Glossary

What is TLS-RPT?

Delivers reports when TLS delivery to your mail servers fails.

Written by the SkyQon engineering team · Last verified 4 August 2026

Why it matters

MTA-STS and DANE fail at the sending end, where you have no visibility. TLS-RPT is the feedback channel: participating senders report back, daily, when TLS delivery to your mail servers failed and what went wrong.

The standard

RFC 8460 (2018). A DNS TXT record at _smtp._tls.<domain> carrying one or more rua destinations, which receive aggregated JSON reports of TLS delivery outcomes.

Official text: RFC 8460

How it fails

TLS-RPT has no failure mode of its own — it either exists or it does not. The practical failure is publishing it and never processing the reports, turning a diagnostic channel into an unread mailbox. Worth knowing: unlike DMARC, TLS-RPT defines no external-destination authorisation record, so pointing reports at a third-party address requires no confirmation from that party.

Related terms

Check this on your own domain

SkyQon reads the same public signals described on this page and scores them for your domain. No account, no agent, nothing to install — a scored report by email in minutes.