Live DNS check · same engine as the full SecLens score

TLS-RPT checker

TLS-RPT is how sending servers tell you that STARTTLS failed on the way to your MX. Without it, MTA-STS and DANE failures are silent. This checker reads _smtp._tls and reports whether a well-formed v=TLSRPTv1 record exists and whether a reporting destination is configured.

Public assessments are free. No account. The full 0–100 stack is included below the focused result.

1.62%
of mail-enabled Top-1M domains publish TLS-RPT
1.67%
have enforced transport security at all

Figures from the July 2026 Top-1M study.

FAQ

Common questions

What is TLS-RPT?

SMTP TLS Reporting (RFC 8460) is a TXT record at _smtp._tls.example.com. It asks sending MTAs to mail you daily JSON reports about STARTTLS success and failure when they deliver to your MX hosts.

Does a TLS-RPT record encrypt my mail?

No. It is telemetry. MTA-STS and DANE are the controls that resist downgrades. TLS-RPT tells you those controls are failing. A record without a usable rua= destination still produces nothing you can read.

Where is the record published?

TXT at _smtp._tls.example.com, typically v=TLSRPTv1; rua=mailto:tlsrpt@example.com or an https: URI. SecLens checks presence, syntax, and whether a reporting destination is configured, then still runs the rest of the stack.

Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.