For organisations using MTA-STS or DANE to enforce encrypted email delivery, monitoring for TLS failures is crucial. When these policies are enforced, configuration issues can lead to email delivery failures rather than falling back to unencrypted delivery. Today, we're introducing TLS Failure Alerts to help quickly notify you of potential disruption to your inbound email.
If you're using MTA-STS or DANE with TLSA records, your email infrastructure is configured to require encrypted connections. While this significantly enhances security, it also means that TLS connection failures will prevent email delivery entirely. Common scenarios include:
Without proactive monitoring, you might only discover these issues when important emails fail to arrive.
TLS Failure Alerts leverage SMTP TLS Reporting (TLS-RPT) to monitor connection attempts from external mail servers. When an external mail server attempts to deliver email to your domain and encounters TLS failures, they generate an SMTP TLS report. As soon as we process this report, you'll receive an alert email containing the affected domain.
From there you can go to the VerifyDMARC Dashboard to further investigate the nature of the failure.
To prevent alert fatigue we suppress further failure alerts for the same domain for 7 days.
Note that there is typically a delay between when TLS failures occur and when we receive the reports from external mail servers. This means alerts are not real-time notifications of failures, but rather prompt notifications when we learn about failures through received reports.
To enable TLS Failure Alerts, you'll need:
When enforcing TLS with MTA-STS or DANE, it's a good idea to use an "out-of-band" email address for alerts. For example:
Here's how TLS Failure Alerts help in a common scenario:
Without alerts, this situation could lead to a configuration issue being overlooked for longer than necessary.
If you're using MTA-STS or DANE:
TLS Failure Alerts are now automatically enabled for all customers using SMTP TLS Reporting with Alert Email Addresses configured. This feature helps you maintain strict security requirements without risking email availability.
Sign up for our 30-day free trial to experience the benefits of TLS Reporting and our comprehensive DMARC management platform. Don't wait - take control of your email security today with VerifyDMARC.
Microsoft will reject mail that "does not meet the required authentication level". To fix this, you need a DMARC record, SPF and DKIM passing, plus SPF or DKIM alignment.
Learn how to stop email spoofing and improve delivery of order confirmations with DMARC. Implementation guide for Shopify, WooCommerce and Marketo.
We're excited to announce two new Insight reports designed to streamline multi-domain management: Sender Compliance Report and SPF Record Checker.