receives reports about TLS delivery problems.
No TLS-RPT recordInfoOptional. Add one to get visibility into TLS failures.

How to fix it

Add a single TXT record:

Host   _smtp._tls
Value  v=TLSRPTv1; rua=mailto:tlsrpt@yourdomain.com

It pairs naturally with MTA-STS: publish the policy to require TLS, and TLS-RPT to learn when something breaks it.

Related checks

MTA-STS · Inbound MX STARTTLS · TLS in transit

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free