What is TLS-RPT?
Delivers reports when TLS delivery to your mail servers fails.
Written by the SkyQon engineering team · Last verified 4 August 2026
Why it matters
MTA-STS and DANE fail at the sending end, where you have no visibility. TLS-RPT is the feedback channel: participating senders report back, daily, when TLS delivery to your mail servers failed and what went wrong.
The standard
RFC 8460 (2018). A DNS TXT record at _smtp._tls.<domain> carrying one or more rua destinations, which receive aggregated JSON reports of TLS delivery outcomes.
Official text: RFC 8460
How it fails
TLS-RPT has no failure mode of its own — it either exists or it does not. The practical failure is publishing it and never processing the reports, turning a diagnostic channel into an unread mailbox. Worth knowing: unlike DMARC, TLS-RPT defines no external-destination authorisation record, so pointing reports at a third-party address requires no confirmation from that party.
Related terms
Check this on your own domain
SkyQon reads the same public signals described on this page and scores them for your domain. No account, no agent, nothing to install — a scored report by email in minutes.