email-transport · severity low
DANE for mail
Share of email-active domains with no DANE/TLSA record — nothing cryptographically binds their mail server's TLS certificate.
Measured every Friday · last updated
How it is measured
Tier 0 (DNS-only, so it works even where port 25 is blocked). TLSA lookup at _25._tcp.<mx>. Denominator: has_mx.
Why it matters
DANE is what turns opportunistic TLS into authenticated TLS — it tells a sender which certificate to expect, closing the downgrade gap that mx-tls-cert exposes.
Limits of this measurement
Near-universally absent outside a few countries; useful as an adoption frontier rather than an actionable defect for a small company.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 5 segments
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.