DIAGNOSTIC PLAYBOOK

TLS-RPT reports are missing: inspect discovery and delivery

A TLS-RPT record requests transport reports but does not guarantee every sender will produce them. Missing reports can reflect record problems, destination delivery issues or limited participating traffic.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Resolve the _smtp._tls TXT record and check its version and reporting destination syntax.
  2. Verify the collector can receive or ingest the supported report format.
  3. Compare recent inbound traffic with previous reporting organizations and coverage periods.

What this looks like

ILLUSTRATIVE EXAMPLE

A reporting mailbox was renamed without updating the published destination. Transport continues, but reports can no longer reach the collector.

A mistake to avoid

No reports is not equivalent to no TLS failures. Retain endpoint checks alongside passive reporting.

Keep the result in context

Transport encryption protects a connection between mail systems. It is different from message authentication and does not imply end-to-end encryption. Investigate the receiving MX hostname, the TLS session and the applicable policy separately before deciding which system needs a change.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.