TLS-RPT Make transport failures visible
TLS-RPT lets sending mail servers report when an encrypted delivery fails. This view creates the early warning system without which MTA-STS and DANE would be operated blindly.
_smtp._tls.example.de. IN TXT "v=TLSRPTv1; rua=mailto:tls-rpt@conbool.com"Without TLS-RPT, a failed transport encryption stays invisible. Only the reports make problems measurable before messages are lost.
MTA-STS and DANE can block deliveries when something is wrong. TLS-RPT answers the decisive question before and after: where exactly does the encryption fail, and which sender is reporting a problem? It is precisely this visibility that keeps an overly strict policy from silently holding back legitimate mail.
What TLS-RPT is
TLS-RPT stands for SMTP TLS Reporting and is standardized in RFC 8460. A TXT record under _smtp._tls of the domain names an address to which sending servers deliver aggregated reports. These reports show how many connections were established with encryption and which ones failed due to a certificate or TLS problem.
Why reports are indispensable
Transport security without feedback is a risk. TLS-RPT closes this gap.
Safe rollout
In the testing mode of MTA-STS, the reports show whether all senders encrypt cleanly before the policy is set to enforce.
Early warning
An expired certificate or a broken TLS configuration stands out immediately, instead of only through missing messages.
Evidence
Over time, the reports demonstrate that email transport is actually encrypted, and they support audits.
Evaluate reports with Conbool
Raw reports in JSON format are unwieldy. Conbool MailGuard turns them into actionable insights.
Receipt and storage
The reports from the large senders are received centrally and retained.
Preparation
Success and failure rates are presented clearly by sender and time period.
Failure causes
Failed connections are categorized by cause, such as certificate errors or missing TLS support.
Interplay with MTA-STS
The evaluation feeds directly into the decision on whether a policy is tightened or observed for now.
Frequently asked questions about TLS-RPT
What does TLS-RPT mean?
How is TLS-RPT set up?
Does TLS-RPT block emails?
Who sends the reports?
Is TLS-RPT worthwhile without MTA-STS or DANE?
How can the TLS-RPT record be checked?
More building blocks of transport security
MTA-STS
Enforced TLS encryption, whose rollout is safeguarded by TLS-RPT.
DANE and TLSA
Cryptographically anchored certificate binding, mandatory under BSI TR-03108.
Directory harvesting protection
Defense against attacks that harvest valid email addresses at the server.
MailGuard
The email security gateway that bundles all transport and content protection functions.
No longer flying blind on transport failures
The free Mail Check shows whether TLS-RPT and the transport encryption of your own domain are set up correctly.