Definition · DNS & Email Spoofing
What is TLS-RPT?
TLS-RPT (SMTP TLS Reporting) is a reporting standard, defined in RFC 8460, that gives domain owners visibility into TLS problems affecting email sent to their domain. Sending mail servers that support TLS-RPT generate daily aggregate reports describing successful and failed TLS connections, and deliver them to an address the domain owner publishes in DNS.
How TLS-RPT works
The domain publishes a DNS TXT record at _smtp._tls.example.com:
v=TLSRPTv1; rua=mailto:tlsrpt@example.com
Participating senders then send JSON-formatted aggregate reports covering each 24-hour period, listing the number of successful sessions and the details of any failures — certificate errors, STARTTLS negotiation failures, or MTA-STS and DANE policy violations.
Why it matters
Encryption policies are risky to enforce blind: a certificate mistake or misconfigured MX could silently block legitimate mail. TLS-RPT is the feedback loop that makes enforcement safe. The usual deployment path is to enable TLS-RPT first, deploy MTA-STS in testing mode, watch the reports, and only then switch to enforce.
This mirrors the role DMARC aggregate reports play for email authentication — reporting first, enforcement once the reports are clean. SurfaceLoop flags domains missing TLS-RPT records as part of its DNS and email security checks.