Definition · DNS & Email Spoofing

What is TLS-RPT?

TLS-RPT (SMTP TLS Reporting) is a reporting standard, defined in RFC 8460, that gives domain owners visibility into TLS problems affecting email sent to their domain. Sending mail servers that support TLS-RPT generate daily aggregate reports describing successful and failed TLS connections, and deliver them to an address the domain owner publishes in DNS.

How TLS-RPT works

The domain publishes a DNS TXT record at _smtp._tls.example.com:

v=TLSRPTv1; rua=mailto:tlsrpt@example.com

Participating senders then send JSON-formatted aggregate reports covering each 24-hour period, listing the number of successful sessions and the details of any failures — certificate errors, STARTTLS negotiation failures, or MTA-STS and DANE policy violations.

Why it matters

Encryption policies are risky to enforce blind: a certificate mistake or misconfigured MX could silently block legitimate mail. TLS-RPT is the feedback loop that makes enforcement safe. The usual deployment path is to enable TLS-RPT first, deploy MTA-STS in testing mode, watch the reports, and only then switch to enforce.

This mirrors the role DMARC aggregate reports play for email authentication — reporting first, enforcement once the reports are clean. SurfaceLoop flags domains missing TLS-RPT records as part of its DNS and email security checks.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.