TLS Reporting

See every TLS connection reported for your domain, what succeeded, what failed, and why, in dashboards instead of raw report files.

Total Volume
128,400
Encrypted Delivery
94.2%
Failed Connections
1,860
Top Failure Reasons
starttls-not-supported 412
certificate-expired 180
certificate-host-mismatch 96

TLS reportingTLS reporting

Key Features of TLS Reporting

Volume and Success Rate at a Glance

See total email volume, encrypted delivery rate, and failed connections in three summary cards.

Two Ways to Read Your Reports

View TLS results Per Sending Source or Per Result to quickly identify successful and failed connections.

Drill Down to the Recipient Domain

Expand each sending source to view volume, results, success rate, and policy status by recipient domain.

See Your MTA-STS Policy in Action

See the Published Policy and Policy Type reported for each source to verify how your MTA-STS policy is being applied.

Success and Failure Trends Over Time

Track successful and failed TLS connections over the last 7 days, last month, or a custom date range.

Exportable Reports

Export TLS-RPT data to CSV and use multi-domain or domain group filters to review your domain portfolio.

Learn Why Your Encryption Is Failing

TLS Reporting breaks failures down by reason so you can distinguish certificate issues, policy problems, and connections where TLS was not successfully established.

Top TLS Encryption Failure Reasons

See your most common TLS failure reasons ranked by volume, making it easier to identify the issues affecting the largest number of connections.

starttls-not-supported

The receiving server did not support STARTTLS, so the connection could not be upgraded to TLS.

certificate-host-mismatch

The certificate presented by the receiving server does not match the hostname used for the TLS connection.

certificate-expired

The receiving server presented a TLS certificate that has passed its expiration date.

certificate-not-trusted

The certificate could not be validated against a trusted certificate authority or trust chain.

validation-failure

The TLS certificate or connection failed validation, preventing a secure connection.

Turn TLS Reports Into Action

Catch encryption failures early

Watch success and failure trends over time instead of waiting for a delivery issue to surface.

Confirm your MTA-STS policy is working

See the policy reported by sending sources and understand how your published policy is being applied.

Fix the right thing first

Identify the most common failure causes and drill down to the recipient domain behind each issue.

Simplify compliance

Export TLS-RPT data as CSV to maintain evidence for audits, internal reviews, and security reporting.

Get Started with TLS Reporting Now

1

Add Your Domain

Add a domain to PowerDMARC and follow the Setup Wizard to publish your TLS-RPT record.

2

Reports Come In

Receiving providers send TLS reports describing the connections made to your domain and the results of those connections.

3

See What's Failing

PowerDMARC parses the reports into dashboards showing volume, success rate, failure reasons, and the sending sources and recipient domains behind them.

Get Visibility Into Your TLS Connections

See the TLS failures reported for your domain, understand why they happened, and get the detail you need to investigate and fix them.