ActiScan

TLS-RPT Record Checker

Instantly check any domain's TLS-RPT record and reporting address.

Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.

How to Use the TLS-RPT Checker

1

Enter a domain

No http:// prefix – just the domain itself (e.g. company.com).

2

Click Check

ActiScan looks up the domain's _smtp._tls TXT record live, over DNS.

3

Read the result

A pass/warn status plus a plain-English explanation of what to do next.

What Your Result Means

Record found with rua=Pass

TLS-RPT is configured with a reporting address – you'll be notified whenever an inbound mail server fails to negotiate TLS to this domain.

Record found, no rua=Warn

A TLS-RPT record exists but is missing rua=, so there's nowhere for reports to go. Add a reporting address to actually receive them.

No TLS-RPT record foundWarn

TLS-RPT isn't configured. If inbound mail servers ever fail to negotiate TLS to this domain – including because of an MTA-STS misconfiguration – nothing tells you it happened.

What is a TLS-RPT Record?

TLS-RPT (RFC 8460) is a DNS TXT record that tells other mail servers where to send reports when they fail to negotiate TLS while delivering mail to your domain. It doesn't enforce anything by itself – it's pure visibility, a daily aggregate report on connection failures and downgrades that would otherwise happen silently.

It's published at the _smtp._tls subdomain: for example.com, that's _smtp._tls.example.com. TLS-RPT complements MTA-STS: MTA-STS enforces TLS on inbound mail, but a misconfiguration – like an MX host missing from your policy file – can silently start bouncing legitimate mail with no report ever reaching you. TLS-RPT closes that gap by reporting every failure back to an address you control, whether or not MTA-STS is even deployed.

TLS-RPT Record Examples

Email reporting only

v=TLSRPTv1; rua=mailto:tls-reports@example.com

The most common setup – daily aggregate reports on TLS failures land in a mailbox you monitor.

Webhook reporting only

v=TLSRPTv1; rua=https://example.com/tls-reports

RFC 8460 also allows an HTTPS endpoint instead of email – useful if you want reports ingested straight into a monitoring pipeline.

Email and webhook

v=TLSRPTv1; rua=mailto:tls-reports@example.com,https://example.com/tls-reports

Destinations are comma-separated – send the same report to a mailbox and an endpoint at once.

Need to build your own? Use the free TLS-RPT generator.

TLS-RPT Record Tags Explained

TagWhat it doesExampleRequired?
vProtocol version. Must be the first tag.v=TLSRPTv1Required
ruaOne or more destinations for aggregate reports on TLS failures. Comma-separated mailto: addresses, https: webhook URLs, or a mix of both.rua=mailto:tls-reports@example.comRequired

How to Find Your TLS-RPT Record Manually

If you'd rather look it up yourself instead of using the checker above:

Using nslookup

nslookup -type=TXT _smtp._tls.yourdomain.com

Using dig

dig TXT _smtp._tls.yourdomain.com

Next Steps After Your Check

No record found?

Build a valid one in under a minute, no manual editing required.

TLS-RPT Generator →

Pair it with MTA-STS

TLS-RPT reports on failures; MTA-STS is what actually enforces TLS in the first place. Check whether this domain has it.

MTA-STS Checker →

Want ongoing monitoring?

ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.

Start free →

Frequently Asked Questions

Is this TLS-RPT checker free?

Yes – check any domain's TLS-RPT record for free, no signup required.

Do I need to own the domain I'm checking?

No. TLS-RPT records are published in public DNS, so anyone can look one up.

What's the difference between a mailto: and an https: rua= destination?

mailto: delivers the report as an email attachment; https: posts it to a webhook URL you control. Both are valid RFC 8460 destinations, and you can list more than one, comma-separated.

Why does my domain show "no record" right after I added one?

DNS changes take time to propagate – wait for the record's TTL to expire (often up to a few hours) and check again.

Where is a TLS-RPT record stored?

As a TXT record at the _smtp._tls subdomain – for example.com, that's _smtp._tls.example.com.

Use the free TLS-RPT checker as often as you need

Start free trial