Skip to main content

Free tools

TLS-RPT checker

Enter the domain that publishes TLS-RPT (usually the same domain as your MX records).

Back to Email authentication tools

What this checks

TLS-RPT TXT at _smtp._tls.domain, rua reporting addresses, and record syntax.

Why it matters

TLS-RPT surfaces TLS negotiation failures senders encounter when delivering to your domain — essential when rolling out MTA-STS.

Run check

Live diagnostic — results run from MailFleet tool APIs or locally in your browser.

Security verification

Required to prevent automated abuse of public tools.

Verification challenge

Results

Common issues

  • Publishing TLS-RPT without a monitored rua mailbox.
  • Syntax errors in the _smtp._tls TXT record.
  • Enabling MTA-STS enforce before reviewing TLS-RPT failure reports.

How to fix

  • Publish a valid TLS-RPT TXT record with working aggregate report addresses.
  • Review reports during MTA-STS testing mode before enforcement.
  • Pair with MX and MTA-STS checks on the same domain.

How MailFleet helps

Use TLS-RPT alongside MailFleet outbound diagnostics when operating domains that both send campaigns and receive inbound mail.

Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.

For regulatory context on commercial email in the United States, see the FTC CAN-SPAM compliance guide.

Frequently asked questions

TLS-RPT is strongly recommended when using MTA-STS so you see TLS failures before enforcing strict policies.

Get started

Prepare and control campaigns with MailFleet

Run integrated diagnostics, manage providers, and monitor campaigns from a professional desktop app.

Available on

  • Windows 10+
  • macOS 12+
  • Linux (DEB & RPM)

Same desktop experience across every platform — one workflow for your entire team.