TLS-RPT builder & validator
TLS-RPT (RFC 8460) lets sending MTAs report TLS / MTA-STS / DANE failures back to you. Publish at _smtp._tls.<domain> alongside your MTA-STS record.
Build a TLS-RPT TXT record
Receivers POST JSON reports to this URL. Use https:// — plain http:// is refused (reports would be plaintext).
- ⚠ Provide a mailto: address, an https:// URL, or both.
v=TLSRPTv1
Pair with MTA-STS. TLS-RPT is most useful once you've published an MTA-STS policy: the reports tell you when senders are seeing failures before your customers notice. The MTA-STS builder generates the matching policy.
Keep hardening your email
Each record is one layer. Check the rest of yours — every tool is free, no account.
Email security scan
Run all 8 checks at once
SPF builder
Assemble a clean SPF record
SPF analyzer
Count your real DNS lookups
DMARC generator
Build a v=DMARC1 record
DMARC validator
Grade a record you have
DMARC report analyzer
Read a rua= XML report
DKIM validator
Check a DKIM key
Header analyzer
Trace a suspicious email
Blocklist checker
Are you on a DNSBL?
BIMI check
Get your logo in inboxes
MTA-STS
Force TLS on inbound mail
DMARC visibility
Ingest your rua= reports
Continuous monitoring
Catch record drift on a schedule