A TLS-RPT record, so you hear about failed encryption from the senders who saw it.
When a sending server cannot negotiate TLS with your mail servers, nothing tells you by default. This record asks senders to report those failures once a day. Publish it before you move MTA-STS to enforce.
An email address or an https:// endpoint. List more than one to send every report to each of them.
No address for them yet? On Protect and above, DDMARC gives each domain its own reporting address and parses the reports for you.
Three things to know before relying on it.
It reports, it does not protect
TLS-RPT changes nothing about how mail is delivered. It only tells you about failures. MTA-STS or DANE is what makes senders refuse an unencrypted connection.
Reports arrive as compressed JSON
Senders send one report a day per sending organization, gzipped. A mailbox fills with attachments nobody opens unless something parses them.
Not every sender reports
Only senders that support TLS-RPT send reports, mostly the large mailbox providers. A clean report covers their traffic, not every server that sends you mail.
Frequently asked questions.
It asks sending mail servers to send you a daily report of their connections to your mail servers, including the ones that failed to negotiate TLS and why. It changes nothing about delivery. It only gives you visibility.
For how the reports read once they arrive, see the TLS reports guide.
DMARC Report Analyzer
Paste or upload a DMARC aggregate (RUA) report and see total volume, pass/fail rates, and which senders are failing. Runs in your browser.
DMARC Record Generator
Create a valid DMARC record for your domain. Configure policy, reporting emails, and advanced options.
SPF Record Generator
Build an SPF record to authorize your email senders. Includes common services and DNS lookup counter.
DKIM Key and Record Generator
Generate a DKIM key pair in your browser and get the TXT record to publish. The private key never leaves your device.
MTA-STS Record and Policy Generator
Build the _mta-sts TXT record and the mta-sts.txt policy file together, with MX patterns and max_age checked.
SPF Checker
Look up a domain's SPF record, walk every include, and count DNS lookups against the limit of 10.
Domain Checker
Check your domain's email authentication setup. See your SPF, DKIM, DMARC, and MTA-STS configuration.
DMARC Checker
Look up any domain's DMARC record and get every tag explained — policy, alignment, reporting, and coverage.
DKIM Checker
Check a domain's DKIM record by selector. See the key type, size, and each tag, with quick-picks for common providers.
MTA-STS & TLS-RPT Checker
Check a domain's MTA-STS policy record and TLS-RPT reporting — the pair that forces inbound mail over TLS.
BIMI Checker
Look up a domain's BIMI record, preview the logo, and confirm the VMC and DMARC enforcement it requires.
Reports are only useful once someone reads them.
Each sender mails a gzipped JSON file a day. On Protect and above, DDMARC parses them and shows which sending servers failed to negotiate TLS with your mail servers, why, and how often. The MTA-STS checker confirms the record resolved.