Skip to content
Spamjadoo

TLS-RPT checker

TLS-RPT (SMTP TLS Reporting) is a DNS record that tells other mail servers where to send a daily report about TLS connections to your domain that failed or were downgraded. This tool fetches the record and shows where those reports go.

Live query, no signup. Results are never stored against your account. Try .

What this tool checks

It fetches the TXT record at _smtp._tls. plus the domain, confirms exactly one v=TLSRPTv1 record exists, and reads the rua= tag for the report destination. Report URIs must be mailto: or https:.

Why TLS failures matter

SMTP negotiates TLS opportunistically by default: a sender that cannot negotiate it, or is actively downgraded by a network attacker, silently falls back to plaintext instead of refusing to send. Without TLS-RPT you would never know it happened. With it, receivers tell you.

TLS-RPT and Spamjadoo

Spamjadoo requests STARTTLS on every outbound connection and can require it for named sender domains. Publishing TLS-RPT closes the loop: you get told when a receiver could not hold up their end, instead of finding out from a customer complaint.

Questions people ask

What is the difference between TLS-RPT and DMARC reports?
DMARC reports cover authentication (SPF/DKIM) on mail claiming your domain. TLS-RPT reports cover the connection itself: whether senders could negotiate TLS to your mail servers at all. They are unrelated records with unrelated report formats.
Do I need MTA-STS to use TLS-RPT?
No, they are independent, but TLS-RPT is far more useful paired with MTA-STS: without an enforced policy, a downgrade attack does not generate a failure report because nothing was expected to fail.
What do I do with the reports?
They arrive as compressed JSON, roughly daily, from each receiver that sends you mail. A summary-and-alerting tool for TLS-RPT (some MTA-STS providers include one) turns them into something you would actually read; raw JSON at volume is not practical by hand.