uCheckeruChecker

TLS-RPT Generator

The most harmless record in mail security: it forbids nothing and changes nothing about delivery, it simply asks for reports about failed attempts to encrypt a connection.

Where to send reports

Either a mail address or an https endpoint. Reports arrive daily and describe failed attempts to establish an encrypted connection to your server.

Generated record

v=TLSRPTv1; rua=mailto:
How to publish it
TypeNameTTL
TXT_smtp._tls3600

Why bother

TLS problems on the receiving side are invisible from the inside. A certificate expires, the name in it stops matching the server, an intermediate hop strips STARTTLS — the sender either delivers the message some other way or does not deliver it at all, and you never hear about it. TLS-RPT turns that invisible layer into a daily summary.

Where to publish it

As a TXT record at _smtp._tls.yourdomain. Most panels only need _smtp._tls in the name field. Both underscores are mandatory.

Questions

Nearby

Channel reports are not list quality

TLS-RPT tells you about connection problems, not about half your list being dead addresses. uChecker checks that before you send — the first 100 addresses are free.

Check your list