What is TLS-RPT (SMTP TLS Reporting)?
TLS-RPT (SMTP TLS Reporting, RFC 8460) is a DNS TXT record at _smtp._tls.domain that tells other mail servers where to send a daily report of TLS connections to your domain that failed or were downgraded. It is published independently of MTA-STS but is most useful paired with it: without an enforced policy, there is nothing to report a failure against.
The record
_smtp._tls.example.com. TXT "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
rua may be a mailto: address, an https: endpoint, or both, comma-separated. Reports arrive roughly daily as compressed JSON, one per receiving system that attempted to deliver mail to the domain.
What gets reported
A TLS-RPT report covers the connection, not the message: whether TLS negotiated, which certificate was presented, and whether an MTA-STS or DANE policy was in effect and honoured. It does not tell you anything about SPF, DKIM or DMARC, those are separate reports covered by DMARC’s own rua tag.
Why it matters without enforcement, too
Even in MTA-STS testing mode, or with no MTA-STS policy at all, TLS-RPT still reports plain negotiation failures: a certificate that expired, a cipher mismatch, a misconfigured load balancer terminating TLS incorrectly. Those are operational problems worth finding before a customer notices mail arrived without encryption.
TLS-RPT and Spamjadoo
Spamjadoo requests STARTTLS on every outbound connection and can require it for named sender or recipient domains. Publishing TLS-RPT is what turns a silent downgrade into a report you actually see, rather than something discovered only after the fact.
Last reviewed 12 September 2026 by Spamjadoo engineering.