Free TLS-RPT Record Generator
Answer a couple of questions and get a valid TLS-RPT TXT record to publish at _smtp._tls.yourdomain.com — this gets you reports whenever an inbound mail server fails to negotiate TLS to your domain.
How to Use the TLS-RPT Generator
Add a destination
An email address, a webhook URL, or both – either works as an RFC 8460 rua= destination.
Click Generate
The generator builds a single TXT record combining every destination you entered.
Publish and verify
Add the record to DNS, then confirm it resolves with the TLS-RPT checker.
Choosing a Destination
Email (mailto:)
The most common destination – daily aggregate reports on TLS failures land as an attachment in a mailbox you monitor.
Webhook (https:)
RFC 8460 also allows an HTTPS endpoint alongside or instead of email – useful if you want reports ingested straight into a monitoring pipeline rather than read by hand.
What is a TLS-RPT Record?
TLS-RPT (RFC 8460) is a DNS TXT record that tells other mail servers where to send reports when they fail to negotiate TLS while delivering mail to your domain. It doesn't enforce anything by itself – it's pure visibility, a daily aggregate report on connection failures and downgrades that would otherwise happen silently.
It's published at the _smtp._tls subdomain: for example.com, that's _smtp._tls.example.com. TLS-RPT complements MTA-STS: MTA-STS enforces TLS on inbound mail, but a misconfiguration – like an MX host missing from your policy file – can silently start bouncing legitimate mail with no report ever reaching you. TLS-RPT closes that gap by reporting every failure back to an address you control, whether or not MTA-STS is even deployed.
TLS-RPT Record Examples
Email reporting only
v=TLSRPTv1; rua=mailto:tls-reports@example.com
The most common setup – daily aggregate reports on TLS failures land in a mailbox you monitor.
Webhook reporting only
v=TLSRPTv1; rua=https://example.com/tls-reports
Sends reports straight to an HTTPS endpoint instead of a mailbox.
Email and webhook
v=TLSRPTv1; rua=mailto:tls-reports@example.com,https://example.com/tls-reports
Destinations are comma-separated – send the same report to a mailbox and an endpoint at once.
TLS-RPT Record Tags Explained
| Tag | What it does | Example | Required? |
|---|---|---|---|
| v | Protocol version. Must be the first tag. | v=TLSRPTv1 | Required |
| rua | One or more destinations for aggregate reports on TLS failures. Comma-separated mailto: addresses, https: webhook URLs, or a mix of both. | rua=mailto:tls-reports@example.com | Required |
How to Publish & Verify
Add the generated record as a TXT record at _smtp._tls.yourdomain.com, then confirm it resolves:
Using nslookup
nslookup -type=TXT _smtp._tls.yourdomain.com
Using dig
dig TXT _smtp._tls.yourdomain.com
Next Steps
Verify what you published
Confirm the record resolves correctly with the free checker.
TLS-RPT Checker →Pair it with MTA-STS
TLS-RPT reports on failures; MTA-STS is what actually enforces TLS in the first place.
MTA-STS Generator →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this TLS-RPT generator free?
Yes – generate a TLS-RPT record for free, no signup required.
Should I use an email address or a webhook?
Email is simpler and works for most domains. A webhook makes sense if you already have somewhere to ingest and parse reports programmatically. You can also list both, comma-separated.
Can I add more than one email address?
Yes – enter as many as you need, comma-separated, and the generator combines them into one rua= value.
Does this generator check my DNS for me?
No – it only builds the record text. Publish it yourself, then use the TLS-RPT checker to confirm it resolves.
What if I already have a TLS-RPT record?
Generating a new one won't change your DNS automatically – you'll still need to replace the existing TXT record at _smtp._tls.yourdomain.com yourself.