Guide · TLS-RPT

Set up and analyse TLS reporting (TLS-RPT)

With TLS reporting (TLS-RPT) you find out whether other mail servers could deliver email to your domain encrypted. Google, Microsoft and other providers send daily reports for this – as JSON files that hardly anyone reads. Mailsecurity24 analyses them for you and shows problems with certificates, the MTA-STS policy or encryption at a glance.

How does TLS-RPT work?

You publish a TXT record at _smtp._tls.your-company.com with the address that should receive reports. Sending providers then summarise once a day how many connections to your mail servers were successfully encrypted and which errors occurred – such as expired certificates, missing STARTTLS or deviations from your MTA-STS policy.

Good to know: TLS-RPT is what makes it safe to switch MTA-STS from testing to enforce – only the reports show whether all connections really work.

TLS reporting in three steps

1. Publish the TLS-RPT record

Publish the TXT record _smtp._tls.your-company.com with v=TLSRPTv1; rua=mailto:…. The portal shows the right report address on your domain’s page.

2. Collect reports

The first reports arrive within one to two days. Mailsecurity24 assigns them to your domain automatically.

3. Fix errors

The analysis shows which providers had problems and why. Fix the cause and watch the rate over the following days.

Common causes in TLS reports

The reports often uncover problems nobody else would notice:

Good to know: TLS-RPT is worthwhile even without MTA-STS – you at least see whether connections to your mail servers are encrypted.

Free domain check

Is your domain protected against email spoofing?

In seconds we check DMARC, SPF, DKIM, MX, MTA-STS, TLS reporting and BIMI for your domain – free and without signing up.

  • No sign-up
  • Result in seconds
  • We do not store your domain

Frequently asked questions about TLS-RPT

It is worthwhile. Even without MTA-STS, the reports show whether connections are encrypted and whether your certificate is accepted. With MTA-STS they are essential.

Mainly large providers such as Google and Microsoft, plus other mail servers that support the standard. Smaller servers often send no reports.

Yes. The record can list several destinations separated by commas, for example your own address and Mailsecurity24’s.

Some connections could not be established with encryption. The analysis shows which provider and why – so you find the cause quickly.

Ready for secure email?

Try Mailsecurity24 free for 14 days. No payment details required.