What this check looks at
TLS-RPT (SMTP TLS Reporting) is a DNS record that asks sending servers to email you aggregate reports about their TLS connections to your domain - including failures. This check looks for the record at _smtp._tls.yourdomain.com and reports whether it's published.
Why it matters
TLS delivery problems are silent by default. If your MX certificate expires, or an MTA-STS policy starts causing senders to refuse delivery, the mail just doesn't arrive and nobody tells you. TLS-RPT turns that silence into actionable reports, so you find out about a downgrade or certificate issue from the senders themselves.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| TLS-RPT published | Pass | The domain receives reports about TLS delivery problems. |
| No TLS-RPT record | Info | Optional. Add one to get visibility into TLS failures. |
How to fix it
Add a single TXT record:
Host _smtp._tls
Value v=TLSRPTv1; rua=mailto:tlsrpt@yourdomain.com
It pairs naturally with MTA-STS: publish the policy to require TLS, and TLS-RPT to learn when something breaks it.