The problem with enforced encryption
MTA-STS and DANE share an awkward property: they work by preventing delivery. If something is wrong with your certificate, the sending server aborts — correctly, because that is what the policy is for. Only you never hear about it. The sender sees a bounce, you see nothing, and since the message never reached your server, your logs are silent too.
TLS-RPT (RFC 8460) closes exactly that gap. The record is an invitation to every sending server: "If you could not deliver to me encrypted, please tell me." It is a single line:
What AnalyzeMy.Email checks
- Presence of the TXT record at
_smtp._tls.<domain> - Valid version —
v=TLSRPTv1must be the first tag - Reporting destination from
rua=—mailto:andhttps:are allowed, several separated by commas - Relationship to the policy — the record is evaluated alongside MTA-STS and DANE, because it makes little sense without them and is urgently needed with them
What the reports contain
Reports arrive as gzip-compressed JSON, usually once a day per sending organization. Three fields matter:
- Policy type —
sts,tlsaorno-policy-found. Persistentno-policy-founddespite having set up MTA-STS means your policy file is not being located. - Success and failure counters per sending organization. A single failure is noise; a sustained ratio is a finding.
- Failure type — the actual diagnosis:
starttls-not-supported,certificate-expired,certificate-host-mismatch,validation-failureorsts-policy-fetch-error.
This lets you pin down the classic outage that would otherwise leave no trace: a backup MX whose certificate has expired and which nobody tests, because it is only used when the primary is down.
Recommendations
- Set it up before tightening. TLS-RPT belongs in place before you move from
testingtoenforce— otherwise you are going live blind. - Use a dedicated address, not the general mailbox. The reports are machine-readable and unreadable in raw form.
- Receive on a domain that stays reachable. If the report goes to the very domain that is currently undeliverable, the feedback channel disables itself.
- Worthwhile even without MTA-STS: the record costs nothing and shows how much of your inbound mail arrives encrypted at all.