Free diagnostic toolReviewed 2026-08-13By HostWithShery technical editorial

TLS-RPT Checker

Retrieve SMTP TLS reporting configuration and show where aggregate transport reports are sent.

Live tool

TLS-RPT Checker

Run the public check first. The explanation below tells you how to interpret and repair the result.

No accountPublic evidence only
Live public check
No account · Public configuration only
Readable result firstRaw data stays availableRelated repair paths included
On this page

TLS-RPT Checker: the question this tool answers

Retrieve SMTP TLS reporting configuration and show where aggregate transport reports are sent. The live result starts with _smtp._tls TXT, then uses rua destinations and syntax to confirm or challenge the first interpretation. A healthy result here is intentionally scoped to business-email DNS and mail authentication; it does not claim that unrelated parts of the domain are healthy.

  • _smtp._tls TXT
  • rua destinations
  • syntax

How to read the _smtp._tls TXT, rua destinations and syntax evidence

Start with the value that directly controls the failing service, then use the other signals to confirm or challenge that interpretation. A single record or response can look correct while another hostname, IP family, redirect or mail-authentication path still fails. The tool therefore keeps the raw observed value visible and explains how the signals relate.

  • _smtp._tls TXTTest the hostname actually requested, its certificate dates and SAN coverage, and the TLS handshake. Root and www can serve different certificates.
  • Rua destinationsVerify rua destinations from the public Internet and compare it with the value the responsible provider says should be live.
  • SyntaxVerify syntax from the public Internet and compare it with the value the responsible provider says should be live.

Common tls-rpt checker failure patterns

The most useful warnings are mismatches rather than isolated missing fields. _smtp._tls TXT can be absent or stale; rua destinations can point somewhere different from the expected provider; and syntax can reveal a second path that behaves differently. If public sources disagree, first decide whether the difference comes from authoritative data, caching, a separate hostname, IPv6, or another protocol layer before editing configuration.

What to change — and what not to change

Change the smallest setting that the evidence proves is wrong. Compare the observed _smtp._tls TXT with the current value supplied by the responsible provider, save the existing value, make one correction, and retest. Do not replace nameservers, delete unrelated MX/TXT records, disable TLS controls or remove IPv6 simply because TLS-RPT Checker shows a warning in another layer. Broad changes can turn one isolated problem into several independent outages.

How HostWithShery runs TLS-RPT Checker

The submitted public input is normalized and validated before any server-side request is made. HostWithShery then obtains _smtp._tls TXT and rua destinations using the appropriate public DNS, HTTP, TLS or mail protocol and adds syntax where it materially changes the interpretation. URL-based checks are restricted to public destinations, and redirect targets are revalidated instead of being trusted automatically.

How to interpret conflicting tls-rpt checker signals

When _smtp._tls TXT looks correct but rua destinations or syntax disagrees, do not treat the whole domain as broken. Isolate the public path that differs, identify whether it belongs to business-email DNS and mail authentication, and verify that path against the authoritative provider value before making a change. HostWithShery keeps these signals separate so a healthy value in one layer cannot mask a failure in another.

When a tls-rpt checker result is inconclusive

This is a public-configuration diagnostic. Network filtering, private control-panel settings, split-horizon DNS, provider-internal state and transient routing conditions can limit what can be confirmed from outside the account. Public diagnostics cannot see private control-panel state, unpublished origin addresses, provider account status or split-horizon/internal DNS. If the remote service times out, blocks automated requests or hides a signal, the result stays inconclusive instead of inventing a provider or configuration. That distinction matters when the next step is a potentially disruptive DNS, SSL or mail change.

How to verify the repair

The public MX/authentication records should match the intended mail provider, required hostnames should resolve, and the relevant SPF/DKIM/DMARC check should no longer show the original failure. Repeat TLS-RPT Checker after the change and compare the same _smtp._tls TXT, rua destinations and syntax evidence that exposed the problem. A provider dashboard saying “saved” is not enough when the public Internet still returns the old value.

What to check next if TLS-RPT Checker is healthy

If _smtp._tls TXT, rua destinations and syntax now agree but the user-facing problem remains, move to the adjacent layer instead of editing the same setting repeatedly. Use the related diagnostics on this page to test the next plausible cause, and keep the previous result as evidence when escalating to a hosting, DNS or email provider.

TLS-RPT is SMTP transport reporting, not website TLS

TLS-RPT is published at _smtp._tls and tells participating mail systems where to send aggregate reports about SMTP TLS delivery failures. It does not inspect the website certificate, HTTPS SAN coverage or browser TLS handshake. Use the SSL Certificate Checker for those web-facing questions.

How TLS-RPT relates to MTA-STS

MTA-STS can publish a policy for secure SMTP delivery while TLS-RPT provides aggregate reporting about transport failures. Either can exist without the other. Check each record and policy endpoint independently rather than treating one as proof that the other is configured.

Technical references

These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.