TLS-RPT checker

Checks the _smtp._tls TXT record - reporting destinations for TLS connection failures.

1 · Input


What TLS-RPT reports on

RFC 8460 defines a way for sending mail servers to report back when a TLS connection to a domain's mail servers failed or could not be negotiated as expected - the visibility half of the MTA-STS/DANE picture. Without it, a domain has no way to know its TLS enforcement is causing legitimate mail to fail somewhere, since a broken MTA-STS policy fails closed and silently on the sending side.

What is checked

  • The _smtp._tls.domain TXT record and its v=TLSRPTv1 version tag
  • The rua= reporting destinations, and whether each is a valid mailto: or https: URI
  • Duplicate records - RFC 8460 treats more than one as invalid

Related tools

See MTA-STS checker - TLS-RPT reports on the connections MTA-STS is meant to protect, so the two are normally deployed together.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.