TLS Reports: is mail to you being encrypted?
DMARC is about who sent the mail. TLS reporting is about whether mail heading to you travelled encrypted. Big providers send you a daily summary of every delivery attempt to your domain and whether TLS worked; this page reads those for you.
- Where to find it
- Reports → TLS Reports
What you'll see
The default view covers the last 30 days.
- Encryption Rate at the top: successful TLS connections as a percentage of all attempts.
- A live check of your MTA-STS policy, whether the
mta-stshost actually resolves, and whether TLS reporting itself is switched on. Each shows pass or fail with the exact fix if something is missing. - Smart Recommendations: automatic, severity-coloured advice. A high failure rate (above 20%) is flagged critical; a clean setup gets an "Excellent TLS Posture" card.
- A Policy Details table per policy domain, a stacked chart of encrypted versus failed traffic per mail server, and a Failure Reasons breakdown you can open by sender IP.
- A Reporters panel listing every organisation that has sent you a TLS report, with its own success/fail ratio. Click one to see exactly which reports it sent.
Getting reports in the first place
You only receive TLS reports if you have published a TLS-RPT record telling providers where to send them. If the page shows TLS reporting as not configured, add this TXT record at your DNS provider:
TLS-RPT record to publish
- Type
TXT- Host
_smtp._tls- Value
v=TLSRPTv1; rua=mailto:tls.reports@dmarcs.com
Reports start arriving within a day. To actually require encryption rather than just report on it, set up Hosted MTA-STS.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.