For organisations using MTA-STS or DANE to enforce encrypted email delivery, monitoring for TLS failures is crucial. When these policies are enforced, configuration issues can lead to email delivery failures rather than falling back to unencrypted delivery. Today, we're introducing TLS Failure Alerts to help quickly notify you of potential disruption to your inbound email.
If you're using MTA-STS or DANE with TLSA records, your email infrastructure is configured to require encrypted connections. While this significantly enhances security, it also means that TLS connection failures will prevent email delivery entirely. Common scenarios include:
Without proactive monitoring, you might only discover these issues when important emails fail to arrive.
TLS Failure Alerts leverage SMTP TLS Reporting (TLS-RPT) to monitor connection attempts from external mail servers. When an external mail server attempts to deliver email to your domain and encounters TLS failures, they generate an SMTP TLS report. As soon as we process this report, you'll receive an alert email containing the affected domain.
From there you can go to the VerifyDMARC Dashboard to further investigate the nature of the failure.
To prevent alert fatigue we suppress further failure alerts for the same domain for 7 days.
Note that there is typically a delay between when TLS failures occur and when we receive the reports from external mail servers. This means alerts are not real-time notifications of failures, but rather prompt notifications when we learn about failures through received reports.
To enable TLS Failure Alerts, you'll need:
When enforcing TLS with MTA-STS or DANE, it's a good idea to use an "out-of-band" email address for alerts. For example:
Here's how TLS Failure Alerts help in a common scenario:
Without alerts, this situation could lead to a configuration issue being overlooked for longer than necessary.
If you're using MTA-STS or DANE:
TLS Failure Alerts are now automatically enabled for all customers using SMTP TLS Reporting with Alert Email Addresses configured. This feature helps you maintain strict security requirements without risking email availability.
Sign up for our 30-day free trial to experience the benefits of TLS Reporting and our comprehensive DMARC management platform. Don't wait - take control of your email security today with VerifyDMARC.
A practical guide for MSPs and SMEs to implement DMARC, SPF and DKIM protection for Microsoft 365, Office 365 and Exchange Online email services.
Even with p=none, DMARC without report monitoring is like driving blindfolded. Mail servers still check authentication, impacting your deliverability.
Learn how to stop email spoofing and improve delivery of order confirmations with DMARC. Implementation guide for Shopify, WooCommerce and Adobe Marketo.