TLS-RPT Record Checker
Instantly check any domain's TLS-RPT record and reporting address.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the TLS-RPT Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan looks up the domain's _smtp._tls TXT record live, over DNS.
Read the result
A pass/warn status plus a plain-English explanation of what to do next.
What Your Result Means
Record found with rua=PassTLS-RPT is configured with a reporting address – you'll be notified whenever an inbound mail server fails to negotiate TLS to this domain.
Record found, no rua=WarnA TLS-RPT record exists but is missing rua=, so there's nowhere for reports to go. Add a reporting address to actually receive them.
No TLS-RPT record foundWarnTLS-RPT isn't configured. If inbound mail servers ever fail to negotiate TLS to this domain – including because of an MTA-STS misconfiguration – nothing tells you it happened.
What is a TLS-RPT Record?
TLS-RPT (RFC 8460) is a DNS TXT record that tells other mail servers where to send reports when they fail to negotiate TLS while delivering mail to your domain. It doesn't enforce anything by itself – it's pure visibility, a daily aggregate report on connection failures and downgrades that would otherwise happen silently.
It's published at the _smtp._tls subdomain: for example.com, that's _smtp._tls.example.com. TLS-RPT complements MTA-STS: MTA-STS enforces TLS on inbound mail, but a misconfiguration – like an MX host missing from your policy file – can silently start bouncing legitimate mail with no report ever reaching you. TLS-RPT closes that gap by reporting every failure back to an address you control, whether or not MTA-STS is even deployed.
TLS-RPT Record Examples
Email reporting only
v=TLSRPTv1; rua=mailto:tls-reports@example.com
The most common setup – daily aggregate reports on TLS failures land in a mailbox you monitor.
Webhook reporting only
v=TLSRPTv1; rua=https://example.com/tls-reports
RFC 8460 also allows an HTTPS endpoint instead of email – useful if you want reports ingested straight into a monitoring pipeline.
Email and webhook
v=TLSRPTv1; rua=mailto:tls-reports@example.com,https://example.com/tls-reports
Destinations are comma-separated – send the same report to a mailbox and an endpoint at once.
Need to build your own? Use the free TLS-RPT generator.
TLS-RPT Record Tags Explained
| Tag | What it does | Example | Required? |
|---|---|---|---|
| v | Protocol version. Must be the first tag. | v=TLSRPTv1 | Required |
| rua | One or more destinations for aggregate reports on TLS failures. Comma-separated mailto: addresses, https: webhook URLs, or a mix of both. | rua=mailto:tls-reports@example.com | Required |
How to Find Your TLS-RPT Record Manually
If you'd rather look it up yourself instead of using the checker above:
Using nslookup
nslookup -type=TXT _smtp._tls.yourdomain.com
Using dig
dig TXT _smtp._tls.yourdomain.com
Next Steps After Your Check
Pair it with MTA-STS
TLS-RPT reports on failures; MTA-STS is what actually enforces TLS in the first place. Check whether this domain has it.
MTA-STS Checker →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this TLS-RPT checker free?
Yes – check any domain's TLS-RPT record for free, no signup required.
Do I need to own the domain I'm checking?
No. TLS-RPT records are published in public DNS, so anyone can look one up.
What's the difference between a mailto: and an https: rua= destination?
mailto: delivers the report as an email attachment; https: posts it to a webhook URL you control. Both are valid RFC 8460 destinations, and you can list more than one, comma-separated.
Why does my domain show "no record" right after I added one?
DNS changes take time to propagate – wait for the record's TTL to expire (often up to a few hours) and check again.
Where is a TLS-RPT record stored?
As a TXT record at the _smtp._tls subdomain – for example.com, that's _smtp._tls.example.com.