TLS-RPT
TLS-RPT (RFC 8460) delivers daily JSON reports on TLS delivery to your mail domain —
successful, policy-compliant sessions as well as negotiation, MTA-STS and DANE failures.
RFC 8460 §4.2.1 calls the success count a “heartbeat … that signifies
reporting is functional”, so reports keep arriving while everything is fine. The
record is a TXT at _smtp._tls.<domain> and pairs naturally with MTA-STS
or DANE.
Exactly one TLS-RPT record. RFC 8460 §3: TXT records at
_smtp._tls that do
not begin with v=TLSRPTv1; are discarded, and if the number of remaining
records “is not one, senders MUST assume the recipient domain does not implement
TLSRPT”. So this record must REPLACE an existing v=TLSRPTv1 record —
delete the old one, do not add this one beside it (an unrelated TXT record at the same
name is harmless). Several destinations belong in this one record as a comma-separated
rua= list.
Records are built in your browser; “Load current record” has our server look up your domain’s DNS. Record Studio · Verify the result with the domain security check