Skip to main content

How to Configure TLS Reporting in Valimail

This article will explain how to set up TLS reporting in Valimail, as well as the MTA-STS policy set up in the DNS

Updated today

TLS Reporting (TLS-RPT) provides visibility into how successfully other mail servers are able to establish secure (TLS-encrypted) connections when sending email to your domain. By collecting and analyzing these reports, Valimail helps you identify delivery issues related to TLS, such as failed encryption attempts, certificate problems, or policy mismatches, so you can strengthen your domain’s email security posture.

Enabling TLS Reporting in Valimail

To have TLS reports ingested and processed in Valimail, you’ll need to publish the following DNS TXT record:

  • Host/Name: _smtp._tls.<yourdomain>

  • Type: TXT

  • Value: v=TLSRPTv1; rua=mailto:[email protected]

  • TTL: 3600 seconds

Once this record is in place, sending systems will begin delivering TLS reports to Valimail for analysis.

To access the TLS report, log into your Valimail account, go to the REPORTS section in the side menu, and click on TLS.

MTA-STS and TLS Reporting

TLS Reporting is commonly used alongside MTA-STS (Mail Transfer Agent Strict Transport Security), which enforces the use of TLS for inbound email. While TLS-RPT provides visibility, MTA-STS defines the policy that sending servers should follow when establishing secure connections.

MTA-STS hosting is available exclusively in Valimail Enforce and is not supported in Valimail Monitor. Enforce users should check this article for the complete guide on setting up the MTA-STS policy.

Did this answer your question?