TLS-RPT record checker

Read the TLS-RPT record at _smtp._tls.domain, check it against RFC 8460, and see exactly where senders will deliver their daily TLS reports. Free, no sign-up, runs in your browser.

TLS-RPT is optional, but it is how you find out an MTA-STS policy or a certificate is failing before mail is lost.

How it works

A feedback channel for encrypted delivery

TLS-RPT (RFC 8460) asks sending servers to report, once a day, how encryption went when they delivered mail to you: how many sessions negotiated TLS, how many failed, and why. Publishing it changes nothing about delivery. It is a feedback channel, not a policy.

What it buys you is warning. An expired certificate, a mail host that stopped offering STARTTLS, or an MTA-STS policy that no longer matches your MX records all show up in these reports days before anyone complains about missing mail.

v=TLSRPTv1

Must come first and is case-sensitive: v=tlsrptv1 makes senders ignore the record.

rua=mailto:

Reports arrive as gzipped JSON attachments. Use a mailbox or a reporting service that can parse them.

rua=https:

Reports are POSTed to an HTTPS endpoint instead.

One record only

Two TLS-RPT records at the same name and senders ignore both.

FAQ

Common questions.

Who sends TLS reports?

Google, Microsoft and several other large providers. Expect one JSON report per sender per day once the record is live.

Do I need MTA-STS to use TLS-RPT?

No. TLS-RPT reports on opportunistic TLS too, but it is most useful alongside MTA-STS or DANE, where a TLS failure means mail is refused.

Can reports go to another domain?

Yes, unlike DMARC reports, TLS-RPT needs no authorization record on the receiving domain.

For agents and pipelines

The same check, as an API and an MCP tool.

Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.

tls-rpt.sh
curl "https://powerline.ai/api/tools/tls-rpt?domain=example.com"
More free tools

Keep going.

MTA-STS Checker

Fetch the MTA-STS policy, check its mode and max_age, and confirm it covers every MX host.

Email Domain Check

SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.

DMARC Checker

Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.

DMARC Report Analyzer

Drop in DMARC aggregate reports (XML, .gz, .zip) to see pass rates, failing sources and what to fix.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools