ActiScan

Free TLS-RPT Record Generator

Answer a couple of questions and get a valid TLS-RPT TXT record to publish at _smtp._tls.yourdomain.com — this gets you reports whenever an inbound mail server fails to negotiate TLS to your domain.

How to Use the TLS-RPT Generator

1

Add a destination

An email address, a webhook URL, or both – either works as an RFC 8460 rua= destination.

2

Click Generate

The generator builds a single TXT record combining every destination you entered.

3

Publish and verify

Add the record to DNS, then confirm it resolves with the TLS-RPT checker.

Choosing a Destination

Email (mailto:)

The most common destination – daily aggregate reports on TLS failures land as an attachment in a mailbox you monitor.

Webhook (https:)

RFC 8460 also allows an HTTPS endpoint alongside or instead of email – useful if you want reports ingested straight into a monitoring pipeline rather than read by hand.

What is a TLS-RPT Record?

TLS-RPT (RFC 8460) is a DNS TXT record that tells other mail servers where to send reports when they fail to negotiate TLS while delivering mail to your domain. It doesn't enforce anything by itself – it's pure visibility, a daily aggregate report on connection failures and downgrades that would otherwise happen silently.

It's published at the _smtp._tls subdomain: for example.com, that's _smtp._tls.example.com. TLS-RPT complements MTA-STS: MTA-STS enforces TLS on inbound mail, but a misconfiguration – like an MX host missing from your policy file – can silently start bouncing legitimate mail with no report ever reaching you. TLS-RPT closes that gap by reporting every failure back to an address you control, whether or not MTA-STS is even deployed.

TLS-RPT Record Examples

Email reporting only

v=TLSRPTv1; rua=mailto:tls-reports@example.com

The most common setup – daily aggregate reports on TLS failures land in a mailbox you monitor.

Webhook reporting only

v=TLSRPTv1; rua=https://example.com/tls-reports

Sends reports straight to an HTTPS endpoint instead of a mailbox.

Email and webhook

v=TLSRPTv1; rua=mailto:tls-reports@example.com,https://example.com/tls-reports

Destinations are comma-separated – send the same report to a mailbox and an endpoint at once.

TLS-RPT Record Tags Explained

TagWhat it doesExampleRequired?
vProtocol version. Must be the first tag.v=TLSRPTv1Required
ruaOne or more destinations for aggregate reports on TLS failures. Comma-separated mailto: addresses, https: webhook URLs, or a mix of both.rua=mailto:tls-reports@example.comRequired

How to Publish & Verify

Add the generated record as a TXT record at _smtp._tls.yourdomain.com, then confirm it resolves:

Using nslookup

nslookup -type=TXT _smtp._tls.yourdomain.com

Using dig

dig TXT _smtp._tls.yourdomain.com

Next Steps

Verify what you published

Confirm the record resolves correctly with the free checker.

TLS-RPT Checker →

Pair it with MTA-STS

TLS-RPT reports on failures; MTA-STS is what actually enforces TLS in the first place.

MTA-STS Generator →

Want ongoing monitoring?

ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.

Start free →

Frequently Asked Questions

Is this TLS-RPT generator free?

Yes – generate a TLS-RPT record for free, no signup required.

Should I use an email address or a webhook?

Email is simpler and works for most domains. A webhook makes sense if you already have somewhere to ingest and parse reports programmatically. You can also list both, comma-separated.

Can I add more than one email address?

Yes – enter as many as you need, comma-separated, and the generator combines them into one rua= value.

Does this generator check my DNS for me?

No – it only builds the record text. Publish it yourself, then use the TLS-RPT checker to confirm it resolves.

What if I already have a TLS-RPT record?

Generating a new one won't change your DNS automatically – you'll still need to replace the existing TXT record at _smtp._tls.yourdomain.com yourself.

Use the free TLS-RPT generator as often as you need

Start free trial