The problem with enforced encryption

MTA-STS and DANE share an awkward property: they work by preventing delivery. If something is wrong with your certificate, the sending server aborts — correctly, because that is what the policy is for. Only you never hear about it. The sender sees a bounce, you see nothing, and since the message never reached your server, your logs are silent too.

TLS-RPT (RFC 8460) closes exactly that gap. The record is an invitation to every sending server: "If you could not deliver to me encrypted, please tell me." It is a single line:

_smtp._tls.example.com. IN TXT "v=TLSRPTv1; rua=mailto:tls-reports@example.com"

What AnalyzeMy.Email checks

  • Presence of the TXT record at _smtp._tls.<domain>
  • Valid version — v=TLSRPTv1 must be the first tag
  • Reporting destination from rua= — mailto: and https: are allowed, several separated by commas
  • Relationship to the policy — the record is evaluated alongside MTA-STS and DANE, because it makes little sense without them and is urgently needed with them

What the reports contain

Reports arrive as gzip-compressed JSON, usually once a day per sending organization. Three fields matter:

  • Policy type — sts, tlsa or no-policy-found. Persistent no-policy-found despite having set up MTA-STS means your policy file is not being located.
  • Success and failure counters per sending organization. A single failure is noise; a sustained ratio is a finding.
  • Failure type — the actual diagnosis: starttls-not-supported, certificate-expired, certificate-host-mismatch, validation-failure or sts-policy-fetch-error.

This lets you pin down the classic outage that would otherwise leave no trace: a backup MX whose certificate has expired and which nobody tests, because it is only used when the primary is down.

Recommendations

  • Set it up before tightening. TLS-RPT belongs in place before you move from testing to enforce — otherwise you are going live blind.
  • Use a dedicated address, not the general mailbox. The reports are machine-readable and unreadable in raw form.
  • Receive on a domain that stays reachable. If the report goes to the very domain that is currently undeliverable, the feedback channel disables itself.
  • Worthwhile even without MTA-STS: the record costs nothing and shows how much of your inbound mail arrives encrypted at all.

Test your own configuration

Send any email to hello@analyzemy.email and within seconds you get back a complete report with over 20 checks — including this one.

Analyze your email now

Last updated: · All checks at a glance