TLS-RPT: the protocol your DMARC vendor probably doesn't support
When a sending server can't establish a TLS connection to your mail server
e.g. a certificate mismatch, expired cert, DANE validation failure, MTA-STS policy violation
TLS-RPT sends you a report
without it, encrypted delivery fails silently
you'd never know that a major sender has been falling back to plaintext (or not delivering at all) for weeks



